Microsoft Maintains Go Fork for FIPS 140-2 Support
1–10 of 21 posts
Re: Microsoft Maintains Go Fork for FIPS 140-2 Support
#2Re: Microsoft Maintains Go Fork for FIPS 140-2 Support
#3This repo doesn't seem to list what sort of high-level/conceptual changes are involved. I could look at the diff, but that sounds exhausting :Þ
Re: Microsoft Maintains Go Fork for FIPS 140-2 Support
#4Does anyone with FIPS experience know what sort of changes are entailed by those requirements? This repo doesn't seem to list what sort of high-level/conceptual changes are involved. I could look at the diff, but that sounds exhausting :Þ
Re: Microsoft Maintains Go Fork for FIPS 140-2 Support
#5https://github.com/golang/go/tree/dev.boringcrypto/misc/bori...
But it looks dead for some time.
However https://github.com/golang-fips/go sprung up to take it's place.
I wonder why microsoft prefers to maintain it's own in entirety rather than share a piece of the burden.
Re: Microsoft Maintains Go Fork for FIPS 140-2 Support
#6Microsoft's security reputation is so flawed, that some parts simply must be intentional, or coerced.
Don't use this repo. Very interesting TIL about golang at Microsoft. Thanks for sharing.
Re: Microsoft Maintains Go Fork for FIPS 140-2 Support
#7If this doesn't also _add_ some "accidental" backdoor, I'd be surprised. Microsoft's security reputation is so flawed, that some parts simply must be intentional, or coerced. Don't use this repo. Very interesting TIL about golang at Microsoft. Thanks for sharing.
Don't use any FIPS branch of any platform, because FIPS is terrible. But the argument presented here seems facile.
Re: Microsoft Maintains Go Fork for FIPS 140-2 Support
#8There used to be the GO FIPS branch: https://github.com/golang/go/tree/dev.boringcrypto/misc/bori... But it looks dead for some time. However https://github.com/golang-fips/go sprung up to take it's place. I wonder why microsoft prefers to maintain it's own in entirety rather than share a piece of the burden.
From the readme.
Re: Microsoft Maintains Go Fork for FIPS 140-2 Support
#9Re: Microsoft Maintains Go Fork for FIPS 140-2 Support
#10If this doesn't also _add_ some "accidental" backdoor, I'd be surprised. Microsoft's security reputation is so flawed, that some parts simply must be intentional, or coerced. Don't use this repo. Very interesting TIL about golang at Microsoft. Thanks for sharing.
They are a lot better than they used to be. They went through a trial by fire in the 90s and early 00s and came through for the better.
It's worth noting that classified computer systems in the military-industrial complex run Windows, and not Linux, nor do they run the security cosplay that is OpenBSD.