Live data from Hacker News

LibreSSL: FIPS mode is not coming back

marc.info

71–80 of 98 posts

Re: LibreSSL: FIPS mode is not coming back

#71
post #3

The OpenBSD people sure are abrasive, but they deserve a ton of praise for taking on a tough task that no one else was willing to do, and for fixing the damn mess. Between FIPS, the NIST and the OpenSSL foundation it's amazing that crypto even works.

I've got to say that I like the abrasiveness. The security industry is rife with imposters and pretenders. All of the artifice and bogus claims make it very easy for people, organizations, industries... hell, governments to be misled into devoting huge amounts of resources into propping up what amounts to security theater, which is generally actively harmful. Abrasiveness and a willingness to ruffle the feathers of p…

Abrasiveness and being opinionated are mostly orthogonal.

I think this is more of a correct opinion (to reduce whale blubber) than intentionally pissing people off.

Re: LibreSSL: FIPS mode is not coming back

#72

Earlier quoted context omitted.

I've got to say that I like the abrasiveness. The security industry is rife with imposters and pretenders. All of the artifice and bogus claims make it very easy for people, organizations, industries... hell, governments to be misled into devoting huge amounts of resources into propping up what amounts to security theater, which is generally actively harmful. Abrasiveness and a willingness to ruffle the feathers of p…

There is hardly a shortage of abrasiveness in the security industry. That said, I find zero things wrong with OpenBSD's work to make LibreSSL. If anyone doesn't like it, I'll offer them their money back.

The problem is that being abrasive without displaying a clear, correct opinion won't lead to greater influence. The latter stance is the important bit.

Security projects need adversarial discussions to keep them honest, but that's a special case.

Re: LibreSSL: FIPS mode is not coming back

#73
post #3

The OpenBSD people sure are abrasive, but they deserve a ton of praise for taking on a tough task that no one else was willing to do, and for fixing the damn mess. Between FIPS, the NIST and the OpenSSL foundation it's amazing that crypto even works.

This stance is counterproductive in my eyes. Lots of security standards, including state/local government and some healthcare environments require FIPS compliance. FIPS isn't perfect, but screens out low-quality crypto implementations that most organizations lack the expertise to evaluate. Dual_EC and that ilk is obviously a serious problem, but FIPS validation addresses other pertinent problems -- like my doctor's o…

FIPS mode is like a clipboard audit. It appears to fulfill a requirement like A+ certifications do for hiring qualified candidates, but instead puts blind faith in process ahead of content.

Re: LibreSSL: FIPS mode is not coming back

#74

Earlier quoted context omitted.

This stance is counterproductive in my eyes. Lots of security standards, including state/local government and some healthcare environments require FIPS compliance. FIPS isn't perfect, but screens out low-quality crypto implementations that most organizations lack the expertise to evaluate. Dual_EC and that ilk is obviously a serious problem, but FIPS validation addresses other pertinent problems -- like my doctor's o…

They point they were making that wasn't clearly elaborated upon is that the code in OpenSSL for FIPS compliance is a charade and is only there to satisfy FIPS requirements. The presence of that code doesn't guarantee or ensure the anything. These compliance standards generally exist to deflect liability in the event of a breech and aren't necessarily there to protect anything. Take PCI for example, much of the DSS re…

Yup. And it's simpler and therefore more secure to support a smaller codebase without magical modes.

Re: LibreSSL: FIPS mode is not coming back

#75
post #7

Its a reasonable stance, I expect someone will create libfipsssl for the reason that they can charge money for it. For a while at Sun I suggested that we meet the "OSI Network Standards" requirement by just sending a library with stubs that would close out the link, and if they ever got called email us. The humor didn't seem to reasonate with the Federal Systems people :-)

Definitely. It'll be expensive commercial open source w/ a subscription and delayed to pass FIPS. And LibreSSL will still be more secure.

Re: LibreSSL: FIPS mode is not coming back

#76
post #31

Earlier quoted context omitted.

Also, I believe that only binaries can be FIPS certified, not source code, so there are times when one has to use an old, out-dated openssl binary in order to be compliant.

OpenSSL FIPS certification (#1747) is for source code, not for binary. This is highly unusual indeed, but it is not the case that only binaries can be FIPS certified. On the other hand, you can't change the source without losing the certification, so it doesn't actually matter.

I guess it begs the question (FIPS mode seems to fail the "talk to a cryptographer rule"): why don't/aren't sec folks more involved to assure standards are meaningful? Was this a NIST-driven process or was it open to public comments?

Re: LibreSSL: FIPS mode is not coming back

#77
post #5

This basically means libressl can not be used by the US Govt or any contractor working with the US Govt, which is a HUGE number of companies. By proxy, it means that libressl will not make its way into Fedora or RHEL, which also limits the adoption of it a fair bit. Perhaps the solution is to fix FIPS instead of berating the people forced to use it.

Sounds good because it suggests sec industry disengagement. Probably simpler to do that and maintain it as a set of minimal patches to LibreSSL, because not many people need it. Either way, it should be secure by default.

Re: LibreSSL: FIPS mode is not coming back

#78
post #52
post #47

Just looking at the wholesale cleanup [1] makes me shudder to think about how tough the code was to maintain in the past. Kudos to the libssl team for injecting some much-needed energy into such a critical library. If only this were available on GitHub, we could more easily browse the code and learn about patterns and anti-patterns in writing secure code. [1] http://freshbsd.org/search?project=openbsd&q=file.name:lib…

An unofficial mirror: https://github.com/libressl/libressl

This is a dupe because it's already synced to git mirrors of openbsd sources.

http://anoncvs.estpak.ee/cgi-bin/cgit/openbsd-src/tree/lib/l...

"When I grow up..." Tandem multiplication commit is hilarious.

Re: LibreSSL: FIPS mode is not coming back

#79
post #78
post #52

Earlier quoted context omitted.

An unofficial mirror: https://github.com/libressl/libressl

This is a dupe because it's already synced to git mirrors of openbsd sources. http://anoncvs.estpak.ee/cgi-bin/cgit/openbsd-src/tree/lib/l... "When I grow up..." Tandem multiplication commit is hilarious.

That's the beautiful thing about DVCS, no?

Please elaborate where the official git sources are.

Re: LibreSSL: FIPS mode is not coming back

#80
post #3

The OpenBSD people sure are abrasive, but they deserve a ton of praise for taking on a tough task that no one else was willing to do, and for fixing the damn mess. Between FIPS, the NIST and the OpenSSL foundation it's amazing that crypto even works.

The OpenBSD people sure are abrasive I've said it before, all "opinionated software" is abrasive, the scale is really how much you notice it based on if you like the faces and decisions involved. It'd be non-controversial to the HN crowd, but there are plenty of developers are happy to trash any GPL/share-alike project on the same grounds.

>all "opinionated software" is abrasive

I don't know you, so this is not directed at you. However, this is the kind of line I hear from abrasive people defending their unwillingness to temper what they say.

It's perfectly possible to have opinionated software (take JUnit or TeX, for example) that simply performs its task in an opinionated way without its authors belittling competitors or being disrespectful to others whose work doesn't fulfill their view of how things should be.

Post reply on HN