Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The likelihood of them ever having the cryptographic components of ScreenOS competently audited is very low.

Most firms didn't even start getting basic software security assessments done until ~5 years ago, and almost nobody gets crypto reviews done (crypto reviews are nosebleed expensive, because only a tiny fraction of software security people can do them competently).



This might be a stupid question, but if they're using their own values, wouldn't this have triggered issues during a FIPS assessment?

ScreenOS has been FIPS-140 validated a couple of times in the last 10 years...


No, you're allowed to use your own values.

Also: FIPS validation isn't particularly meaningful. It's not like a serious crypto assessment.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: