2 ms·
How is that “a problem with FIPS?” In layman’s terms that basically says if there’s a 0-day, patch first and we’ll worry about validation later. You could say
by tw04 2mo ago
How is that “a problem with FIPS?”
In layman’s terms that basically says if there’s a 0-day, patch first and we’ll worry about validation later.
You could say that’s “an issue” with literally every software package that has a support contract on earth. I can’t count how many times in my career we had to apply a patch release that wasn’t “officially ga” because of a zero day. That’s common sense, not a FIPS issue.
- rileymat2 2mo agoIf our need to update fips certified packages out paces the ability to certify packages, that is absolutely a problem with the design of FIPs certifications.
- beardedwizard 2mo ago+1, been all the way to fed ramp high and this is a huge part of the security theater that is fedramp. The second best part is either getting really good at patching every single thing, or playing the POA&M game.
- pseudohadamard 2mo agoSo your choice inevitably boils down to running some ancient vulnerability-riddled version that's FIPS certified or running a recent less vulnerability-riddled version that's not certified. Most orgs that I've worked with keep running the vulnerable version because they have to be able to check the box that says "FIPS certified".