TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]

20 pointsby oxaloabout 10 years ago

4 comments

AlyssaRowanabout 10 years ago
Directly related, if you&#x27;ve been keeping up: RC4 is considered weak crypto and, now that CVE-2013-2566 has a base score of 4.3 (i.e. more than 4.0) and RFC 7465 has been published forbidding its use, offering or accepting RC4 should be considered an automatic fail by any PCI compliance scan.<p>Most of the tiny percentage of sites which <i>only</i> offer RC4 that I&#x27;ve found have been financial. They may not all necessarily fall under PCI themselves, but this is probably about all we can do.<p>The next round is on the browsers: IE, Chrome and Firefox turning it off completely (it&#x27;s already only offered on fallbacks for IE, and recent Firefox; Fx nightlies only offered it on a whitelist of sites which still needed it but I don&#x27;t think that change made it to release because it broke sites, although obviously breaking sites which will only use weak ciphers is unavoidable).<p>Now this is out of the way, all we really need to do is set a flag day and throw the switch.<p>If you&#x27;re still using or offering RC4 for some reason, for heaven&#x27;s sake stop, because you&#x27;re going to regret it if you don&#x27;t. XP has been out of <i>extended</i> extended support for more than a year now, and even unsupported early Android versions have alternatives.
feldabout 10 years ago
&quot;Early TLS&quot; means TLS 1.0<p>This is not very clear until you start digging in. I&#x27;ve never heard TLS 1.0 referred to as &quot;early TLS&quot; and nobody should do that; it has a very specific version number, please use it.
评论 #9450763 未加载
mdeeksabout 10 years ago
We&#x27;re going to be stuck with TLS 1.0 for a long time due to Android. Only Kitkat and above support TLS 1.1 and 1.2. Right now Kitkat&#x2F;Lollipop around hanging around 50% market share for and it&#x27;s only moving a few percent per month :(
robertpohlabout 10 years ago
IE&lt;11 on Windows 7 require TLS1 or SSL3, which is not approved by PCI DSS :( How will that work in reality?
评论 #9450431 未加载
评论 #9450857 未加载