HeadlinesBriefing favicon HeadlinesBriefing.com

FIPS 140-3: A Certification, Not a Security Guarantee

Hacker News •
×

FIPS 140-3 certification confirms a cryptographic module's compliance but does not ensure overall system security. Many organizations disable FIPS mode despite purchasing certified HSMs, as the certification only validates specific cryptographic algorithms and configurations. NIST’s certification process is a snapshot, binding to exact firmware and configurations, which often become outdated as systems evolve.

Historical flaws like ROCA, EUCLEAK, and Dual_EC_DRBG demonstrate that certified modules can harbor vulnerabilities for years. The 2019 Yubi Key FIPS Series incident revealed certified devices could be less secure than non-certified models. The certification process is slow, with vendors choosing to ship flawed but validated builds to avoid losing certification.

Go’s native cryptographic module, validated in 2024, now runs outdated code due to the certification freeze. FIPS compliance is a procurement requirement, not a security assurance, and its limitations must be understood.