SSL No Longer Considered Strong Cryptography
In a recent bulletin the Payment Card Industry Security Standards Council (PCI SSC) stated that updates will be forthcoming to the Data Security Standard (DSS) version 3.0 – and very soon. The change is related to vulnerabilities seen with Secure Socket Layer (SSL) cryptography.
The National Institute of Standards and Technology (NIST) no longer views Secure Sockets Layer (SSL) v3.0 protocol being acceptable for protection of data due to inherent weaknesses within the protocol.
Thus no version of SSL meets the PCI SSC definition of ‘strong cryptography’ and they will be addressing this with revisions to the PCI DSS and the PA-DSS. The PCI SSC will soon publish PCI DSS v3.1 and PA-DSS v3.1 to address this issue as well as some other minor updates and clarifications. The new versions of the standards will be effective immediately when released.
So what does that mean for you? If you’re still using SSL, you’ll need to start implementing Transport Layer Security v1.1 or later, better known in information security circles as TLS, and do so immediately. Once the PCI SSC releases their updated versions, organizations that are using SSL will no longer be in compliance. All organizations, regardless of level, will be held to this new standard. Interested in more information on PCI v3.0?
Author: Viviana Wesley, PCI QSA
PCI DSS Requirements
PCI DSS Requirement 5.4.1: Anti-spoofing controls such as DMARC, which stands for Domain-based Message Authentication, Reporting and Conformance, Sender Policy Framework (SPF), and Domain Keys Identified Mail (DKIM) can help stop phishers from spoofing the entity’s domain and impersonating personnel.
Clarification on eCommerce Outsourcing PCI DSS requirements 6.4.3 and 11.6.1
Unpacking the New PCI DSS Password Standards
Is Your Organization Prepared for PCI DSS Automation – Requirement 10.4.1.1?
What is the PCI DSS v4 Authenticated Scanning Mandate – Requirement 11.3.1.2?
What is the PCI DSS v4.0.1 Requirement for PoLP – Requirement 7.2.5?
The New PCI DSS v4.0.1 Software Catalog Mandate – Requirement 6.3.2
How to Analyze An Attestation of Compliance (AOC)
PCI Compliance New Requirements and Targeted Risk Analysis (TRA)
RESOURCES & NEWS
Learn more about Penetration Testing and new exploits in HALOCK’s Exploit Insider.
The Dangers of Legacy Protocols
PCI Targeted Risk Analysis & DoCRA
https://www.halock.com/pci-compliance-new-requirements-and-targeted-risk-analysis/
HIPAA & Penetration Testing & Incident Response Plans
Top Threats in Healthcare
https://www.halock.com/top-cyber-threats-in-healthcare/
Cloud Security Risk Management
https://www.halock.com/prioritized-findings-and-remediation-in-cloud-security-reporting/
Penetration Testing Reports to Manage and Prioritize Risk
https://www.halock.com/a-threat-based-approach-to-penetration-test-reporting/