<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>nist &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/nist/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Thu, 20 Nov 2025 22:55:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>Introducing the Landing Zone Accelerator on AWS Universal Configuration and LZA Compliance Workbook</title>
		<link>https://noise.getoto.net/2025/11/21/introducing-the-landing-zone-accelerator-on-aws-universal-configuration-and-lza-compliance-workbook/</link>
		
		<dc:creator><![CDATA[Kevin Donohue]]></dc:creator>
		<pubDate>Thu, 20 Nov 2025 22:55:20 +0000</pubDate>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[AWS Shared Responsibility Model]]></category>
		<category><![CDATA[C5]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[hipaa]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=48542fedab25e33613418e212a204230</guid>

					<description><![CDATA[We’re pleased to announce the availability of the latest sample security baseline from Landing Zone Accelerator on AWS (LZA)—the Universal Configuration. Developed from years of field experience with highly regulated customers including governments across the world, and in consultation with AWS Partners and industry experts, the Universal Configuration was built to help you implement security […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Everything you need to know about NIST’s new guidance in “SP 1800-35: Implementing a Zero Trust Architecture”</title>
		<link>https://noise.getoto.net/2025/06/19/everything-you-need-to-know-about-nists-new-guidance-in-sp-1800-35-implementing-a-zero-trust-architecture/</link>
		
		<dc:creator><![CDATA[Aaron McAllister]]></dc:creator>
		<pubDate>Thu, 19 Jun 2025 13:00:00 +0000</pubDate>
				<category><![CDATA[Cloudflare Zero Trust]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Zero-Trust]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=43e6fbb9bfd52345e79a3b1ce3133c57</guid>

					<description><![CDATA[We read NIST’s new guidance on “Implementing a Zero-Trust Architecture” so that you don’t have to.  Read this to get the key points on the newly-released NIST Special Publication 1800-35.]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>A Taxonomy of Adversarial Machine Learning Attacks and Mitigations</title>
		<link>https://noise.getoto.net/2025/03/27/a-taxonomy-of-adversarial-machine-learning-attacks-and-mitigations/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 27 Mar 2025 11:00:32 +0000</pubDate>
				<category><![CDATA[machine learning]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[taxonomies]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=70050</guid>

					<description><![CDATA[NIST just released a comprehensive taxonomy of adversarial machine learning attacks and countermeasures.
]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Updated whitepaper available: Aligning to the NIST Cybersecurity Framework in the AWS Cloud</title>
		<link>https://noise.getoto.net/2025/01/29/updated-whitepaper-available-aligning-to-the-nist-cybersecurity-framework-in-the-aws-cloud/</link>
		
		<dc:creator><![CDATA[Luca Iannario]]></dc:creator>
		<pubDate>Tue, 28 Jan 2025 22:13:02 +0000</pubDate>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[CSF]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Cybersecurity Framework]]></category>
		<category><![CDATA[Federal Information Security Modernization Act]]></category>
		<category><![CDATA[FISMA]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[National Institute of Standards and Technology]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[NIST CSF]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=fb4b9a0dc09599fe79d2b9571a850bd3</guid>

					<description><![CDATA[Today, we released an updated version of the Aligning to the NIST Cybersecurity Framework (CSF) in the AWS Cloud whitepaper to reflect the significant changes introduced in the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) 2.0, published in February 2024. This comprehensive update helps you understand how AWS services align with the […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>AWS-LC FIPS 3.0: First cryptographic library to include ML-KEM in FIPS 140-3 validation</title>
		<link>https://noise.getoto.net/2024/12/10/aws-lc-fips-3-0-first-cryptographic-library-to-include-ml-kem-in-fips-140-3-validation/</link>
		
		<dc:creator><![CDATA[Jake Massimo]]></dc:creator>
		<pubDate>Tue, 10 Dec 2024 16:28:08 +0000</pubDate>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Federal Information Processing Standard]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[post quantum]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=586e82f740e1016d0c0f98ad279650f6</guid>

