Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Isn't there still need for non- or post- FIPS-140 -like cipher restrictions in non FIPS-140 environments?
How much code is needed to implement Classical+PQ (Hybrid PQ) or PQ-only (Only PQ) cipher selection restrictions just?
FWIU, with golang:
tlsref needs to be revised to specify PQ cipher lists.# This allows X25519MLKEM768 (Hybrid PQ) GODEBUG=fips140=on # This prevents any PQ ciphers from being used: GODEBUG=fips140=onlyby westurner - It's been 2-4d since a maintainer replied. Why escalate the situation by trying to raise HN attention to it?by clivedup
- What's up with all the likes, urgency, and pressure? Is this part of some kind of operation?by pamcake
- From having had my own prior interactions with you, I am entirely unsurprised that you're getting some cold shoulder due to other people's experiences with you.
As far as I can tell you're great at cryptography code. You've gotten better at the social parts of collaborative software engineering, but there's still room to grow.
by eqvinox - Alberto (https://github.com/golang/go/issues/81639#issuecomment-58553...) found only a 75kB difference between the 'bloat' and your proposed patch in a stripped binary; and Roland (https://github.com/golang/go/issues/81639#issuecomment-58402...) contended:
> the symbols in your tester2 program account for ~67kb out of a 2.3mb binary
OP did find a "600k difference" in an unstripped comparison but if binary size was critical enough that 600k was a big deal, I'd assume users would be stripping the binaries outright or using a different language (tinygo perhaps) if a <100kb diff was on their list of concerns.
by nateb2022