5 ms·
There is also a large difference between FIPS compliant and FIPS certified. The former is running in FIPS mode and the latter is running a cryptographic module
by walth 3y ago
There is also a large difference between FIPS compliant and FIPS certified. The former is running in FIPS mode and the latter is running a cryptographic module that has been inspected and verified by the CMVP.
And then the whole thing is really terrible security theater as you are technically out of certification if you apply any non-inspected updates.
- p_l 3y agoOpenSSL 3 made a huge improvements in getting oneself FIPS certified, by isolating the FIPS-covered code to small auditable module that doesn't have to be updated all that much, thus letting you update OpenSSL in general while retaining CMVP-verified crypto. Now, getting it into some of the open source code was a PITA, especially when you have things like components that depended on MD5 somewhere...
- hedora 3y agoI’ve heard this approach called the “draw an imaginary and arbitrary box in your architecture diagram” approach to FIPS compliance. Fun fact: the fips compliant stuff doesn’t have to be on the data path if you draw the rectangle correctly. In other news, my smart refrigerator has military grade encryption, so no one can steal my sandwich.
- wahern 3y ago> And then the whole thing is really terrible security theater as you are technically out of certification if you apply any non-inspected updates. The days when FIPS compliance required using relatively weak ciphers and modes were lamentable. But all the other tedious box checking work arguably shows that cipher bike shedding is the real security theater. If you don't have a plan--and follow that plan--to track software origins and updates, or an ability to quickly resolve dependency issues that make it difficult to refactor or even update your systems, then you have much bigger problems than whether your latest software is using the Noise protocol or has migrated from BLAKE2 to BLAKE3. Which is not to say that maintaining FIPS certification or FedRAMP compliance equates to good security. It's trivial to identify simplifications that would result in better operational security. But the vast majority of projects and organizations struggling to meet those standards are struggling precisely because their security posture is horrendously poor when looked at comprehensively.
- somat 3y agoThe saying goes something like. Good operational security will get you through times of bad crypto. But the converse is not true. Good crypto will not save you from bad opsec.
- cqqxo4zV46cp 3y agoThe typical person with a geeky interest in security will dig their heels in quite a bit when faced with the reality that most effort does, and should, go toward boring operational opsec.
- tguvot 3y ago>And then the whole thing is really terrible security theater as you are technically out of certification if you apply any non-inspected updates. FedRAMP now prefers to use non-certified updates to been certified but vulnerable. Especially when fips module comes from company that has a "proven track record of obtaining certification"