aeris22’s avataraeris22’s Twitter Archive—№ 34,165

      1. …in reply to @dusan_panic
        @dusan_panic @lanodan NIST guidelines and PCI DSS are just #LOLWTF in terms of security…
    1. …in reply to @aeris22
      @dusan_panic @lanodan For example, NIST requires possibly backdoored ECC curve. PCI DSS doesn’t reject SSLv3 and doesn’t enforce TLSv1.2.
  1. …in reply to @aeris22
    @dusan_panic @lanodan Neither reject CBC cipher, or enforce HSTS/HPKP or worse, PFS only ciphers.