Remix.run Logo
FIPS 140-3 is not a security guarantee, and auditors know it(808bits.com)
14 points by meehow an hour ago | 5 comments
afarah1 17 minutes ago | parent | next [-]

Huh, I don't know about the world of HSMs or crypto and their audits, but in FedRAMP SaaS, you absolutely have to run everything with FIPS mode enabled, there are strong guarantees that need to be in place and audited.

sublinear 27 minutes ago | parent | prev | next [-]

Why does the tone have to be ragebait? This is just a basic overview of what compliance looks like.

sscaryterry 14 minutes ago | parent | next [-]

At this point, I'd rather be waterboarded than do any more compliance. Especially in this heat.

PunchyHamster 15 minutes ago | parent | prev [-]

because for most use cases FIPS-140 have been waste of time for everyone involved

meehow an hour ago | parent | prev [-]

[dead]