Could this all be a positive thing if it promotes development of open source libraries and tools ?
Not only that, but I wander how feasible is to create binary APIs for most operating systems and CPU architectures, where you could download, verify (that they were build from a commit id of some know open source implementation), and plug in crypto modules as binaries.
So you buy your software from any vendor, any country. If they implement the use of this API, then get your verified crypto modules and plug them in. Or you build your own in house from source.
I can see how that mechanism would of course be a massive attack target by all kinds of actors, but in theory is that possible? Maybe make it decentralized as much as possible.
Not only that, but I wander how feasible is to create binary APIs for most operating systems and CPU architectures, where you could download, verify (that they were build from a commit id of some know open source implementation), and plug in crypto modules as binaries.
So you buy your software from any vendor, any country. If they implement the use of this API, then get your verified crypto modules and plug them in. Or you build your own in house from source.
I can see how that mechanism would of course be a massive attack target by all kinds of actors, but in theory is that possible? Maybe make it decentralized as much as possible.