[109752] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Flaws in OpenSSL FIPS Object Module

daemon@ATHENA.MIT.EDU (Paul Hoffman)
Mon Dec 3 16:52:32 2007

In-Reply-To: <87d4tnlt9r.fsf@snark.cb.piermont.com>
Date: Mon, 3 Dec 2007 07:51:47 -0800
To: "Perry E. Metzger" <perry@piermont.com>, cryptography@metzdowd.com
From: Paul Hoffman <paul.hoffman@vpnc.org>

At 9:58 AM -0500 12/3/07, Perry E. Metzger wrote:
>I don't know if people have been following this, but it is interesting
>from the point of view of studying how the FIPS process does (or does
>not) interact with the underlying goal of producing assured systems.

Another interesting part is that open-source systems are much more 
susceptible to being attacked by competitors (that is, having their 
validation suspended) than are closed-source systems.

--Paul Hoffman, Director
--VPN Consortium

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post