Hacker News new | ask | show | jobs
by tptacek 4807 days ago
FIPS 140-2 is very narrowly constrained and the parts that aren't crypto-related are the same kind of boilerplate make-work that EAL2/EAL3 is. But also bear in mind that you can pull a list of EAL4+ products right now, and quickly see how many of them have had ridiculous vulnerabilities.