Login Register






Thread Rating:
  • 0 Vote(s) - 0 Average


ssl is officially declared dead filter_list
Author
Message
ssl is officially declared dead #1
https://pciguru.wordpress.com/2015/02/07...ared-dead/

On January 30, 2015, QSAs received the latest edition of the Council’s Assessor Newsletter. Buried in that edition was the following statement.

“Notice: PCI DSS and PA-DSS v3.1 Revisions Coming
In order to address a few minor updates and clarifications and one impacting change, there will be a revision for PCI DSS and PA-DSS v3.0 in the very near future. The impacting change is related to several vulnerabilities in the SSL protocol. Because of this, no version of SSL meets PCI SSC’s definition of “strong cryptography,” and updates to the standards are needed to address this issue. (Highlighting emphasis added by the PCI Guru)
We are working with industry stakeholders to determine the impact and the best way to address the issue. While we do not have the final publication date, our goal is to keep you apprised of the progress and to provide you with advanced notification for these pending changes. We are also preparing several FAQs that will accompany release of the revised standards.
Should you have any questions, please contact your Program Manager.”
Because the announcement was titled about the coming v3.1 revisions to the PCI DSS and PA-DSS standards, I am sure a lot of QSAs missed this pronouncement.

Not that this should be a surprise to any QSA as the POODLE vulnerability effectively killed SSL. The Council has now officially announced that SSL is no longer deemed to be strong cryptography.

Therefore, those of you still using SSL to secure transmissions containing cardholder data (CHD) need to stop that practice as soon as possible and convert to TLS or IPSec.
---
Click here to get started with Linux!

If I helped you, please +rep me, apparently we've started over on Rep and I'd like to break 100 again...

Inori Wrote: got clickbaited by roger

Reply

RE: ssl is officially declared dead #2
Wrist in piss, SSLv3. Anyone conscious dumped you years ago.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: ssl is officially declared dead #3
Finally. It was getting so old.

Reply

RE: ssl is officially declared dead #4
Lol, we knew this was coming eventually. Rip, SSL.

Reply

RE: ssl is officially declared dead #5
Thought thus thread said SL is declared dead.
scary part us i believed it...rofl

Reply







Users browsing this thread: 2 Guest(s)