7 ms·
If you're stuck with FIPS 140-2, you should probably have someone on your payroll to answer your questions instead of an Internet document given to the broader
by CiPHPerCoder 9y ago
If you're stuck with FIPS 140-2, you should probably have someone on your payroll to answer your questions instead of an Internet document given to the broader audience of software developers.
- Spooky23 9y agoI suppose that’s is one way to look at it. Guidance from experts from a use case perspective is difficult to find, as documentation is always product centric. Additionally, many members of the HN community have exposure they aren’t aware of. If you represent that you “encrypt” data, many organizations consider data that isn’t FIPS unencrypted. A password database compromise of your scrypt protected passwords may be a problem if you just accept boilerplate terms when selling a few licenses to state, local or federal customers.
- CiPHPerCoder 9y agoHere's an idea: Wrap securely encrypted data in FIPS certified encryption. FIPS-140-2: "Use AES" So: aes_cbc_encrypt(crypto_secretbox(message, nonce, k1), iv, k2)