2 ms·
> The stat I was most curious about is in 9th position: SSLv3 with DES-CBC3-SHA, which accounts for 0.2% of the traffic, is a signature from Windows XP pre-sp3
by NeutronBoy 10y ago
> The stat I was most curious about is in 9th position: SSLv3 with DES-CBC3-SHA, which accounts for 0.2% of the traffic, is a signature from Windows XP pre-sp3 clients, when SChannel didn't support TLSv1 or AES. 0.2% may seem insignificant, unless you're one of these users and the only way you will browse the internet is by first downloading Firefox from mozilla.org.
It's an interesting problem - do you disable insecure/depreciated cipher suites, with the rationale it's an insecure method to download Firefox, knowing that it's people using outdated OSs trying to get Firefox and have no alternative?
- If you disable it, these people won't have any channel to get Firefox on their machine, and arguably be less safe when browsing the internet.
- If you leave it enabled, these people are still vulnerable at (arguably) the most vulnerable point (obtaining a new browser), but then being less vulnerable going forward.