					<description><![CDATA[We’re excited to announce that AWS-LC FIPS 3.0 has been added to the National Institute of Standards and Technology (NIST) Cryptographic Module Validation Program (CMVP) modules in process list. This latest validation of AWS-LC introduces support for Module Lattice-Based Key Encapsulation Mechanisms (ML-KEM), the new FIPS standardized post-quantum cryptographic algorithm. This is a significant step towards enhancing the […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>NIST Recommends Some Common-Sense Password Rules</title>
		<link>https://noise.getoto.net/2024/09/27/nist-recommends-some-common-sense-password-rules/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 27 Sep 2024 11:01:53 +0000</pubDate>
				<category><![CDATA[nist]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[reports]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69432</guid>

					<description><![CDATA[<p>NIST’s second draft of its “<a href="https://pages.nist.gov/800-63-4/sp800-63b.html">SP 800-63-4</a>“—its digital identify guidelines—finally contains some really good rules about passwords:</p>
<blockquote><p>The following requirements apply to passwords:</p>
<ol>
<li>lVerifiers and CSPs SHALL require passwords to be a minimum of eight characters in length and SHOULD require passwords to be a minimum of 15 characters in length.
</li><li>Verifiers and CSPs SHOULD permit a maximum password length of at least 64 characters.
</li><li>Verifiers and CSPs SHOULD accept all printing ASCII [RFC20] characters and the space character in passwords.
</li><li>Verifiers and CSPs SHOULD accept Unicode [ISO/ISC 10646] characters in passwords. Each Unicode code point SHALL be counted as a signgle character when evaluating password length.
...</li></ol></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>NIST’s first post-quantum standards</title>
		<link>https://noise.getoto.net/2024/08/20/nists-first-post-quantum-standards/</link>
		
		<dc:creator><![CDATA[Luke Valenta]]></dc:creator>
		<pubDate>Tue, 20 Aug 2024 13:00:39 +0000</pubDate>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[post quantum]]></category>
		<category><![CDATA[research]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=a596517eb9399dd4fd51ec0c60b03e55</guid>

					<description><![CDATA[NIST has published the first cryptographic standards for protecting against attacks from quantum computers. Learn what this means for you and your organization]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>NIST Releases First Post-Quantum Encryption Algorithms</title>
		<link>https://noise.getoto.net/2024/08/15/nist-releases-first-post-quantum-encryption-algorithms/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 15 Aug 2024 15:37:42 +0000</pubDate>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[national security policy]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[quantum computing]]></category>
		<category><![CDATA[security standards]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=69264</guid>

					<description><![CDATA[<p>From the <a href="https://www.govinfo.gov/content/pkg/FR-2024-08-14/pdf/2024-17956.pdf">Federal Register</a>:</p>
<blockquote><p>After three rounds of evaluation and analysis, NIST selected four algorithms it will standardize as a result of the PQC Standardization Process. The public-key encapsulation mechanism selected was CRYSTALS-KYBER, along with three digital signature schemes: CRYSTALS-Dilithium, FALCON, and SPHINCS+.</p></blockquote>
<p>These algorithms are part of three NIST standards that have been finalized:</p>
<ul>
<li>FIPS 203: <a href="https://csrc.nist.gov/pubs/fips/203/final">Module-Lattice-Based Key-Encapsulation Mechanism Standard</a></li>
<li>FIPS 204: <a href="https://csrc.nist.gov/pubs/fips/204/final">Module-Lattice-Based Digital Signature Standard</a></li>
<li>FIPS 205: <a href="https://csrc.nist.gov/pubs/fips/203/final">Stateless Hash-Based Digital Signature Standard...</a></li></ul>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>AWS achieves third-party attestation of conformance with the Secure Software Development Framework (SSDF)</title>
		<link>https://noise.getoto.net/2024/07/10/aws-achieves-third-party-attestation-of-conformance-with-the-secure-software-development-framework-ssdf/</link>
		
		<dc:creator><![CDATA[Hayley Kleeman Jung]]></dc:creator>
		<pubDate>Wed, 10 Jul 2024 20:11:40 +0000</pubDate>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[AWS security]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Assurance]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=78134a298104d171fbae27a7c51da5b5</guid>

