Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I seem to remember that WolfSSL had some fairly egregious vulnerabilities even while being FIPS certified.

Do you have some reason to believe that WolfSSL has suddenly gotten better for some reason?



For one thing, they are rather transparent:

https://www.wolfssl.com/docs/security-vulnerabilities/

For another, I used them for an embedded project for 5 years and they were the most complete, competent, and up-to-date library of the open-source ones we surveyed (and had a TON of optimizations for TI, STM, Arm and Cavium MCUs).


Per my understanding, FIPS certification only guarantees the crypto implementation does what it is supposed to do and nothing else. If implementation has language-specific vulnerabilities (like buffer overflow, memory management issues), then FIPS is not designed to catch these.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: