PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]
pcisecuritystandards.org
PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]
1–9 of 9 posts
Re: PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]
#2Most of the tiny percentage of sites which only offer RC4 that I've found have been financial. They may not all necessarily fall under PCI themselves, but this is probably about all we can do.
The next round is on the browsers: IE, Chrome and Firefox turning it off completely (it's already only offered on fallbacks for IE, and recent Firefox; Fx nightlies only offered it on a whitelist of sites which still needed it but I don't think that change made it to release because it broke sites, although obviously breaking sites which will only use weak ciphers is unavoidable).
Now this is out of the way, all we really need to do is set a flag day and throw the switch.
If you're still using or offering RC4 for some reason, for heaven's sake stop, because you're going to regret it if you don't. XP has been out of extended extended support for more than a year now, and even unsupported early Android versions have alternatives.
Re: PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]
#3This is not very clear until you start digging in. I've never heard TLS 1.0 referred to as "early TLS" and nobody should do that; it has a very specific version number, please use it.
Re: PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]
#4Re: PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]
#5Re: PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]
#6IE<11 on Windows 7 require TLS1 or SSL3, which is not approved by PCI DSS :( How will that work in reality?
Re: PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]
#7Re: PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]
#8"Early TLS" means TLS 1.0 This is not very clear until you start digging in. I've never heard TLS 1.0 referred to as "early TLS" and nobody should do that; it has a very specific version number, please use it.
Re: PCI DSS v3.1: SSL and early TLS no longer considered strong crypto [pdf]
#9IE<11 on Windows 7 require TLS1 or SSL3, which is not approved by PCI DSS :( How will that work in reality?
(I'm not saying they will, but they could.)