					<description><![CDATA[Amazon Web Services (AWS) is pleased to announce the successful attestation of our conformance with the National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF), Special Publication 800-218. This achievement underscores our ongoing commitment to the security and integrity of our software supply chain. Executive Order (EO) 14028, Improving the Nation’s Cybersecurity […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Implementing a compliance and reporting strategy for NIST SP 800-53 Rev. 5</title>
		<link>https://noise.getoto.net/2024/06/11/implementing-a-compliance-and-reporting-strategy-for-nist-sp-800-53-rev-5/</link>
		
		<dc:creator><![CDATA[Josh Moss]]></dc:creator>
		<pubDate>Tue, 11 Jun 2024 17:06:18 +0000</pubDate>
				<category><![CDATA[automation]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[FedRAMP]]></category>
		<category><![CDATA[Intermediate (200)]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Technical How-to]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=5bb0f29b544bfa6fde8ca0796760daa7</guid>

					<description><![CDATA[Amazon Web Services (AWS) provides tools that simplify automation and monitoring for compliance with security standards, such as the NIST SP 800-53 Rev. 5 Operational Best Practices. Organizations can set preventative and proactive controls to help ensure that noncompliant resources aren’t deployed. Detective and responsive controls notify stakeholders of misconfigurations immediately and automate fixes, thus […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>NIST Cybersecurity Framework 2.0</title>
		<link>https://noise.getoto.net/2024/03/01/nist-cybersecurity-framework-2-0/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Fri, 01 Mar 2024 12:08:23 +0000</pubDate>
				<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=68557</guid>

					<description><![CDATA[<p>NIST has released <a href="https://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework">version 2.0</a> of the Cybersecurity Framework:</p>
<blockquote><p>The CSF 2.0, which supports implementation of the <a href="https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf">National Cybersecurity Strategy</a>, has an expanded scope that goes beyond protecting critical infrastructure, such as hospitals and power plants, to all organizations in any sector. It also has a new focus on governance, which encompasses how organizations make and carry out informed decisions on cybersecurity strategy. The CSF’s governance component emphasizes that cybersecurity is a major source of enterprise risk that senior leaders should consider alongside others such as finance and reputation...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Apple Announces Post-Quantum Encryption Algorithms for iMessage</title>
		<link>https://noise.getoto.net/2024/02/26/apple-announces-post-quantum-encryption-algorithms-for-imessage/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Mon, 26 Feb 2024 12:04:34 +0000</pubDate>
				<category><![CDATA[academic papers]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[cryptanalysis]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[quantum computing]]></category>
		<category><![CDATA[security standards]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=68476</guid>

					<description><![CDATA[<p>Apple announced <a href="https://security.apple.com/blog/imessage-pq3/">PQ3</a>, its post-quantum encryption standard based on the <a href="https://pq-crystals.org/kyber/">Kyber</a> secure key-encapsulation protocol, one of the post-quantum algorithms <a href="https://csrc.nist.gov/Projects/post-quantum-cryptography/selected-algorithms-2022">selected</a> by NIST in 2022.</p>
<p>There’s a lot of detail in the Apple <a href="https://security.apple.com/blog/imessage-pq3/">blog post</a>, and more in Douglas Stabila’s <a href="https://security.apple.com/assets/files/Security_analysis_of_the_iMessage_PQ3_protocol_Stebila.pdf">security analysis</a>.</p>
<p>I am of two minds about this. On the one hand, it’s probably premature to switch to any particular post-quantum algorithms. The mathematics of cryptanalysis for these lattice and other systems is still rapidly evolving, and we’re likely to break more of them—and learn a lot in the process—over the coming few years. But if you’re going to make the switch, this is an excellent choice. And Apple’s ability to do this so efficiently speaks well about its algorithmic agility, which is probably more important than its particular cryptographic design. And it is probably about the right time to worry about, and defend against, attackers who are storing encrypted messages in hopes of breaking them later on future quantum computers...</p>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>AWS Customer Compliance Guides now publicly available</title>
		<link>https://noise.getoto.net/2024/02/22/aws-customer-compliance-guides-now-publicly-available/</link>
		
