The U.S. National Institute for Standards and Technology (NIST) said SMS-based two factor authentication would soon be deprecated. This deprecation by NIST isn't an indication that 1024-bit RSA is compromised, instead it is a preemptive move to stay ahead of attacks. OOB using SMS is deprecated, and may no longer be allowed in future releases of this guidance. And under the current NIST recommendation, RSA-2048 is valid until 2030. NIST's move to begin the deprecation of TDEA will inevitably result in PCI following suit. Data Encryption Standard (DES) has been deprecated by NIST. In a 1024-bit RSA key, there is a 1024-bit integer value, called the modulus: this is a big integer whose value lies between $2^{1023}$ and $2^{1024}$. SMPET standard currently uses 2048 bits RSA certificate for key agreement and transport in ETM (S430-3), KDM (S430-1) format and ASM (S430-6) protocol. RSA 1024 and 2048 Key Exchange (Note RSA 1024 has been deprecated by NIST.) In 2014, the POODLE vulnerability of SSL 3.0 was discovered, which takes advantage the known vulnerabilities in CBC, and an insecure fallback negotiation used in browsers. The designation of a major encryption algorithm as a security risk has implications to US Federal Institutions and vendors subject to NIST guidelines. Within this draft, NIST is deprecating their recommendation of using SMS as a delivery mechanism for one-time-passcodes as an out-of-band authentication method. Additionally, FIPS 202 outlines the use of SHA-3 at the -224, -256, -384 and -512 output lengths. The Transport Layer Security (TLS) protocol provides the ability to secure communications across networks. TLS usually functions quietly in the background, but contrary to what one might think, TLS is not a black box that just works. SHA-1 has been deprecated for the purposes of digital signatures, but may continue to be used for the majority of other hash functions. NIST Recommended Elliptic Curves defined in FIPS PUB 186- 4: Digital Signature Standard (DSS) issued July 2013. In this release, the TLS_RSA_ cipher suites have been removed entirely. The transition affects many other algorithms as well, like DSA, ECDSA. NIST's official guidelines (PDF, page 64 and 67) deprecated 1024-bit RSA keys at the end of 2013. In the latest draft of its Digital Authentication Guideline, there's the line: [Out of band verification] using SMS is deprecated, and will no longer be allowed in future releases of this guidance. Further, in 2017, researchers from Google and CWI Amsterdam [SHA-1-Collision] proved SHA-1 collision attacks were practical. The proposal to formally retire the algorithm is not entirely surprising, especially considering historical movements by NIST: Rapid advances in computational power and cloud computing make it easy for cybercriminals to break 1024-bit keys. NIST also says that the "80-bit" security level should be shunned except when mandated for interoperability with legacy systems. Passwords continue to be a massive headache for businesses and their IT departments, a new survey shows, but both NIST and identity and access management (IAM) technology providers like RSA are working on solutions. SHA-1 has been deprecated for the purposes of digital signatures, but may continue to be used for the majority of other hash functions. NIST is No Longer Recommending Two-Factor Authentication Using SMS. At SecureAuth, we agree with NIST's guidance. Many websites today are using digital certificates signed using algorithms based on the hash algorithm called SHA-1. In addition to hard tokens, NIST continue to approve of RSA SecurID soft tokens. NIST Special Publication 800-131A announced that RSA public keys shorter than 2048 bits are disallowed. The NIST recommendation is to discontinue 1024-bit RSA certificates by December 31, 2010. ASV scan customers will need to obtain a 2048-bit or larger public key length certificate from their Certificate Authority. The Transport Layer Security (TLS) protocol [01] is the primary means of protecting network communications over the Internet. NIST also recommends that this security policy should be deprecated in 2012 for key lengths less than 2048 bit. NIST continues to approve of RSA SecurID tokens for such authentication. 