Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


my goth gf posted:

what's a fips

a miserable pile of standards




according to google anyway because i don't actuallu know

Adbot
ADBOT LOVES YOU

Shame Boy
Mar 2, 2010

power botton posted:

A bunch of our customers love FIPS mode and last year we finally updated all our poo poo so that it would work with FIPS enabled and I have no clue what it does but its very important to the enterprise

i turned it on in thunderbird once just to see what it did and then could never turn it back off again the whole time i used it and it didn't seem to do anything except break some features

Shaggar
Apr 26, 2006
fips is a collection of now out of date crypto standards the feds require for any software they buy. unless you're selling to the feds you don't want to use fips.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
if i had to guess i'd say a soc auditor said we should be using it

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

my goth gf posted:

what's a fips
as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

Shaggar posted:

fips is a collection of now out of date crypto standards the feds require for any software they buy. unless you're selling to the feds you don't want to use fips.

And idiots think it is Bible for what they need to adopt in their organisation even if they have no real reason to

minivanmegafun
Jul 27, 2004

Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

Kuvo
Oct 27, 2008

Blame it on the misfortune of your bark!
Fun Shoe

Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

:drat:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/matthew_d_green/status/860237158447271938

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
behind the shitposts: i set up my computer to turn "flipmode" into "ɟlıdmode" which made it hard to search for

Midjack
Dec 24, 2007



Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

Shaggar
Apr 26, 2006

Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/taviso/status/860679110728622080

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
it's tavis time motherfuckers

ate shit on live tv
Feb 15, 2004

by Azathoth

Is it RDP? I bet it's RDP.

Maybe SMB?

Let's go Old School with a new twist, UDP packet Fragments -> buffer overrun, but the packets are IPv6!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

ate poo poo on live tv posted:

Is it RDP? I bet it's RDP.

Maybe SMB?

Let's go Old School with a new twist, UDP packet Fragments -> buffer overrun, but the packets are IPv6!
https://twitter.com/taviso/status/860681252034142208

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice
my body is ready

redleader
Aug 18, 2005

Engage according to operational parameters
turn all computers off imo

Asshole Masonanie
Oct 27, 2009

by vyelkin

redleader posted:

turn all computers off imo

no truer words

Zil
Jun 4, 2011

Satanically Summoned Citrus


redleader posted:

turn all computers off imo

but how will we poo poo post?

Wiggly Wayne DDS
Sep 11, 2010



any bets on expected patch time? time to public disclosure from patch hitting a server? sudden pull of the update after it's been reversed due to no qa?

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

Meat Beat Agent posted:

it's tavis time motherfuckers

A Pinball Wizard posted:

my body is ready

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

Zil posted:

but how will we poo poo post?

smoke signals

akadajet
Sep 14, 2003

Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

Phone
Jul 30, 2005

親子丼をほしい。

Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

Storysmith
Dec 31, 2006

Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"



secfuck thread bringing the hits
:five::five::five:

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
having worked with military customers in the past idk what the fuss is about fips mode just disables some poo poo and requires that all certs be generated with that poo poo disabled.

on the other hand now i occasionally have to deal with SMB customers so i imagine when i tell them that they need to hire a dedicated computer toucher they hire some fuckwit who wasnt in the military but worked with peeps who got their gi bill and went on to be successful computer touchers after their stint touching computers in the military and heard said successful person mention fips as a requirement for miltiary networks at some point.

what im tryna say is

MILITARY.

GRADE.

ENCRYPTION.

customer confidence inspired.

Moo Cowabunga
Jun 15, 2009

[Office Worker.




Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

ErIog
Jul 11, 2001

:nsacloud:

Zil posted:

but how will we poo poo post?

my goth gf posted:

smoke signals

smoke fart signals

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

anatoliy pltkrvkay posted:

having worked with military customers in the past idk what the fuss is about fips mode just disables some poo poo and requires that all certs be generated with that poo poo disabled.

on the other hand now i occasionally have to deal with SMB customers so i imagine when i tell them that they need to hire a dedicated computer toucher they hire some fuckwit who wasnt in the military but worked with peeps who got their gi bill and went on to be successful computer touchers after their stint touching computers in the military and heard said successful person mention fips as a requirement for miltiary networks at some point.

what im tryna say is

MILITARY.

GRADE.

ENCRYPTION.

customer confidence inspired.

it's really in vogue with uk banks and corporates too, probably because of those three magic words. it's not actually a bad baseline as such things go (god knows it's better than how the majority of companies have things set up), it's just like ten years out of date.

Carbon dioxide
Oct 9, 2012

https://img-9gag-fun.9cache.com/photo/ajXGN30_460sv.mp4

flakeloaf
Feb 26, 2003

Still better than android clock

goddamnedtwisto posted:

it's really in vogue with uk banks and corporates too, probably because of those three magic words. it's not actually a bad baseline as such things go (god knows it's better than how the majority of companies have things set up), it's just like ten years out of date.

it's something policymakers can turn into a checklist

that's really all

pairofdimes
May 20, 2001

blehhh

goddamnedtwisto posted:

it's really in vogue with uk banks and corporates too, probably because of those three magic words. it's not actually a bad baseline as such things go (god knows it's better than how the majority of companies have things set up), it's just like ten years out of date.

The base document is old, but stuff like the approved ciphers are kept at least somewhat up to date (http://csrc.nist.gov/publications/fips/fips140-2/fips1402annexa.pdf)

Even some of the requirements of the base standard aren't bad, it includes things like requiring the use of a good source of entropy for your crypto system, something that is easy to screw up on things like embedded devices, verification that all the ciphers/hashes/etc are implemented correctly. The problems are more with the certification itself which has some big problems:

1. It's really complicated. FIPS 140-2 is only 70 pages, but to actually pass certification there's info scattered in a bunch of other places, like the annex above, or the implementation guide that's over 1000 pages last I checked. This means you'll probably need a consultant that keeps up with everything just to pass.

2. Certification is really slow. I don't know what the backlog is now, but in the past it was 9+ months from when you submitted your documents to when you actually got certified assuming no problems were found.

3. You have to follow the product's security policy in order it to actually use it in the correct way. Since as others have mentioned this is just a checklist item for most companies, they probably aren't actually doing this. I recall hearing one time that Cisco sold way more FIPS boxes than security kits, meaning that most of those devices were not running in an approved manner.

4. This is a really big one, but once you've gotten certification you can not make any changes within the cryptographic boundary. If you do the new code/device is not considered certified. Find a security flaw and fix it? That new version is not certified even though it's objectively more secure. I think this is gotten around sometimes by saying that the new version is based on a FIPS version, but it's stupid that something like that can even happen. IIRC this may stem from the standard before FIPS 140 being only for hardware devices where respinning a chip was way less common than making a software change.

Anyway I don't do FIPS anymore so none of this is my problem now.

vOv
Feb 8, 2014

https://twitter.com/bcrypt/status/860735972756963328

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

what

vOv
Feb 8, 2014


tavis tweeted that he figured out a key part of one of his lastpass exploits in the shower

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Cocoa Crispies posted:

as a shorty playing in group policy settings
fell down and i deleted my cipher suite
somebody helped me up and asked me if i deleted my cipher suite
i said "yeah"
so then they said "oh so that mean we gon, you gon switch it on then?"
i said "yeah, fipsmode, fipsmode is the greatest"

Adbot
ADBOT LOVES YOU

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

vOv posted:

tavis tweeted that he figured out a key part of one of his lastpass exploits in the shower

oh haha, i remember that

  • Locked thread