Live data from Hacker News

LibreSSL: FIPS mode is not coming back

marc.info

91–98 of 98 posts

Re: LibreSSL: FIPS mode is not coming back

#91
OpenBSD lives their mantra and are unafraid of what the internet comment boards have to say about it.

They do what they feel is right and believe others are free to benefit from it or go make your own. The world needs more of this not less.

What the world needs less of is people with opinions and inability or unwillingness to take action other than complain about the actions of others.

Re: LibreSSL: FIPS mode is not coming back

#92
post #62
post #3

The OpenBSD people sure are abrasive, but they deserve a ton of praise for taking on a tough task that no one else was willing to do, and for fixing the damn mess. Between FIPS, the NIST and the OpenSSL foundation it's amazing that crypto even works.

but they deserve a ton of praise for taking on a tough task that no one else was willing to do There seemed to be some serious momentum behind getting proper resources and financing in place for a real effort that the project deserves, but all of that dissolved when this team started making a lot of sound and fury about their fork of something purportedly "beyond fixing". Aside from several incidents of spite-driven…

I tend to think the reason that support dissolved was that many people, myself included, think OpenBSD will do a better job of responsible maintenance. I have no good reason to think throwing money at OpenSSL would actually improve anything that matters. Much more likely we'd just get more of what we've been getting.

Re: LibreSSL: FIPS mode is not coming back

#93

Earlier quoted context omitted.

There is hardly a shortage of abrasiveness in the security industry. That said, I find zero things wrong with OpenBSD's work to make LibreSSL. If anyone doesn't like it, I'll offer them their money back.

I don't think that the first statement is correct. OpenBSD is not nearly so visible as RSA, Norton, Verisign, et. al., and those brands are heavily invested in the theatrical aspects of security to the point of emphasizing appearances over actual security. The part of the industry that is visible to the general public, and even probably most of the technical community are brands such as those, and you can't trust the…

> RSA, Norton, Verisign, et. al., and those brands are heavily invested in the theatrical aspects of security to the point of emphasizing appearances over actual security.

I think appearance over function is true ever since politics and advertising were invented.

Re: LibreSSL: FIPS mode is not coming back

#94
post #79
post #78

Earlier quoted context omitted.

This is a dupe because it's already synced to git mirrors of openbsd sources. http://anoncvs.estpak.ee/cgi-bin/cgit/openbsd-src/tree/lib/l... "When I grow up..." Tandem multiplication commit is hilarious.

That's the beautiful thing about DVCS, no? Please elaborate where the official git sources are.

There is none, OpenBSD uses CVS.

Re: LibreSSL: FIPS mode is not coming back

#96
post #87
post #3

The OpenBSD people sure are abrasive, but they deserve a ton of praise for taking on a tough task that no one else was willing to do, and for fixing the damn mess. Between FIPS, the NIST and the OpenSSL foundation it's amazing that crypto even works.

"Fixing" it in a way that guarantees that the changes will not be pulled back into OpenSSL has the following problems: * the fork will lag behind when new features are introduced into OpenSSL * the fork will lag behind when new fixes for OpenSSL are implemented This creates a permanent maintenance burden for the LibreSSL maintainers; sure they have attention now, but in 3 months nobody will give a shit any more.

> "Fixing" it in a way that guarantees that the changes will not be pulled back into OpenSSL has the following problems:

> * the fork will lag behind when new features are introduced into OpenSSL

> * the fork will lag behind when new fixes for OpenSSL are implemented

> This creates a permanent maintenance burden for the LibreSSL maintainers; sure they have attention now, but in 3 months nobody will give a shit any more.

So, it's gonna be apache all over again. Where they maintained their own fork, with no security patches applied.

Or perhaps like OpenSSH, where a linux user is forced to `./configure && make && make install'.

I'm trusting your opinion, after careful reviewing of all your commits. :)

/irony off

Post reply on HN