-
@dusan_panic @lanodan NIST guidelines and PCI DSS are just #LOLWTF in terms of security…
-
@dusan_panic @lanodan For example, NIST requires possibly backdoored ECC curve. PCI DSS doesn’t reject SSLv3 and doesn’t enforce TLSv1.2.
-
@dusan_panic @lanodan And none reject 3DES (and RC4 if I remember).
-
@dusan_panic @lanodan Neither reject CBC cipher, or enforce HSTS/HPKP or worse, PFS only ciphers.
-
@dusan_panic @lanodan CryptCheck check for REALLY secure parameters, like HSTS, HPKP… Can check HTTPS, SMTP, plain TLS, SSH…
-
@dusan_panic @lanodan And later, DNSSec, DANE and others :)
aeris22’s Twitter Archive—№ 34,160