frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

WolfGuard: WireGuard with FIPS 140-3 cryptography

https://github.com/wolfssl/wolfguard
31•789c789c789c•1h ago

Comments

AaronFriel•56m ago
The conventional wisdom in cryptography is that if you don't know you need FIPS, if you don't have paper and a dollar figure telling you how much you need it, you don't need or want FIPS.
elevation•40m ago
Wireguard exemplifies the superiority of a qualified independent developer over the fractal layers of ossified cruft that you get from industry efforts and compliance STIGS.

So it feels wrong to see wireguard adapted for compliance purposes. If compliance orgs want superior technology, let their standards bodies approve/adopt wireguard without modifying it.

LtWorf•23m ago
but wolfssl is in the business of selling FIPS compliance so…
alfanick•21m ago
And they do it fast, thankfully Compliant Static Code Analyser catches issues like https://github.com/wolfSSL/wolfGuard/commit/fa21e06f26de201b...
jmclnx•6m ago
Yes, but be aware, openvpn is much better if you live in a Country like China, Russia and a few others. That is due to a a known design issue with wireguard.

For most people, wireguard is fine.

LunaSea•2m ago
Could you expand on the design flaw in question?
dmbche•3m ago
> fractal layers of ossified cruft Someone got a thesaurus in their coffee today! (Not a jab)
pphysch•39m ago
Can't you also get FIPS 140-3 WireGuard by compiling wireguard-go with the new native FIPS support in Go?
inahga•29m ago
The ciphers used by WireGuard are not FIPS 140-3 certified. So you have to also change the ciphers, as is done in this project.
loeg•10m ago
E.g., ChaPoly AEAD -> AES-GCM, Blake2s -> SHA2/3, that kind of thing.
PunchyHamster•26m ago
So a step backward in security ?
kstrauser•19m ago
In fairness, modern versions of FIPS are much less awful. AFAICT it's now possible to be FIPS compliant and meet reasonable crypto expectations, which was not always the case before.
loeg•8m ago
It's fine. None of the FIPS algorithms are known to be broken, either. The only risk here is implementation bugs doing the conversion and any maintenance burden incurred due to diverging from upstream wireguard.
usui•21m ago
I know software developers complain about forced compliance due to the security theatre aspects, but I would like to charitably ask from someone who has technical understanding of FIPS-compliant cryptography. Are there any actual security advantages on technical grounds for making WireGuard FIPS-compliant? Assume the goal is not to appease pencil pushers. I really want to know if this kind of effort has technical gains.
alfanick•20m ago
I presume it's a product strategy to provide a box of "compliant" libraries/services, so other companies can quickly tick and sign a checkbox saying "we use compliant VPN", because someone else is going to look whether the checkbox is ticked and signed, because someone else is going to...
NewJazz•16m ago
You failed to answer the question. Why did you reply?
loeg•15m ago
There is no security advantages or technical grounds for using FIPS algorithms in a WireGuard clone instead of Chacha / Blake2. It's purely a compliance move. ChaPoly, Blake2, etc, are not known to be broken and we have every reason to believe they are strong.
briandw•9m ago
[delayed]

How to Build a PMF Machine

https://speedrun.substack.com/p/how-to-build-a-pmf-machine
1•babelfish•48s ago•0 comments

Fitbit Data Sheds Light on Best Time to Exercise

https://nautil.us/fitbit-data-sheds-light-on-best-time-to-exercise-1279140
1•Brajeshwar•2m ago•0 comments

OpenWonton: Nomad-Compatible Workload Orchestrator

https://github.com/openwonton/openwonton
1•InitEnabler•2m ago•0 comments

Richland Correctional Institution rehabilitates animals and people

https://www.ashlandsource.com/2025/10/17/prison-opossums-how-richland-correctional-institution-is...
1•pavel_lishin•3m ago•0 comments

Who Makes What, and Where with the US ISP CPE Supply Chain

https://www.senki.org/operators-security-toolkit/us-isp-cpe-supply-chain/
1•speckx•4m ago•0 comments

The US bans all new foreign-made network routers

https://www.engadget.com/big-tech/the-us-bans-all-new-foreign-made-network-routers-223622966.html
3•ZunarJ5•4m ago•0 comments