		<dc:creator><![CDATA[Kevin Donohue]]></dc:creator>
		<pubDate>Thu, 22 Feb 2024 18:37:25 +0000</pubDate>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[CSF]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[hipaa]]></category>
		<category><![CDATA[IRAP]]></category>
		<category><![CDATA[ISMAP]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[NIST CSF]]></category>
		<category><![CDATA[NIST SP 800-53]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Shared Responsibility Model]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=051ecc490059c43b4f6aed88286f9ef4</guid>

					<description><![CDATA[The AWS Global Security &#38; Compliance Acceleration (GSCA) Program has released AWS Customer Compliance Guides (CCGs) on the AWS Compliance Resources page to help customers, AWS Partners, and assessors quickly understand how industry-leading compliance frameworks map to AWS service documentation and security best practices. CCGs offer security guidance mapped to 16 different compliance frameworks for more than […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Improving the Cryptanalysis of Lattice-Based Public-Key Algorithms</title>
		<link>https://noise.getoto.net/2024/02/14/improving-the-cryptanalysis-of-lattice-based-public-key-algorithms/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 14 Feb 2024 12:08:03 +0000</pubDate>
				<category><![CDATA[academic papers]]></category>
		<category><![CDATA[cryptanalysis]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[quantum computing]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=68429</guid>

					<description><![CDATA[The winner of the Best Paper Award at Crypto this year was a significant improvement to lattice-based cryptanalysis.
This is important, because a bunch of NIST&#8217;s post-quantum options base their security on lattice problems.
I worry about standard...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>AWS FedRAMP Revision 5 baselines transition update</title>
		<link>https://noise.getoto.net/2023/10/25/aws-fedramp-revision-5-baselines-transition-update/</link>
		
		<dc:creator><![CDATA[Kevin Donohue]]></dc:creator>
		<pubDate>Wed, 25 Oct 2023 13:22:37 +0000</pubDate>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[AWS (US) GovCloud]]></category>
		<category><![CDATA[AWS East/West]]></category>
		<category><![CDATA[AWS GovCloud (US)]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[Federal]]></category>
		<category><![CDATA[Federal government]]></category>
		<category><![CDATA[FedRAMP]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Shared Responsibility Model]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=6c62b246a36a7b6ca9e8b11f92f95a85</guid>

					<description><![CDATA[On May 20, 2023, the Federal Risk and Authorization Management Program (FedRAMP) released the FedRAMP Rev.5 baselines. The FedRAMP baselines were updated to correspond with the National Institute of Standards and Technology’s (NIST) Special Publication (SP) 800-53 Rev. 5 Catalog of Security and Privacy Controls for Information Systems and Organizations and SP 800-53B Control Baselines for Information Systems […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Bounty to Recover NIST’s Elliptic Curve Seeds</title>
		<link>https://noise.getoto.net/2023/10/12/bounty-to-recover-nists-elliptic-curve-seeds/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Thu, 12 Oct 2023 11:09:38 +0000</pubDate>
				<category><![CDATA[backdoors]]></category>
		<category><![CDATA[contests]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[random numbers]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=67930</guid>

					<description><![CDATA[<p><a href="https://words.filippo.io/dispatches/seeds-bounty/">This</a> is a fun challenge:</p>
<blockquote><p>The NIST elliptic curves that power much of modern cryptography were generated in the late ’90s by hashing seeds provided by the NSA. How were the seeds generated? Rumor has it that they are in turn hashes of English sentences, but the person who picked them, Dr. Jerry Solinas, passed away in early 2023 leaving behind a cryptographic mystery, some conspiracy theories, and an historical password cracking challenge.</p></blockquote>
<p>So there’s a $12K prize to recover the hash seeds.</p>
<p>Some <a href="https://news.ycombinator.com/item?id=37784499">backstory</a>:</p>
<blockquote><p>Some of the backstory here (it’s the funniest fucking backstory ever): it’s lately been circulating—though I think this may have been somewhat common knowledge among practitioners, though definitely not to me—that the “random” seeds for the NIST P-curves, generated in the 1990s by Jerry Solinas at NSA, were simply SHA1 hashes of some variation of the string “Give Jerry a raise”...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>AWS-LC is now FIPS 140-3 certified</title>
		<link>https://noise.getoto.net/2023/10/06/aws-lc-is-now-fips-140-3-certified/</link>
		
