• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: [Fed-Talk] CoreCrypto / CoreCrypto Kernel now in "In - Review" (CMVP)
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Fed-Talk] CoreCrypto / CoreCrypto Kernel now in "In - Review" (CMVP)


  • Subject: Re: [Fed-Talk] CoreCrypto / CoreCrypto Kernel now in "In - Review" (CMVP)
  • From: "Marcus, Allan B" <email@hidden>
  • Date: Mon, 11 Feb 2013 22:37:31 +0000
  • Thread-topic: [Fed-Talk] CoreCrypto / CoreCrypto Kernel now in "In - Review" (CMVP)

Good news Shawn, but what will it mean when iOS is FIPS compliant? Will is mean that when a program uses core crypto it's FIPS compliant? How will we end users be able to know if an app is using core crypto in a FIPS compliant state?

Or will it mean there will be a way to turn FIPS compliant encryption on for the whole device? By this I mean with a "pre-use" authentication? Even with a password now I can access any non-encrypted data on the device before the password is entered (with out jailbreaking, simply by using a USB cable and freeware device access software) 

-- 
Thanks,

Allan Marcus
Chief IT Architect
Los Alamos National Laboratory
505-667-5666
email@hidden

From: Shawn Geddis <email@hidden>
Date: Monday, February 11, 2013 12:53 PM
To: Fed Talk <email@hidden>
Subject: [Fed-Talk] CoreCrypto / CoreCrypto Kernel now in "In - Review" (CMVP)

Fed-Talk Community,

Many of you ask on a regular basis what the status is on the Validation of the Crypto Modules used within OS X and iOS.  If you take a look at the weekly posted PDF from CMVP, you will see that all four of these modules have now been moved to "in-Review" which means that the validation has been assigned to someone within CMVP and has finally made its way out of the backlog queue after 6 months + 1 week with no CMVP activity. 

http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140InProcess.pdf

So there is hope before the next turn of the century....but, Validation Process Reform is sorely needed.

- Shawn
________________________________________
Shawn Geddis   
Security Consulting Engineer 
Apple Enterprise Division

 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:

This email sent to email@hidden

  • Next by Date: [Fed-Talk] Federal groups using Caper for management?
  • Next by thread: Re: [Fed-Talk] CoreCrypto / CoreCrypto Kernel now in "In - Review" (CMVP)
  • Index(es):
    • Date
    • Thread