Remix.run Logo
dlgeek an hour ago

FedRAMP actually has a bunch of workarounds for the problems of FIPS.

In the "FedRAMP Policy for Cryptographic Module Selection and Use" (https://www.fedramp.gov/resources/documents/FedRAMP_Policy_f...), there are a ton of gems that make it clear that the FedRAMP folks are fed up with the CMVP process backlog. The most explicit is:

"FRR9: CSPs shall determine if updating to a newer version of the software, whether or not its cryptographic modules are FIPS validated, would eliminate the vulnerabilities; if it would, CSPs shall promptly update if that is feasible."

tw04 7 minutes ago | parent [-]

How is that “a problem with FIPS?”

In layman’s terms that basically says if there’s a 0-day, patch first and we’ll worry about validation later.

You could say that’s “an issue” with literally every software package that has a support contract on earth. I can’t count how many times in my career we had to apply a patch release that wasn’t “officially ga” because of a zero day. That’s common sense, not a FIPS issue.