[110456] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Flaws in OpenSSL FIPS Object Module

daemon@ATHENA.MIT.EDU (Ed Gerck)
Tue Dec 11 13:25:08 2007

Date: Mon, 10 Dec 2007 11:56:40 -0800
From: Ed Gerck <edgerck@nma.com>
To: cryptography@metzdowd.com
In-Reply-To: <200712101628.lBAGSYqM020475@TheWorld.com>

Vin McLellan wrote:
> 
> What does it say about the integrity of the FIPS program, and its CMTL 
> evaluation process, when it is left to competitors to point out 
> non-compliance of evaluated products -- proprietary or open source -- to 
> basic architectural requirements of the standard?

Enter Reality 2.0. Yesterday, security was based on authority --
on some particular agency or expert. Today, security is /also/ based
on anyone else that can point out non-compliance, and solutions.

The integrity of the FIPS program, and any other evaluation process,
can only increase when [x] are also able (entirely on their own and
not by a mandate) to point out non-compliance of evaluated products
-- proprietary or open source -- to basic architectural requirements
of the standard. Here [x] = competitors, attackers, outside experts,
anyone in general.

Cheers,
Ed Gerck

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post