Abstract The FIPS140 code, especially its RNG, sits unused and bloaty on the overwhelming majority of Go binaries. All but the most specific users actually jump through the hoops of turning on this...
8 comments
As far as I can tell you're great at cryptography code. You've gotten better at the social parts of collaborative software engineering, but there's still room to grow.
> the symbols in your tester2 program account for ~67kb out of a 2.3mb binary
OP did find a "600k difference" in an unstripped comparison but if binary size was critical enough that 600k was a big deal, I'd assume users would be stripping the binaries outright or using a different language (tinygo perhaps) if a <100kb diff was on their list of concerns.
How much code is needed to implement Classical+PQ (Hybrid PQ) or PQ-only (Only PQ) cipher selection restrictions just?
FWIU, with golang:
# This allows X25519MLKEM768 (Hybrid PQ)
GODEBUG=fips140=on
# This prevents any PQ ciphers from being used:
GODEBUG=fips140=only
tlsref needs to be revised to specify PQ cipher lists.So, if you only want PQC, you'll have to do that manually either way. But, I think you'll find many servers aren't ready for that: https://www.netmeister.org/blog/pqc-use-2026-09.html
mozilla/ssl-config-generator is now tlsref/configurar: https://github.com/tlsref/configurator .. http://configurator.tlsref.org/
Read the full thread on Hacker News →
Related stories
- Lobsters · 86 points · about 1 year ago
- Hacker News · 8 points · 6 days ago
- Hacker News · 14 points · 8 days ago
- DEV Community · 14 points · 11 days ago
- Hacker News · 3 points · 9 days ago
- Hacker News · 1 points · 10 days ago