Golang: Crypto/fips140: do not bloat crypto code unnecessarily
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
Golang: Crypto/fips140: do not bloat crypto code unnecessarily
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
westurner · · focus · HN ↗
How much code is needed to implement Classical+PQ (Hybrid) or PQ-only cipher selection restrictions just?
FWIU, with golang:
tlsref needs to be revised to specify PQ cipher lists.twiss · · focus · HN ↗
So, if you only want PQC, you'll have to do that manually either way. But, I think you'll find many servers aren't ready for that: <a href="https://www.netmeister.org/blog/pqc-use-2026-09.html" rel="nofollow">https://www.netmeister.org/blog/pqc-use-2026-09.html
westurner · · focus · HN ↗
eqvinox · · focus · HN ↗
As far as I can tell you're great at cryptography code. You've gotten better at the social parts of collaborative software engineering, but there's still room to grow.
clivedup · · focus · HN ↗
pamcake · · focus · HN ↗
nateb2022 · · focus · HN ↗
> the symbols in your tester2 program account for ~67kb out of a 2.3mb binary
OP did find a "600k difference" in an unstripped comparison but if binary size was critical enough that 600k was a big deal, I'd assume users would be stripping the binaries outright or using a different language (tinygo perhaps) if a <100kb diff was on their list of concerns.
pseudohadamard · · focus · HN ↗
Having said that, I'm not sure there's much chance of it being adopted. Crypto people really want to have all the complexity all the time, which this is the exact opposite of. I mean, do you really need a custom AVX2-accelerated SHA256 implementation so you can generate a 128-bit random value? Or all of SHA256 and SHA3 and cSHAKE and SHA512? This is what makes WireGuard so secure, there's only one mode and that's secure-by-default.