Risk

9/27/2018
12:15 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Blue Cedar Teams Up with OpenSSL, Akamai, NetApp, VMware to Build Next-Gen FIPS Module

New FIPS Module for OpenSSL will democratize access to widely used cryptographic library.

SAN FRANCISCO, September 27, 2018 – Blue Cedar today announced it has joined an industry initiative to develop the next-generation open-source FIPS 140-2 module for OpenSSL. Blue Cedar will collaborate with established industry leaders, including Open SSL, Akamai, NetApp, and VMware, in the effort to upgrade and improve secure data transfers using the OpenSSL cryptographic library. Updating the open source FIPS 140-2module, which is currently used by millions of web servers and internet-connected devices, will make it easier for companies to comply with the ubiquitous TLS and SSL open source cryptographic standards. 

FIPS (Federal Information Processing Standard) 140-2 is the widely accepted certification standard used by government agencies, financial, healthcare, and other industries as the de facto standard for certification of the cryptographic modules used within commercial and open source products. FIPS 140-2 certification ensures strong and validated cryptographic protection for data at rest and data in transit across networks. 

The current FIPS 140-2 module for OpenSSL is overdue for an upgrade. The last significant update was in 2012, and encryption standards have evolved considerably since then. Until a FIPS 140-2 validated cryptographic module is available for OpenSSL, federal agencies and organizations are forced to rely on older, less secure implementations of OpenSSL.

“Today, if a small company wishes to engage with a government, bank, or healthcare system, it can do one of two things to meet the FIPS 140-2 certification requirement: build its own cryptographic library or buy one at great expense,” said Kevin Fox, CTO at Blue Cedar. “We are proud to be joining with other key players in the Free and Open Source Security (FOSS) community to develop an option that will maintain an open standard with truly secure cryptography that is accessible to all.”

Blue Cedar, which specializes in powerful, in-app security solutions that protect mobile and other edge apps and data whenever and wherever they are used, is contributing its expertise and other resources to the FIPS 140-2 module development effort. Last month, an expert team of Blue Cedar security engineers took part in a face-to-face meeting in Brisbane, Australia where members of the consortium and partner organizations focused on a modernized implementation of FIPS 140-2 that can support the community now and in the future.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
12 Free, Ready-to-Use Security Tools
Steve Zurier, Freelance Writer,  10/12/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.
CVE-2018-18375
PUBLISHED: 2018-10-16
goform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via the rand parameter.
CVE-2018-18376
PUBLISHED: 2018-10-16
goform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected devices (hostnames, IP addresses, MAC addresses, and connection time) via the rand parameter.