You've invested heavily in your FIPS efforts over the years, so you should understand as much as anyone that it undermines the program to misrepresent capabilities with inaccurate marketing messaging.
Attention @kingstontech & @helpnetsecurity - You can't "deliver FIPS 140-3 Level 3" until you actually have a #FIPS140 validation posted by @NIST. Your announcement is misleading and requires revision.
You're still in 'Coordination' status, @EclypsesInc. And only just got there a couple weeks ago.
Why double down on inaccurate claims, @brychampagne? And @apexaiq looks bad now too.
Everyone who misrepresents #FIPS140 undermines the entire program.
https://t.co/WJxQbvYRBd
We would ask you for your #FIPS140 validation certificate number to verify your claims, @EclypsesInc... except we both know that there aren't any 140-3 validations yet. https://t.co/3W7qKQ46Q2
We wish you a safe and successful 2022, Happy New Year!
Learn how our patented, FIPS 140-3 validated MTE technology replaces your data with instantly obsolete random streams of values and restores it on the other side: https://t.co/pnhX4fJrqz
#NewYear#mobileappsecurity
Further, you mention that it is "compliant with 140, Level 3". Compliant is not the same as certified or validated. And 140-3 is not the same as Level 3.
The vendor, @BenQEurope, has responsibility to fact-check, but you should also ensure that your language is accurate when it comes to technical language.
Your article mentions that the WDC30 contains a "FIPS 140-3-certified crypto module" which is impossible - no vendor has achieved a 140-3 validation yet, it's still too new!
C'mon, @KIOXIAAmerica. There are literally zero #FIPS140-3 validations completed yet, so there is also zero chance that you can honestly announce the "CM6 Series Enterprise NVMe SSDs (with FIPS 140-3 security module validation)" as part of your plans for #HPEDiscover.
Leveraging the #FIPS140 validated BoringCrypto module is a great strategy, but @HashiCorp PR ran wild on this one. Please issue corrections. This is embarrassing.
Hey @HashiCorp - We love your initiative getting a letter to show 3rd party review and confirmation that your product can properly implement a #FIPS140 validated BoringCrypto module... BUT your press release is terribly misleading and straight-up wrong.
โThe certification of FIPS 140-2 within Vault Enterprise demonstrates our continued investment and commitment to these customers.โ c'mon @0xtbt, this is your quote and you should know the difference.
The folks at @WolfSSL have blocked this account, but you should be wondering how they can tweet triumphantly that they have just submitted their module for 140-3 and still not retract their previous claims of being first to achieve validation. #FIPS140
https://t.co/2xcxO768rX
@nozominetworks#FIPS140 "compliant" is just a claim. There's no validation behind it, so those #federal customers that you mention aren't assured at all. In fact, they're not supposed to procure your solution unless/until you actually complete the certification. Step up!