‹ BackHN Continuity

Thread

Golang: Crypto/fips140: do not bloat crypto code unnecessarily

19 points · 8 comments · zx2c4

  1. pseudohadamard · · focus · HN ↗
    That's not just some random guy, zx2c4 is the author of WireGuard and I'd trust him to get things right more than, oh, about 99.9% of people doing crypto out there. And the problem isn't so much the code size, it's the huge amount of unnecessary complexity and attack surface that this all this stuff adds.

    Having said that, I'm not sure there's much chance of it being adopted. Crypto people really want to have all the complexity all the time, which this is the exact opposite of. I mean, do you really need a custom AVX2-accelerated SHA256 implementation so you can generate a 128-bit random value? Or all of SHA256 and SHA3 and cSHAKE and SHA512? This is what makes WireGuard so secure, there's only one mode and that's secure-by-default.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.