• Hacker News
  • new|
  • comments|
  • show|
  • ask|
  • jobs|
  • meehow 1 hours

    [dead]

  • afarah1 26 minutes

    Huh, I don't know about the world of HSMs or crypto and their audits, but in FedRAMP SaaS, you absolutely have to run everything with FIPS mode enabled, there are strong guarantees that need to be in place and audited.

    bb88 8 minutes

    If the requirement causes a massive security hole, the lawyers will probably tell you that knowingly allowing a security hole from a liability perspective is worse than turning off something an audit will flag.

  • sublinear 36 minutes

    Why does the tone have to be ragebait? This is just a basic overview of what compliance looks like.

    PunchyHamster 24 minutes

    because for most use cases FIPS-140 have been waste of time for everyone involved

    sscaryterry 23 minutes

    At this point, I'd rather be waterboarded than do any more compliance. Especially in this heat.