		<dc:creator><![CDATA[Nevine Ebeid]]></dc:creator>
		<pubDate>Fri, 06 Oct 2023 17:55:44 +0000</pubDate>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Federal Information Processing Standard]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=56c4a959be229dd89c54114867bc60f9</guid>

					<description><![CDATA[AWS Cryptography is pleased to announce that today, the National Institute for Standards and Technology (NIST) awarded AWS-LC its validation certificate as a Federal Information Processing Standards (FIPS) 140-3, level 1, cryptographic module. This important milestone enables AWS customers that require FIPS-validated cryptography to leverage AWS-LC as a fully owned AWS implementation. AWS-LC is an […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>You Can’t Rush Post-Quantum-Computing Cryptography Standards</title>
		<link>https://noise.getoto.net/2023/08/08/you-cant-rush-post-quantum-computing-cryptography-standards/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 08 Aug 2023 11:13:22 +0000</pubDate>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[national security policy]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[quantum computing]]></category>
		<category><![CDATA[security standards]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=67648</guid>

					<description><![CDATA[<p>I just read <a href="https://www.esecurityplanet.com/trends/nist-encryption-standards/">an article</a> complaining that NIST is taking too long in finalizing its post-quantum-computing cryptography standards.</p>
<blockquote><p>This process has been going on since 2016, and since that time there has been a huge increase in quantum technology and an equally large increase in quantum understanding and interest. Yet seven years later, we have <a href="https://www.esecurityplanet.com/trends/quantum-safe-cryptography-standards/">only four algorithms</a>, although last week NIST <a href="https://csrc.nist.gov/news/2023/additional-pqc-digital-signature-candidates">announced</a> that a number of other candidates are under consideration, a process that is expected to take “several years.</p>
<p>The delay in developing quantum-resistant algorithms is especially troubling given the time it will take to get those products to market. It generally takes four to six years with a new standard for a vendor to develop an ASIC to implement the standard, and it then takes time for the vendor to get the product validated, which seems to be taking a troubling amount of time...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>Customer Compliance Guides now available on AWS Artifact</title>
		<link>https://noise.getoto.net/2023/06/23/customer-compliance-guides-now-available-on-aws-artifact/</link>
		
		<dc:creator><![CDATA[Kevin Donohue]]></dc:creator>
		<pubDate>Fri, 23 Jun 2023 13:14:27 +0000</pubDate>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[AWS Artifact]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Department of Defense (DoD)]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[FedRAMP]]></category>
		<category><![CDATA[Foundational (100)]]></category>
		<category><![CDATA[GovCloud]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[hipaa]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[Public Sector]]></category>
		<category><![CDATA[Secret]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Security, Identity & Compliance]]></category>
		<category><![CDATA[Shared Responsibility Model]]></category>
		<category><![CDATA[SOC]]></category>
		<guid isPermaLink="false">http://noise.getoto.net/?guid=ca6ae159be4d6e3bb6ce24cb1d5279a7</guid>

					<description><![CDATA[Amazon Web Services (AWS) has released Customer Compliance Guides (CCGs) to support customers, partners, and auditors in their understanding of how compliance requirements from leading frameworks map to AWS service security recommendations. CCGs cover 100+ services and features offering security guidance mapped to 10 different compliance frameworks. Customers can select any of the available frameworks and services […]]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
		<item>
		<title>NIST Draft Document on Post-Quantum Cryptography Guidance</title>
		<link>https://noise.getoto.net/2023/05/02/nist-draft-document-on-post-quantum-cryptography-guidance/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Tue, 02 May 2023 14:10:30 +0000</pubDate>
				<category><![CDATA[algorithms]]></category>
		<category><![CDATA[Applied Cryptography]]></category>
		<category><![CDATA[nist]]></category>
		<category><![CDATA[quantum computing]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=67297</guid>

					<description><![CDATA[NIST has released a draft of Special Publication1800-38A: &#8220;Migration to Post-Quantum Cryptography: Preparation for Considering the Implementation and Adoption of Quantum Safe Cryptography.&#8221; It&#8217;s only four pages long, and it doesn&#38;#821...]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 77/383 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-05 19:16:21 by W3 Total Cache
-->