Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Isn't there still need for non- or post- FIPS-140 -like cipher restrictions in non FIPS-140 environments?

    How much code is needed to implement Classical+PQ (Hybrid PQ) or PQ-only (Only PQ) cipher selection restrictions just?

    FWIU, with golang:

      # This allows X25519MLKEM768 (Hybrid PQ)
      GODEBUG=fips140=on
    
      # This prevents any PQ ciphers from being used:
      GODEBUG=fips140=only
    
    tlsref needs to be revised to specify PQ cipher lists.
  • It's been 2-4d since a maintainer replied. Why escalate the situation by trying to raise HN attention to it?
  • What's up with all the likes, urgency, and pressure? Is this part of some kind of operation?
  • From having had my own prior interactions with you, I am entirely unsurprised that you're getting some cold shoulder due to other people's experiences with you.

    As far as I can tell you're great at cryptography code. You've gotten better at the social parts of collaborative software engineering, but there's still room to grow.

  • Alberto (https://github.com/golang/go/issues/81639#issuecomment-58553...) found only a 75kB difference between the 'bloat' and your proposed patch in a stripped binary; and Roland (https://github.com/golang/go/issues/81639#issuecomment-58402...) contended:

    > the symbols in your tester2 program account for ~67kb out of a 2.3mb binary

    OP did find a "600k difference" in an unstripped comparison but if binary size was critical enough that 600k was a big deal, I'd assume users would be stripping the binaries outright or using a different language (tinygo perhaps) if a <100kb diff was on their list of concerns.

Explore Birbla archives