Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I did some consulting once for a government lab. FIPS is idiotic. It's primarily protectionism for commercial software vendors from OSS competition, and it does not improve security. If anything it hurts-- it mandates closed-source options that cannot easily be audited, and it slows down the upgrade cycle thus preventing bugs that emerge from being quickly patched.


> It's primarily protectionism

This. It's also protectionism for government IA managers. And it stymies the hell out of anyone trying to do research on a budget, which often depends on open source (for both review, quality and cost reasons).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: