Federal Information Processing Standards
48
MENTIONS
23
EPISODES
21
PODCASTS
Search complete. 48 mentions across 23 episodes found for "Federal Information Processing Standards".
Sep 30, 2026
The October 2026 Root KSK roll
G
16:07George MichaelsonHOST
HSMs, they have this set of levels you can operate in, and you really do want to know the implications of the level you run in.
G
16:16George MichaelsonHOST
And I believe the KSK operates in FIPS, so Federal Information Processing Standard, FIPS 120 Level 2.
G
16:25George MichaelsonHOST
And it's a mode which allows you to take a key and send it to another of exactly the same generation.
G
16:31George MichaelsonHOST
using special keys to protect it in transit between the two machines.
The New Technology Frontier: Quantum, AI, & National Security
S
16:37Sanjeev BhaskarGUEST
understanding that you must protect that data now and have it stay confidential because there's a risk if it's stolen now, it may be decrypted later.
S
16:46Sanjeev BhaskarGUEST
So once we have come up on an agreement that Q-Day is coming and we must update our cryptography, the next question is, how do we do it? NIST has published the FIP standards or the Federal Information Processing Standards publicly.
S
17:02Sanjeev BhaskarGUEST
identifying opportunities, in this case, we refer to them as FIPS 203, 204, 205, that you see on your computer right here, a variety of algorithms that are approved for protecting against quantum computing, in essence, PQC algorithms.
S
17:18Sanjeev BhaskarGUEST
So without going into much detail, you'll see they have different algorithms First off, labels, names, numbers, and purposes.
SPRS Scoring Explained in Plain English: How the 110-to-Negative-203 Scale Works and How to Fix a Bad Score
B
44:31BrookeHOST
Hopefully, they get rid of Hopefully they get rid of the no programmable thing.
B
44:36BrookeHOST
Hopefully they get rid of the whole FIPS thing.
B
44:39BrookeHOST
And hopefully they get rid of the FedRAMP requirement, you know, or at the very least allow FedRAMP 20X, you know.
B
44:49BrookeHOST
But, you know, if they can do those three things and then back off on the number of assessors that is required, who knows? I mean, that'll go a long way to helping out.
From AGENTS.md to Enterprise Deployment
N
4:12Nick KuhnGUEST
So you're gonna be highly regulated.
N
4:14Nick KuhnGUEST
You're gonna have to deal with, you know, potential, like, you know, PCI or SOX compliance or HIPAA or, uh, FIPS or, you know, and I could probably go on and on about all the different compliance tiers that you would have to deal with.
N
4:26Nick KuhnGUEST
So it's just a whole different ball game where, you know, you could potentially do something that has, uh, dramatic consequences and, um, you have a, you know, highly controlled, highly regulated environment where even some of the customers I work with are, like, you know, they actually have the real air gap where we're, like, we're carrying in things, you know, physically into the data center, uh, because there is no internet access type of thing.
N
4:47Nick KuhnGUEST
So it's-
The BOM Explosion & Why PQC Stopped Being 10 Years Away with David Pollak & Allan Friedman
D
17:47David PollakGUEST
You have, you know, RSA 4096 certs.
D
17:50David PollakGUEST
Great, they're FIPS 140 compliant.
D
17:53David PollakGUEST
Or you have RSA 1024 certs, which are not FIPS compliant.
D
17:58David PollakGUEST
Okay, you want to know that.
D
17:59David PollakGUEST
And finally, how is your application actually using the cryptography and can your application be adjusted based on the new cryptographic material that it may be seeing? Sorry, was that a long prattle or did that answer your C-bomb question?
37 MINS LATER
D
55:16David PollakGUEST
That's one of the lessons.
D
55:18David PollakGUEST
It's the analog to the IPv6.
D
55:20David PollakGUEST
We are going to go through that, and we need to know the libraries, and we also, whatever libraries, you know, the FIPS, what is it, 203, 204, and 205 certified libraries, those are going to change in five years because there are going to be weaknesses discovered.
