Hacker News new | ask | show | jobs
by gruez 3886 days ago
Hexview provided their reason for believing that. Care to explain why you think otherwise?
1 comments

Original quote:

>That is not a big deal, considering that Levels 1 and 2 of the FIPS140-2 certification are just a marketing gimmick for most electronic devices.

They have a point here: technically, the iPhone is FIPS140-1/2 compliant. By itself, that doesn't mean that the device is secure. It does show two important requirements for security.

FIPS isn't trivial. There is a lot of shit crypto on the market, establishing FIPS is not banal. Regardless of FIPS, if not utilized properly, it protects nothing. If utilized correctly, it protects what it needs to. Discounting it show lack of understanding.
A little education goes a long way: http://csrc.nist.gov/groups/STM/cmvp/