Hacker News new | ask | show | jobs
by AaronFriel 84 days ago
The conventional wisdom in cryptography is that if you don't know you need FIPS, if you don't have paper and a dollar figure telling you how much you need it, you don't need or want FIPS.
2 comments

FIPS just locks you into a specific (generally fairly old) version of everything and sets some more annoying defaults. The only benefit is to be able to check a box on a form saying you qualify.
It's not just that, would you rely on crypto code from Jason Donenfeld or crypto code from "all the CVEs" WolfSSL, https://www.wolfssl.com/docs/security-vulnerabilities/?
FIPS is pain