NIST (And PCI-SSC) certainly disagrees on that statement. http://nvlpubs.nist.gov/nistpubs/Spe...P.800-52r1.pdf