Hacker News new | ask | show | jobs
by kevin_thibedeau 1515 days ago
Nowadays it means outdated, bare minimum security so we can still certify 3DES.
2 comments

Only for grandfathered-in systems that are critical to keep operating that can't be replaced. New systems and lower-impact existing systems cannot use 3DES at all, unless it's only to decrypt stuff previously encrypted with it.
Frankly it doesn’t even guarantee THAT. If they could certify it, they could list the mil-spec certification. It’s pure weasel wording.