So a step backward in security ?
WolfGuard: WireGuard with FIPS 140-3 cryptography
11–20 of 65 posts
Re: WolfGuard: WireGuard with FIPS 140-3 cryptography
#12I know software developers complain about forced compliance due to the security theatre aspects, but I would like to charitably ask from someone who has technical understanding of FIPS-compliant cryptography. Are there any actual security advantages on technical grounds for making WireGuard FIPS-compliant? Assume the goal is not to appease pencil pushers. I really want to know if this kind of effort has technical gai…
I presume it's a product strategy to provide a box of "compliant" libraries/services, so other companies can quickly tick and sign a checkbox saying "we use compliant VPN", because someone else is going to look whether the checkbox is ticked and signed, because someone else is going to...
Re: WolfGuard: WireGuard with FIPS 140-3 cryptography
#13I know software developers complain about forced compliance due to the security theatre aspects, but I would like to charitably ask from someone who has technical understanding of FIPS-compliant cryptography. Are there any actual security advantages on technical grounds for making WireGuard FIPS-compliant? Assume the goal is not to appease pencil pushers. I really want to know if this kind of effort has technical gai…
Re: WolfGuard: WireGuard with FIPS 140-3 cryptography
#14Can't you also get FIPS 140-3 WireGuard by compiling wireguard-go with the new native FIPS support in Go?
The ciphers used by WireGuard are not FIPS 140-3 certified. So you have to also change the ciphers, as is done in this project.
Re: WolfGuard: WireGuard with FIPS 140-3 cryptography
#15I know software developers complain about forced compliance due to the security theatre aspects, but I would like to charitably ask from someone who has technical understanding of FIPS-compliant cryptography. Are there any actual security advantages on technical grounds for making WireGuard FIPS-compliant? Assume the goal is not to appease pencil pushers. I really want to know if this kind of effort has technical gai…
Re: WolfGuard: WireGuard with FIPS 140-3 cryptography
#16So a step backward in security ?
Re: WolfGuard: WireGuard with FIPS 140-3 cryptography
#17Wireguard exemplifies the superiority of a qualified independent developer over the fractal layers of ossified cruft that you get from industry efforts and compliance STIGS. So it feels wrong to see wireguard adapted for compliance purposes. If compliance orgs want superior technology, let their standards bodies approve/adopt wireguard without modifying it.
For most people, wireguard is fine.
Edit: I should have said "choice" instead of "issue", but Firefox 140 is failing on this site so I could not correct the txt. I was able to edit this after reverting back to Firefox 128.
Re: WolfGuard: WireGuard with FIPS 140-3 cryptography
#18Wireguard exemplifies the superiority of a qualified independent developer over the fractal layers of ossified cruft that you get from industry efforts and compliance STIGS. So it feels wrong to see wireguard adapted for compliance purposes. If compliance orgs want superior technology, let their standards bodies approve/adopt wireguard without modifying it.
Someone got a thesaurus in their coffee today! (Not a jab)
Re: WolfGuard: WireGuard with FIPS 140-3 cryptography
#19Wireguard exemplifies the superiority of a qualified independent developer over the fractal layers of ossified cruft that you get from industry efforts and compliance STIGS. So it feels wrong to see wireguard adapted for compliance purposes. If compliance orgs want superior technology, let their standards bodies approve/adopt wireguard without modifying it.
Yes, but be aware, openvpn is much better if you live in a Country like China, Russia and a few others. That is due to a known design issue with wireguard. For most people, wireguard is fine. Edit: I should have said "choice" instead of "issue", but Firefox 140 is failing on this site so I could not correct the txt. I was able to edit this after reverting back to Firefox 128.
Re: WolfGuard: WireGuard with FIPS 140-3 cryptography
#20Earlier quoted context omitted.
Yes, but be aware, openvpn is much better if you live in a Country like China, Russia and a few others. That is due to a known design issue with wireguard. For most people, wireguard is fine. Edit: I should have said "choice" instead of "issue", but Firefox 140 is failing on this site so I could not correct the txt. I was able to edit this after reverting back to Firefox 128.
Could you expand on the design flaw in question?
>OpenVPN does not store any of your private data, including IP addresses, on VPN servers, which is ideal.
https://www.pcmag.com/comparisons/openvpn-vs-wireguard-which...