Why Performance Reviews Need a Makeover

https://www.ft.com/content/c3d40d72-3c91-4dbe-9c48-a8f2940cc147
1•karakoram•5m ago•1 comments

PBMs Extract $30B/Year from Drug Prices (Data Analysis)

https://andrewrexroad.substack.com/p/the-middlemen
1•rexroad•5m ago•0 comments

ARM to make processors for first time in their history

https://newsroom.arm.com/news/arm-agi-cpu-launch
1•nateguchi•5m ago•0 comments

Welp, I Bought an iPhone Again

https://www.theverge.com/tech/899602/best-phone-android-ios-app-store
1•coloneltcb•7m ago•0 comments

Elon Musk Announces $20B 'Terafab' Chip Plant in Texas to Supply His Companies

https://www.kvue.com/article/tech/elon-musk-announces-chip-plant-austin-travis-county-texas/269-f...
1•m463•7m ago•0 comments

Arm Holdings, in Break from Past, Will Sell Its Own Computer Chips

https://www.nytimes.com/2026/03/24/technology/arm-holdings-sell-chips.html
2•donohoe•7m ago•0 comments

What up world -Systems Cat here with a query

1•CentralPlexus•8m ago•0 comments

A Solid Education Starts with Facts

https://www.restoringthewest.com/p/a-solid-education-starts-with-facts
1•mpweiher•9m ago•0 comments

Software Engineering Has Been Commoditized and Automated. What's Next?

https://www.eetimes.com/software-engineering-has-been-commoditized-and-automated-whats-next
1•ua709•9m ago•0 comments

Yann LeCun's research team trains stable JEPA from pixels on one GPU

https://le-wm.github.io/?lid=h11EVOyjVZPe220i
1•linkregister•9m ago•0 comments

Addressing global removal race in Wayland

https://blog.vladzahorodnii.com/2026/03/24/addressing-global-removal-race-in-wayland/
1•TangerineDream•9m ago•0 comments

Apple Is Set to Put Ads in Apple Maps in Services Push

https://www.bloomberg.com/news/articles/2026-03-23/apple-is-set-to-add-search-advertising-to-maps...
2•thisislife2•10m ago•0 comments

Iranian strikes on Amazon data centers highlight industry's vulnerability

https://apnews.com/article/amazon-aws-data-center-uae-iran-bahrain-71066b0a822c4cfd88b61e3fe79af917
3•rurp•11m ago•0 comments

My practical guide for optimizing docs for agents

https://promptless.ai/blog/technical/agent-docs/
1•frances-liu•11m ago•0 comments

TrajectoryKit, a competitive open-source deep research agent without fine-tuning

https://www.williamlugoloobi.com/blog/building-trajectorykit
1•stansApprentice•12m ago•0 comments

AI2 MolmoWeb: An open agent for automating web tasks

https://allenai.org/blog/molmoweb
4•publicdiego•12m ago•0 comments

A Million Young Britons Are Falling Through the Cracks

https://www.ft.com/content/a9d8cbdc-fe26-4a83-b6b5-ee9820ce7f0c
2•karakoram•13m ago•1 comments

Gökçe Güven – Another Forbes 30U30 Facing Prison

https://nymag.com/intelligencer/article/gokce-guven-forbes-30-under-30-kalder-indictment.html
1•karakoram•14m ago•1 comments

Intel Binary Optimization Tool: Enhanced Performance for Gaming

https://www.intel.com/content/www/us/en/support/articles/000102604/processors.html
1•pieterr•16m ago•0 comments

Antimatter has been transported for the first time ever – in the back of a truck

https://www.nature.com/articles/d41586-026-00950-w
1•tzury•17m ago•0 comments

No Signs of AI Replacing Offshore Workers

https://www.apolloacademy.com/no-signs-of-ai-replacing-offshore-workers/
3•akyuu•18m ago•1 comments

Official CLI for Resend

https://resend.com/changelog/cli
1•goldkey•18m ago•0 comments

Building a Blog with Elixir and Phoenix

https://jola.dev/posts/building-a-blog-with-elixir-and-phoenix
3•shintoist•19m ago•1 comments

Security vendor slams supplier for delayed notice after staff data exposed

https://www.theregister.com/2026/03/24/hackerone_supplier_breach/
2•sillywabbit•19m ago•0 comments