[HN Gopher] Microsoft Maintains Go Fork for FIPS 140-2 Support
       ___________________________________________________________________
        
       Microsoft Maintains Go Fork for FIPS 140-2 Support
        
       Author : dschofie
       Score  : 27 points
       Date   : 2024-04-30 19:02 UTC (3 hours ago)
        
 (HTM) web link (github.com)
 (TXT) w3m dump (github.com)
        
       | interroboink wrote:
       | Does anyone with FIPS experience know what sort of changes are
       | entailed by those requirements?
       | 
       | This repo doesn't seem to list what sort of high-level/conceptual
       | changes are involved. I could look at the diff, but that sounds
       | exhausting :Th
        
         | bpicolo wrote:
         | They document exactly that
         | https://github.com/microsoft/go/tree/microsoft/main/eng/doc/...
        
       | metadat wrote:
       | There used to be the GO FIPS branch:
       | 
       | https://github.com/golang/go/tree/dev.boringcrypto/misc/bori...
       | 
       | But it looks dead for some time.
       | 
       | However https://github.com/golang-fips/go sprung up to take it's
       | place.
       | 
       | I wonder why microsoft prefers to maintain it's own in entirety
       | rather than share a piece of the burden.
        
         | abtinf wrote:
         | > Our goal is to share this implementation with others in the
         | Go community who have the same requirement, and to merge this
         | capability into upstream Go as soon as possible.
         | 
         | From the readme.
        
       | purpleidea wrote:
       | If this doesn't also _add_ some "accidental" backdoor, I'd be
       | surprised.
       | 
       | Microsoft's security reputation is so flawed, that some parts
       | simply must be intentional, or coerced.
       | 
       | Don't use this repo. Very interesting TIL about golang at
       | Microsoft. Thanks for sharing.
        
         | tptacek wrote:
         | It's built from source. You can just diff it. Of course, you
         | don't have to, because they provide the patches.
         | 
         | Don't use any FIPS branch of any platform, because FIPS is
         | terrible. But the argument presented here seems facile.
        
           | SAI_Peregrinus wrote:
           | FIPS is terrible, except that sometimes if you shout "FIPS
           | 140 compliance for US gov contracts" enough into the
           | corporate hierarchy you eventually get the budget to
           | implement _any security whatsoever, even though it 's just
           | FIPS_.
           | 
           | If you're not trying to get US government contracts that
           | require it, don't bother with FIPS. It mandates older
           | algorithms; they're secure enough but not as performant and
           | there are a lot more footguns. FIPS 140-3 fixed a few, but
           | not all.
        
         | nvy wrote:
         | >Microsoft's security reputation is so flawed, that some parts
         | simply must be intentional, or coerced.
         | 
         | They are a lot better than they used to be. They went through a
         | trial by fire in the 90s and early 00s and came through for the
         | better.
         | 
         | It's worth noting that classified computer systems in the
         | military-industrial complex run Windows, and not Linux, nor do
         | they run the security cosplay that is OpenBSD.
        
         | bitwize wrote:
         | Jonathan Blow ranted about the susceptibility of open source to
         | supply chain attacks from state actors, which discussion
         | recently became germane again in light of the xz backdoor.
         | 
         | What he didn't discuss was how vulnerable proprietary vendors
         | (including, but by no means limited to, Microsoft) are to
         | "rubber-hose vulnerability injection".
         | 
         | Anyway, it's good to see Microsoft actually participating in
         | the open source process.
        
       ___________________________________________________________________
       (page generated 2024-04-30 23:01 UTC)