Article may be outdated

This article is 57 days old. Some details may have changed since publication.

Hacker News·5 min read·hard

FIPS 140-3 is not a security guarantee, and auditors know it

M
meehow
✦AI Summary

This analysis argues that FIPS 140-3 certification is often misunderstood as a comprehensive security guarantee rather than a narrow validation of cryptographic modules. The author notes that many organizations purchase certified hardware but fail to operate it in the validated configuration, rendering the certification ineffective.

Why it matters

It challenges the industry reliance on compliance certifications as a substitute for actual security engineering and rigorous risk management.

✦Dive DeeperCreate a free account to unlock

A sales engineer at one of the major HSM vendors told me recently that over 90 percent of their customers who buy FIPS-enabled HSMs run them with FIPS mode disabled . They pay a premium for the certificate, then switch off the configuration it describes. By the end of this article you will understand why that is often the correct engineering decision.

On September 21, 2026, every remaining FIPS 140-2 certificate moves to NIST's historical list , and modules on that list should no longer be included in new federal procurements . Procurement teams are spending this summer chasing vendors for FIPS 140-3 paper, and vendors are spending it in a validation queue. A lot of money and attention is flowing toward a certificate.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in