[HN Gopher] Microsoft Maintains Go Fork for FIPS 140-2 Support
___________________________________________________________________
Microsoft Maintains Go Fork for FIPS 140-2 Support
Author : dschofie
Score : 27 points
Date : 2024-04-30 19:02 UTC (3 hours ago)
(HTM) web link (github.com)
(TXT) w3m dump (github.com)
| interroboink wrote:
| Does anyone with FIPS experience know what sort of changes are
| entailed by those requirements?
|
| This repo doesn't seem to list what sort of high-level/conceptual
| changes are involved. I could look at the diff, but that sounds
| exhausting :Th
| bpicolo wrote:
| They document exactly that
| https://github.com/microsoft/go/tree/microsoft/main/eng/doc/...
| metadat wrote:
| There used to be the GO FIPS branch:
|
| https://github.com/golang/go/tree/dev.boringcrypto/misc/bori...
|
| But it looks dead for some time.
|
| However https://github.com/golang-fips/go sprung up to take it's
| place.
|
| I wonder why microsoft prefers to maintain it's own in entirety
| rather than share a piece of the burden.
| abtinf wrote:
| > Our goal is to share this implementation with others in the
| Go community who have the same requirement, and to merge this
| capability into upstream Go as soon as possible.
|
| From the readme.
| purpleidea wrote:
| If this doesn't also _add_ some "accidental" backdoor, I'd be
| surprised.
|
| Microsoft's security reputation is so flawed, that some parts
| simply must be intentional, or coerced.
|
| Don't use this repo. Very interesting TIL about golang at
| Microsoft. Thanks for sharing.
| tptacek wrote:
| It's built from source. You can just diff it. Of course, you
| don't have to, because they provide the patches.
|
| Don't use any FIPS branch of any platform, because FIPS is
| terrible. But the argument presented here seems facile.
| SAI_Peregrinus wrote:
| FIPS is terrible, except that sometimes if you shout "FIPS
| 140 compliance for US gov contracts" enough into the
| corporate hierarchy you eventually get the budget to
| implement _any security whatsoever, even though it 's just
| FIPS_.
|
| If you're not trying to get US government contracts that
| require it, don't bother with FIPS. It mandates older
| algorithms; they're secure enough but not as performant and
| there are a lot more footguns. FIPS 140-3 fixed a few, but
| not all.
| nvy wrote:
| >Microsoft's security reputation is so flawed, that some parts
| simply must be intentional, or coerced.
|
| They are a lot better than they used to be. They went through a
| trial by fire in the 90s and early 00s and came through for the
| better.
|
| It's worth noting that classified computer systems in the
| military-industrial complex run Windows, and not Linux, nor do
| they run the security cosplay that is OpenBSD.
| bitwize wrote:
| Jonathan Blow ranted about the susceptibility of open source to
| supply chain attacks from state actors, which discussion
| recently became germane again in light of the xz backdoor.
|
| What he didn't discuss was how vulnerable proprietary vendors
| (including, but by no means limited to, Microsoft) are to
| "rubber-hose vulnerability injection".
|
| Anyway, it's good to see Microsoft actually participating in
| the open source process.
___________________________________________________________________
(page generated 2024-04-30 23:01 UTC)