« BackFIPS dependencies and prebuilt binariesdocker.comSubmitted by LaurentGoderre 2 hours ago
  • direwolf20 an hour ago

    FIPS compliance should be used when the customer demands FIPS compliance, and at no other time. It does not make your software more secure. The federal government has many reasons for its Information Processing Standards, and actual security isn't high up the list.

    • JasonADrury an hour ago

      > FIPS compliance is a great idea that makes the entire software supply chain safer

      Yes, gotta implement that Dual_EC_DRBG compatibility.

      FIPS compliance is not a great idea, the benefits are questionable and possibly nonexistent. It's also significantly worse advice than simple "implement decent modern crypto", you can do all kinds of really bizarre stuff and still be FIPS compliant.