frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

FIPS dependencies and prebuilt binaries

https://www.docker.com/blog/fips-dependencies-and-prebuilt-binaries/
17•LaurentGoderre•2h ago
Author here. This came out of debugging a real Rails app running in a FIPS enabled container.

Everything looked correct. OpenSSL 3 with the FIPS provider enabled. Ruby built against it. A simple pg connection worked.

The app failed once ActiveRecord was involved. The error came from libpq. It turned out the pg gem had pulled in a prebuilt native dependency that was linked against different crypto. That path was always there. It just was not exercised until ActiveRecord hit it.

Forcing a source build fixed the issue because the extension then linked against the OpenSSL in the image.

The takeaway is that a FIPS base image does not mean your dependency graph respects the same boundary once native code is involved.

Curious how others have seen this play out in Ruby, Python wheels, Go with CGO, or Node native addons.

Comments

JasonADrury•1h ago
> FIPS compliance is a great idea that makes the entire software supply chain safer

Yes, gotta implement that Dual_EC_DRBG compatibility.

FIPS compliance is not a great idea, the benefits are questionable and possibly nonexistent. It's also significantly worse advice than simple "implement decent modern crypto", you can do all kinds of really bizarre stuff and still be FIPS compliant.

pixl97•17m ago
>FIPS compliance is not a great idea, the benefits are questionable and possibly nonexistent.

I counter about the benefits of FIPS. If you don't do it, you don't get paid by the government for whatever contract you have. Many people find getting paid to be beneficial.

Now, it's not the vast majority of applications, but I'm sure there are a significant number of developers on HN that are working on applications that need to meet FedRamp requirements and posts like this point out potential pitfalls on what needs enabled.

Not much different when dealing with stuff like STIGs. A large number of them are highly questionable and may only apply to very specific applications, yet you see barely trained button pushers saying you need to follow them. If you're aware of them when writing your application it will save a bunch of implementation headaches when it ends up in the field.

direwolf20•1h ago
FIPS compliance should be used when the customer demands FIPS compliance, and at no other time. It does not make your software more secure. The federal government has many reasons for its Information Processing Standards, and actual security isn't high up the list.
voidfunc•28m ago
FIPS is what happens when idiots get promoted and start reading too much LinkedIn CISO slop.

If a customer demands FIPS compliance charge them out the ass for it. Its not inherently secure, it requires in some cases massive re-engineering of product and toolchains, and mostly seems to be an ask from clueless deep pocketed Fortune 500 companies looking to minimize liability claims after a breach by being able to point at their FIPS compliance.

GPTZero finds 100 new hallucinations in NeurIPS 2025 accepted papers

https://gptzero.me/news/neurips/
685•segmenta•9h ago•375 comments

Show HN: isometric.nyc – giant isometric pixel art map of NYC

https://cannoneyed.com/isometric-nyc/
618•cannoneyed•8h ago•150 comments

Capital One to acquire Brex for $5.15B

https://www.reuters.com/legal/transactional/capital-one-buy-fintech-firm-brex-515-billion-deal-20...
95•personjerry•3h ago•60 comments

Why does SSH send 100 packets per keystroke?

https://eieio.games/blog/ssh-sends-100-packets-per-keystroke/
266•eieio•5h ago•177 comments

I was banned from Claude for scaffolding a Claude.md file?

https://hugodaniel.com/posts/claude-code-banned-me/
322•hugodan•6h ago•257 comments

100x (YC S22) Is Hiring a Technical Content Creator

https://100x.bot/creator-program
1•shardullavekar•14m ago

Why medieval city-builder video games are historically inaccurate (2020)

https://www.leidenmedievalistsblog.nl/articles/why-medieval-city-builder-video-games-are-historic...
29•benbreen•52m ago•6 comments

Improving the usability of C libraries in Swift

https://www.swift.org/blog/improving-usability-of-c-libraries-in-swift/
27•timsneath•1h ago•0 comments

Qwen3-TTS family is now open sourced: Voice design, clone, and generation

https://qwen.ai/blog?id=qwen3tts-0115
458•Palmik•11h ago•138 comments

Turso is an in-process SQL database, compatible with SQLite

https://github.com/tursodatabase/turso
23•marklit•3d ago•7 comments

Anthropic Economic Index economic primitives

https://www.anthropic.com/research/anthropic-economic-index-january-2026-report
45•malshe•3h ago•33 comments

Douglas Adams on the English–American cultural divide over "heroes"

https://shreevatsa.net/post/douglas-adams-cultural-divide/
314•speckx•11h ago•342 comments

Composing APIs and CLIs in the LLM era

https://walters.app/blog/composing-apis-clis
26•zerf•8h ago•4 comments

My first year in sales as technical founder

https://www.fabiandietrich.com/blog/first-year-in-sales.html
65•f3b5•5d ago•24 comments

Vibe a Guitar Pedal

https://polyend.com/endless/
7•mulhoon•46m ago•4 comments

Compiling Scheme to WebAssembly

https://eli.thegreenplace.net/2026/compiling-scheme-to-webassembly/
64•chmaynard•5d ago•10 comments

CSS Optical Illusions

https://alvaromontoro.com/blog/68091/css-optical-illusions
132•ulrischa•7h ago•12 comments

'Active' sitting is better for brain health: review of studies

https://www.sciencealert.com/not-all-sitting-is-equal-one-type-was-just-linked-to-better-brain-he...
66•mikhael•6h ago•29 comments

Your app subscription is now my weekend project

https://rselbach.com/your-sub-is-now-my-weekend-project
202•robteix•4d ago•159 comments

Recent discoveries on the acquisition of the highest levels of human performance

https://www.science.org/doi/abs/10.1126/science.adt7790
100•colincooke•7h ago•46 comments

Metastable Failures and Interactions Between Systems

https://charap.co/on-metastable-failures-and-interactions-between-systems/
5•PaulHoule•59m ago•0 comments

Rate Limiting, Cells, and GCRA

https://brandur.org/rate-limiting
4•panic•6d ago•0 comments

'Askers' vs. 'Guessers' (2010)

https://www.theatlantic.com/national/2010/05/askers-vs-guessers/340891/
78•BoorishBears•13h ago•52 comments

Extracting a UART Password via SPI Flash Instruction Tracing

https://zuernerd.github.io/blog/2026/01/07/switch-password.html
34•Eduard•3h ago•6 comments

Tree-sitter vs. Language Servers

https://lambdaland.org/posts/2026-01-21_tree-sitter_vs_lsp/
207•ashton314•10h ago•55 comments

In Europe, wind and solar overtake fossil fuels

https://e360.yale.edu/digest/europe-wind-solar-fossil-fuels
472•speckx•11h ago•492 comments

FIPS dependencies and prebuilt binaries

https://www.docker.com/blog/fips-dependencies-and-prebuilt-binaries/
17•LaurentGoderre•2h ago•4 comments

Keeping 20k GPUs healthy

https://modal.com/blog/gpu-health
85•jxmorris12•4d ago•37 comments

Scaling PostgreSQL to power 800M ChatGPT users

https://openai.com/index/scaling-postgresql/
24•mustaphah•3h ago•7 comments

A Year of 3D Printing

https://brookehatton.com/blog/making/a-year-of-3d-printing/
86•nindalf•5d ago•87 comments