-
@dusan_panic @lanodan NIST guidelines and PCI DSS are just #LOLWTF in terms of security…
-
@dusan_panic @lanodan For example, NIST requires possibly backdoored ECC curve. PCI DSS doesn’t reject SSLv3 and doesn’t enforce TLSv1.2.
-
@dusan_panic @lanodan And none reject 3DES (and RC4 if I remember).
-
@dusan_panic @lanodan Neither reject CBC cipher, or enforce HSTS/HPKP or worse, PFS only ciphers.
aeris22’s Twitter Archive—№ 34,164