Originally Posted by
GoingAway
I definitely agree that their purpose here is in line with your thoughts.
We can't pass our own test, so it must not be a good test. Let's put a new one in place that we'll call "statistically" relevant and then pat ourselves on the back that we can pass it -- that its useless to verifying anything related to security will be irrelevant, of course
My bet is that they will just let the issue sunset...
They will expire the current process, since it is not statistically relevant, then claim that it is too expensive to come up with a statistically relevant testing regimen and just not test anymore.