Skip to content

Zero of 773 FIPS 140-3 certificates are validated at Level 4

808bits.com
7 pointsmeehow3 comments
On HN

Comments

That's not surprising. FIPS 140 is primary a signalling mechanism for how desperate you are to sell to the USG and USG-affiliated organisations, not a security indicator. Only a company prepared to set fire to $100k or more gets to play.

And if you're a hardware vendor, you have to set fire to $300-400k because to play there you need to be level 3. Levels 2 and 4 may as well not exist because you need 1 for software and 3 for hardware, why would any company set fire to more money than they need to to get their ticket to ride? It's not like we're talking about AI here.

All the really high end stuff is in financial data centers anyway, surrounded by TV cameras 24/7. Tamper reactance in the HSM itself is cool and everything but the surrounding security handles a lot of what the HSM is made to do.

Side-channel ignorance: none of the SW solutions are properly zeroing the data. Side-channels can still read them. SW vendors refuse to do that because of performance. Clearing the caches is too expensive.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.