Live data from Hacker News

LibreSSL: FIPS mode is not coming back

marc.info

1–10 of 98 posts

Re: LibreSSL: FIPS mode is not coming back

#2
I did some consulting once for a government lab. FIPS is idiotic. It's primarily protectionism for commercial software vendors from OSS competition, and it does not improve security. If anything it hurts-- it mandates closed-source options that cannot easily be audited, and it slows down the upgrade cycle thus preventing bugs that emerge from being quickly patched.

Re: LibreSSL: FIPS mode is not coming back

#3
The OpenBSD people sure are abrasive, but they deserve a ton of praise for taking on a tough task that no one else was willing to do, and for fixing the damn mess.

Between FIPS, the NIST and the OpenSSL foundation it's amazing that crypto even works.

Re: LibreSSL: FIPS mode is not coming back

#5
This basically means libressl can not be used by the US Govt or any contractor working with the US Govt, which is a HUGE number of companies. By proxy, it means that libressl will not make its way into Fedora or RHEL, which also limits the adoption of it a fair bit.

Perhaps the solution is to fix FIPS instead of berating the people forced to use it.

Re: LibreSSL: FIPS mode is not coming back

#7
Its a reasonable stance, I expect someone will create libfipsssl for the reason that they can charge money for it. For a while at Sun I suggested that we meet the "OSI Network Standards" requirement by just sending a library with stubs that would close out the link, and if they ever got called email us. The humor didn't seem to reasonate with the Federal Systems people :-)

Re: LibreSSL: FIPS mode is not coming back

#8
post #5

This basically means libressl can not be used by the US Govt or any contractor working with the US Govt, which is a HUGE number of companies. By proxy, it means that libressl will not make its way into Fedora or RHEL, which also limits the adoption of it a fair bit. Perhaps the solution is to fix FIPS instead of berating the people forced to use it.

I'm sure Red Hat has the money to pay someone to implement FIPS for their port.

Re: LibreSSL: FIPS mode is not coming back

#9
post #5

This basically means libressl can not be used by the US Govt or any contractor working with the US Govt, which is a HUGE number of companies. By proxy, it means that libressl will not make its way into Fedora or RHEL, which also limits the adoption of it a fair bit. Perhaps the solution is to fix FIPS instead of berating the people forced to use it.

Yes, and the way to fix FIPS is to refuse to support it until it gets fixed.

Re: LibreSSL: FIPS mode is not coming back

#10
post #5

This basically means libressl can not be used by the US Govt or any contractor working with the US Govt, which is a HUGE number of companies. By proxy, it means that libressl will not make its way into Fedora or RHEL, which also limits the adoption of it a fair bit. Perhaps the solution is to fix FIPS instead of berating the people forced to use it.

I don't think lobbying the US Federal government is in OpenBSD developers' wheelhouse. Contractors working with the US government on the other hand have a long, distinguished history of successfully doing just that. In fact, that's largely the entire business model.

So it makes a lot of sense for each party to do what they are good at: OpenBSD developers write a clean, secure library, and contractors lobby to be allowed to use it.

Post reply on HN