FedRAMP actually has a bunch of workarounds for the problems of FIPS.
In the "FedRAMP Policy for Cryptographic Module Selection and Use" (https://www.fedramp.gov/resources/documents/FedRAMP_Policy_f...), there are a ton of gems that make it clear that the FedRAMP folks are fed up with the CMVP process backlog. The most explicit is:
"FRR9: CSPs shall determine if updating to a newer version of the software, whether or not its cryptographic modules are FIPS validated, would eliminate the vulnerabilities; if it would, CSPs shall promptly update if that is feasible."
In layman’s terms that basically says if there’s a 0-day, patch first and we’ll worry about validation later.
You could say that’s “an issue” with literally every software package that has a support contract on earth. I can’t count how many times in my career we had to apply a patch release that wasn’t “officially ga” because of a zero day. That’s common sense, not a FIPS issue.
If our need to update fips certified packages out paces the ability to certify packages, that is absolutely a problem with the design of FIPs certifications.
So your choice inevitably boils down to running some ancient vulnerability-riddled version that's FIPS certified or running a recent less vulnerability-riddled version that's not certified. Most orgs that I've worked with keep running the vulnerable version because they have to be able to check the box that says "FIPS certified".
Quantum Fiber doesn't use PPPoE, it uses IPoE w/ VLAN tagging using VLAN 201, which is a common approach for legacy GPON networks. CenturyLink Fiber does use PPPoE, but I believe only the authentication portion of PPPoE, but I have never had CenturyLink Fiber so I can't say for certain.
I have Quantum and a UCG fiber. IIRC you only have to turn off vlan tagging on the ONT, and then set DHCP and the vlan tag on the UCG. If you try to keep the vlan tag on ONT you will get horrendous latency. The ISP still shows as CenturyLink.
Thanks, it's a bit frustrating when a piece of old news is reported without a followup. Happens all the time, and due to news agencies not bothering to report the not-so-interesting stuff, it's often difficult to find out what happened after.
```
Update #3: DCS and SAR have returned to service as of 1630Z. Engineers will now work to restore ABI and expect imaging to resume by 1900Z. Image navigation may be slightly degraded for the first hour after imaging starts. The GOES-19 instruments will be restored in the following order:
ABI
GLM
SUVI
CCOR-1/EXIS/MAG/SEISS
The recovery process to return all GOES-19 instruments to normal operations is projected to take approximately 8 hours.
Update #2: The GOES-19 Safehold has been resolved and engineers are working to prepare for restart of the onboard instruments. More information on the recovery timeline will be provided when known.
```
Looks like its started to publish new imagery again! I'm sure those fellows are relieved to have it working... I can't imagine the stress of trying to debug something that far away and unreachable!
He's not just the CEO, he's a co-owner... Meaning that the profits from the business acrue to him...
and therefore enable this party.
So, it's a question of "am I ok paying for this service, knowing that a portion of that money will flow to this political party and how do I feel about the results of that funding?"
How do you feel about providing value to Hacker News, a plattform made by Y Combinator funding several startups, many of them destroying our society and benefiting from mass surveillance? You can do this argument with every company.
I'm not paying to use HN. I'm jaded and opposed to techno-optimism, so if anything by just expressing my honest opinions here I'm wearing away at those startups' power by challenging their most critical base of supporters.