‹ BackHN Continuity

Thread

Golang: Crypto/fips140: do not bloat crypto code unnecessarily

18 points · 5 comments · zx2c4

Loading the complete thread in the background. This saved snapshot is available now. Refresh

  1. westurner · · focus · HN ↗
    Isn't there still need for non- or post- FIPS-140 -like cipher restrictions in non FIPS-140 environments?

    How much code is needed to implement Classical+PQ (Hybrid) or PQ-only cipher selection restrictions just?

    FWIU, with golang:

      # This allows X25519MLKEM768 (Hybrid PQ)
      GODEBUG=fips140=on
    
      # This prevents any PQ ciphers from being used:
      GODEBUG=fips140=only
    
    tlsref needs to be revised to specify PQ cipher lists.
    1. twiss · · focus · HN ↗
      FIPS-140 doesn't yet require PQC, nor does Go in FIPS mode (or any other mode).

      So, if you only want PQC, you&#x27;ll have to do that manually either way. But, I think you&#x27;ll find many servers aren&#x27;t ready for that: <a href="https:&#x2F;&#x2F;www.netmeister.org&#x2F;blog&#x2F;pqc-use-2026-09.html" rel="nofollow">https:&#x2F;&#x2F;www.netmeister.org&#x2F;blog&#x2F;pqc-use-2026-09.html

      1. westurner · · focus · HN ↗
        Some notes on PQC and MTC roadmaps in &quot;Shipping post-quantum cryptography to Python – The Trail of Bits Blog&quot; <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48789958">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48789958
  2. eqvinox · · focus · HN ↗
    From having had my own prior interactions with you, I am entirely unsurprised that you&#x27;re getting some cold shoulder due to other people&#x27;s experiences with you.

    As far as I can tell you&#x27;re great at cryptography code. You&#x27;ve gotten better at the social parts of collaborative software engineering, but there&#x27;s still room to grow.

  3. clivedup · · focus · HN ↗
    Posting this to HN as if we&#x27;re a jury.
  4. pamcake · · focus · HN ↗
    What&#x27;s up with all the likes, urgency, and pressure? Is this part of some kind of operation?
  5. nateb2022 · · focus · HN ↗
    Alberto (<a href="https:&#x2F;&#x2F;github.com&#x2F;golang&#x2F;go&#x2F;issues&#x2F;81639#issuecomment-5855332392" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;golang&#x2F;go&#x2F;issues&#x2F;81639#issuecomment-58553...) found only a 75kB difference between the &#x27;bloat&#x27; and your proposed patch in a stripped binary; and Roland (<a href="https:&#x2F;&#x2F;github.com&#x2F;golang&#x2F;go&#x2F;issues&#x2F;81639#issuecomment-5840291260" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;golang&#x2F;go&#x2F;issues&#x2F;81639#issuecomment-58402...) contended:

    &gt; the symbols in your tester2 program account for ~67kb out of a 2.3mb binary

    OP did find a &quot;600k difference&quot; in an unstripped comparison but if binary size was critical enough that 600k was a big deal, I&#x27;d assume users would be stripping the binaries outright or using a different language (tinygo perhaps) if a &lt;100kb diff was on their list of concerns.

  6. pseudohadamard · · focus · HN ↗
    That&#x27;s not just some random guy, zx2c4 is the author of WireGuard and I&#x27;d trust him to get things right more than, oh, about 99.9% of people doing crypto out there. And the problem isn&#x27;t so much the code size, it&#x27;s the huge amount of unnecessary complexity and attack surface that this all this stuff adds.

    Having said that, I&#x27;m not sure there&#x27;s much chance of it being adopted. Crypto people really want to have all the complexity all the time, which this is the exact opposite of. I mean, do you really need a custom AVX2-accelerated SHA256 implementation so you can generate a 128-bit random value? Or all of SHA256 and SHA3 and cSHAKE and SHA512? This is what makes WireGuard so secure, there&#x27;s only one mode and that&#x27;s secure-by-default.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.