> the symbols in your tester2 program account for ~67kb out of a 2.3mb binary
OP did find a "600k difference" in an unstripped comparison but if binary size was critical enough that 600k was a big deal, I'd assume users would be stripping the binaries outright or using a different language (tinygo perhaps) if a <100kb diff was on their list of concerns.
eqvinox 11 hours ago [-]
From having had my own prior interactions with you, I am entirely unsurprised that you're getting some cold shoulder due to other people's experiences with you.
As far as I can tell you're great at cryptography code. You've gotten better at the social parts of collaborative software engineering, but there's still room to grow.
pamcake 2 hours ago [-]
What's up with all the likes, urgency, and pressure? Is this part of some kind of operation?
clivedup 3 hours ago [-]
It's been 2-4d since a maintainer replied. Why escalate the situation by trying to raise HN attention to it?
westurner 2 days ago [-]
Isn't there still need for non- or post- FIPS-140 -like cipher restrictions in non FIPS-140 environments?
How much code is needed to implement Classical+PQ (Hybrid PQ) or PQ-only (Only PQ) cipher selection restrictions just?
FWIU, with golang:
# This allows X25519MLKEM768 (Hybrid PQ)
GODEBUG=fips140=on
# This prevents any PQ ciphers from being used:
GODEBUG=fips140=only
tlsref needs to be revised to specify PQ cipher lists.
twiss 7 hours ago [-]
FIPS-140 doesn't yet require PQC, nor does Go in FIPS mode (or any other mode).
> the symbols in your tester2 program account for ~67kb out of a 2.3mb binary
OP did find a "600k difference" in an unstripped comparison but if binary size was critical enough that 600k was a big deal, I'd assume users would be stripping the binaries outright or using a different language (tinygo perhaps) if a <100kb diff was on their list of concerns.
As far as I can tell you're great at cryptography code. You've gotten better at the social parts of collaborative software engineering, but there's still room to grow.
How much code is needed to implement Classical+PQ (Hybrid PQ) or PQ-only (Only PQ) cipher selection restrictions just?
FWIU, with golang:
tlsref needs to be revised to specify PQ cipher lists.So, if you only want PQC, you'll have to do that manually either way. But, I think you'll find many servers aren't ready for that: https://www.netmeister.org/blog/pqc-use-2026-09.html