3 ms·
From my PoV, FIPS is bureaucratic nonsense and people trusting in it deserve what they are getting. It might have had sense a long time ago, to ensure that ven
by dpc_pw 6y ago
From my PoV, FIPS is bureaucratic nonsense and people trusting in it deserve what they are getting.
It might have had sense a long time ago, to ensure that vendors don't do something ridiculous and call it a day. It does mandate certain thing that are common sense and good practice, yes. But you can't really mandate security via a checklists from 10 years ago. Government can't keep up with cryptography, software bugs being discovered, new threats and so on. It's just too slow, and requires more than just going through a checklist.
The exact details of how things are done at the lower level are simply insane. It's very common that the FIPS-certified product has security strictly lower than non certified one, e.g. because the certified FIPS base had bugs, that are known, trivial to get fixed (3-liners, etc) but can't because that would take months/years and hundreds of thousands of dollars to re-certify the whole codebase being patched.
The whole thing was probably created by lobbyists to create another corrupted channel to monopolize and overcharge government and related institutions, just like many other nonsensical laws in the US.