Flaws in OpenSSL FIPS Object Module

I don't know if people have been following this, but it is interesting
from the point of view of studying how the FIPS process does (or does
not) interact with the underlying goal of producing assured systems.

Another interesting part is that open-source systems are much more 
susceptible to being attacked by competitors (that is, having their 
validation suspended) than are closed-source systems.