Secure Software Development
M
14:42Matt TreinerHOST
So I think this is a good lead.
M
14:44Matt TreinerHOST
And people have talked about this with FIPS adoption for years of like how inherently FIPS is an anti-pattern.
M
14:50Matt TreinerHOST
Like if there's a zero day in a crypto algorithm, which Heartbleed, it existed, right? And then it was like, well, you can't use the secure one because FIPS hasn't validated it yet.
M
15:01Matt TreinerHOST
And that's like, that's really at the bit and byte level in software development.
M
15:04Matt TreinerHOST
But as you get up towards infrastructure and, as the difference between software and infrastructure get really really blended with these hyperscale cloud environments even the regional versions of them which might only have a subset or might work in a weirdly different way we're still at a point now where it's our expectation that software and infrastructure can converge in ways that even five years ago would have seemed to be like Not five years ago, that wasn't insane, but it definitely wasn't assumed to be the way to do it.
Just In Time Networking For Agentic AI with EVA Networks
D
35:02Dan SheldonGUEST
Yeah.
D
35:03Dan SheldonGUEST
And this is really scary for organizations that are dealing with PII or GDPR or PCI, FIPS, ISO, all of those regulatory compliance suites that are trying to keep heavily protected information heavily protected.
D
35:22Dan SheldonGUEST
So right now you have actors that they get access to a stream.
D
35:25Dan SheldonGUEST
They're basically recording it at a packet level, downloading all of that, and they're saving it for years until they can decrypt it.
Quantum Computing Risk: What Internal Auditors Need to Know
C
17:59Cory MissimoreGUEST
couple of things that we all about look for is first watch for other algorithms failing.
C
18:03Cory MissimoreGUEST
So what I mean by that is So NIST has, for years now, been evaluating some post-conversion algorithms, and they got through years of testing, rounds of review, and we now have FIPS 203, 204, 205, which are very specific post-conversion algorithms that people can begin to utilize in Migrate 2.
C
18:25Cory MissimoreGUEST
Now, two other encryptions being valued are Hawk and Falcon.
C
18:30Cory MissimoreGUEST
Hawk was recently broken by a classical computer powered by an AI, Mythos.
Quantum Computing Risk: What Internal Auditors Need to Know
C
17:59Cory MissimoreGUEST
couple of things that we all about look for is first watch for other algorithms failing.
C
18:03Cory MissimoreGUEST
So what I mean by that is So NIST has, for years now, been evaluating some post-conversion algorithms, and they got through years of testing, rounds of review, and we now have FIPS 203, 204, 205, which are very specific post-conversion algorithms that people can begin to utilize in Migrate 2.
C
18:25Cory MissimoreGUEST
Now, two other encryptions being valued are Hawk and Falcon.
C
18:30Cory MissimoreGUEST
Hawk was recently broken by a classical computer powered by an AI, Mythos.
HN842: How Network Engineers Can Prepare for a Post-Quantum World
B
28:48Bill DockeryGUEST
Cause yeah, I, I think that, uh, I don't want to say they approve.
B
28:55Bill DockeryGUEST
They're FIPS, right? So it's a recommendation at the end of the day.
B
28:59Bill DockeryGUEST
So what the government does and what other governments are doing, too, by the way, because NIST is, you know, U.S.-based. There's Canadian and name a country.
B
29:06Bill DockeryGUEST
They all have their own encryption that they're trying to use.
B
30:58Bill DockeryGUEST
You have to implement it.
B
30:59Bill DockeryGUEST
You have to implement it in their code.
S
31:01Scott RobohnHOST
The FIPS standards and NIST standards give you, here's the algorithm and here are the parameters.
S
31:06Scott RobohnHOST
Yes.
13 more episodes mention Federal Information Processing Standards.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.