Why FIPS 140 Means Running Old Code

🫧 Open on Bubbles You need to use FIPS 140 because of compliance, but have you ever asked what that requirement is actually for? What security properties are the authors of these policies trying to achieve? In high-assurance deployments, the practical goal is usually to establish a meaningful security boundary around cryptographic keys. Organizations want explicit controls over who and what can use a key, and they do not want the answer to be every application or administrator with access to the host. They

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论