Skip to main content
Federal Information Processing Standards

Federal Information Processing Standards

Search complete. 48 mentions across 23 episodes found for "Federal Information Processing Standards".

Sep 30, 2026

George MichaelsonHOST
16:07
HSMs, they have this set of levels you can operate in, and you really do want to know the implications of the level you run in.
George MichaelsonHOST
16:16
And I believe the KSK operates in FIPS, so Federal Information Processing Standard, FIPS 120 Level 2.
George MichaelsonHOST
16:25
And it's a mode which allows you to take a key and send it to another of exactly the same generation.
George MichaelsonHOST
16:31
using special keys to protect it in transit between the two machines.
Sanjeev BhaskarGUEST
16:37
understanding that you must protect that data now and have it stay confidential because there's a risk if it's stolen now, it may be decrypted later.
Sanjeev BhaskarGUEST
16:46
So once we have come up on an agreement that Q-Day is coming and we must update our cryptography, the next question is, how do we do it? NIST has published the FIP standards or the Federal Information Processing Standards publicly.
Sanjeev BhaskarGUEST
17:02
identifying opportunities, in this case, we refer to them as FIPS 203, 204, 205, that you see on your computer right here, a variety of algorithms that are approved for protecting against quantum computing, in essence, PQC algorithms.
Sanjeev BhaskarGUEST
17:18
So without going into much detail, you'll see they have different algorithms First off, labels, names, numbers, and purposes.
BrookeHOST
44:31
Hopefully, they get rid of Hopefully they get rid of the no programmable thing.
BrookeHOST
44:36
Hopefully they get rid of the whole FIPS thing.
BrookeHOST
44:39
And hopefully they get rid of the FedRAMP requirement, you know, or at the very least allow FedRAMP 20X, you know.
BrookeHOST
44:49
But, you know, if they can do those three things and then back off on the number of assessors that is required, who knows? I mean, that'll go a long way to helping out.
Nick KuhnGUEST
4:12
So you're gonna be highly regulated.
Nick KuhnGUEST
4:14
You're gonna have to deal with, you know, potential, like, you know, PCI or SOX compliance or HIPAA or, uh, FIPS or, you know, and I could probably go on and on about all the different compliance tiers that you would have to deal with.
Nick KuhnGUEST
4:26
So it's just a whole different ball game where, you know, you could potentially do something that has, uh, dramatic consequences and, um, you have a, you know, highly controlled, highly regulated environment where even some of the customers I work with are, like, you know, they actually have the real air gap where we're, like, we're carrying in things, you know, physically into the data center, uh, because there is no internet access type of thing.
Nick KuhnGUEST
4:47
So it's-
David PollakGUEST
17:47
You have, you know, RSA 4096 certs.
David PollakGUEST
17:50
Great, they're FIPS 140 compliant.
David PollakGUEST
17:53
Or you have RSA 1024 certs, which are not FIPS compliant.
David PollakGUEST
17:58
Okay, you want to know that.
David PollakGUEST
17:59
And finally, how is your application actually using the cryptography and can your application be adjusted based on the new cryptographic material that it may be seeing? Sorry, was that a long prattle or did that answer your C-bomb question?

37 MINS LATER

David PollakGUEST
55:16
That's one of the lessons.
David PollakGUEST
55:18
It's the analog to the IPv6.
David PollakGUEST
55:20
We are going to go through that, and we need to know the libraries, and we also, whatever libraries, you know, the FIPS, what is it, 203, 204, and 205 certified libraries, those are going to change in five years because there are going to be weaknesses discovered.
Matt TreinerHOST
14:42
So I think this is a good lead.
Matt TreinerHOST
14:44
And people have talked about this with FIPS adoption for years of like how inherently FIPS is an anti-pattern.
Matt TreinerHOST
14:50
Like if there's a zero day in a crypto algorithm, which Heartbleed, it existed, right? And then it was like, well, you can't use the secure one because FIPS hasn't validated it yet.
Matt TreinerHOST
15:01
And that's like, that's really at the bit and byte level in software development.
Matt TreinerHOST
15:04
But as you get up towards infrastructure and, as the difference between software and infrastructure get really really blended with these hyperscale cloud environments even the regional versions of them which might only have a subset or might work in a weirdly different way we're still at a point now where it's our expectation that software and infrastructure can converge in ways that even five years ago would have seemed to be like Not five years ago, that wasn't insane, but it definitely wasn't assumed to be the way to do it.
Dan SheldonGUEST
35:02
Yeah.
Dan SheldonGUEST
35:03
And this is really scary for organizations that are dealing with PII or GDPR or PCI, FIPS, ISO, all of those regulatory compliance suites that are trying to keep heavily protected information heavily protected.
Dan SheldonGUEST
35:22
So right now you have actors that they get access to a stream.
Dan SheldonGUEST
35:25
They're basically recording it at a packet level, downloading all of that, and they're saving it for years until they can decrypt it.
Cory MissimoreGUEST
17:59
couple of things that we all about look for is first watch for other algorithms failing.
Cory MissimoreGUEST
18:03
So what I mean by that is So NIST has, for years now, been evaluating some post-conversion algorithms, and they got through years of testing, rounds of review, and we now have FIPS 203, 204, 205, which are very specific post-conversion algorithms that people can begin to utilize in Migrate 2.
Cory MissimoreGUEST
18:25
Now, two other encryptions being valued are Hawk and Falcon.
Cory MissimoreGUEST
18:30
Hawk was recently broken by a classical computer powered by an AI, Mythos.
Cory MissimoreGUEST
17:59
couple of things that we all about look for is first watch for other algorithms failing.
Cory MissimoreGUEST
18:03
So what I mean by that is So NIST has, for years now, been evaluating some post-conversion algorithms, and they got through years of testing, rounds of review, and we now have FIPS 203, 204, 205, which are very specific post-conversion algorithms that people can begin to utilize in Migrate 2.
Cory MissimoreGUEST
18:25
Now, two other encryptions being valued are Hawk and Falcon.
Cory MissimoreGUEST
18:30
Hawk was recently broken by a classical computer powered by an AI, Mythos.
Bill DockeryGUEST
28:48
Cause yeah, I, I think that, uh, I don't want to say they approve.
Bill DockeryGUEST
28:55
They're FIPS, right? So it's a recommendation at the end of the day.
Bill DockeryGUEST
28:59
So what the government does and what other governments are doing, too, by the way, because NIST is, you know, U.S.-based. There's Canadian and name a country.
Bill DockeryGUEST
29:06
They all have their own encryption that they're trying to use.
Bill DockeryGUEST
30:58
You have to implement it.
Bill DockeryGUEST
30:59
You have to implement it in their code.
Scott RobohnHOST
31:01
The FIPS standards and NIST standards give you, here's the algorithm and here are the parameters.
Scott RobohnHOST
31:06
Yes.

13 more episodes mention Federal Information Processing Standards.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.