Jump to content
View in the app

A better way to browse. Learn more.

FMForums.com

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Featured Replies

I love the fact that we can turn on SSL encryption on the server to secure information between the server and the client, but how good is this encryption? Would it be on par with creating a VPN using SSL for security purposes ? and are there any known vulnerabilities with SSL that would comprimise the information.

It's TripleDES with HMAC-SHA1 as the integrity checker. TripleDES is generally held to be strong encryption. It is not as strong as AES; but it is still held to be strong encryption.

HTH

Steven

  • Author

Thats great to know, thanks Steve.

  • 4 months later...
  • Author

Hi Steven, This is just a question I was asked and thought of you as someone that could answer it. I was asked "does Filemaker meet the federal encryption standard?" Based on the SSL (TripleDES with HMAC-SHA1) I would assume the answer is yes. Could you expand on this for me please.

Thanks, Ron

the federal encryption standard?

Which is what? There are a number of these for various agencies and uses. Some are actually classified.

Steven

  • Author

In other words is the SSL Triple DES encryption still considered a strong enough encryption with AES available. I've read that AES is the federal standard for encryption even though Triple DES has yet to actually be comprimised. Just in case I’m asked this question I was looking for any input you may add. I work strictly in the law enforcement community and it seems to me that the security with the FM is quite adequate. Any input would be greatly appreciated.

There is no signle Federal standard. NIST 800-53 talks a lot about security within the Federal Government, but, for example, the DOD and Intelligence communities have their own standards that are actually classified.

TripleDES is considered strong encryption. So is AES. And there is now an effort underway--or there will be shortly--to develop a new standard.

It's an arms race.

Steven

  • Author

Thanks again Steve, you're a wealth of informaton. Much appreciated!

Create an account or sign in to comment

Important Information

By using this site, you agree to our Terms of Use.

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.