> On Mar 13, 2018, at 6:38 PM, Salz, Rich <rs...@akamai.com> wrote:
> The second paragraph talks about how quickly PCI DSS moved. As a 
> counterpoint, how quickly did they move to delay TLS 1.0 when organizations 
> pushed back?   SSL3 was "safe" to remove.  So far they can't even follow 
> industry best practices and remove TLS 1.0!  The last part of the paragraph 
> repeats the previous concern and adds nothing new.

+1.  That paragraph is bizarre and defies explanation.

