4 ms·
I think SSL Labs could be an option, but its penalty for configurations that don't support forward secrecy is not strong enough. That's my fault (sorry!), but I
by ivanr 9y ago
I think SSL Labs could be an option, but its penalty for configurations that don't support forward secrecy is not strong enough. That's my fault (sorry!), but I'll hopefully fix it soon.
Ultimately, I think the only way to kill the RSA key exchange is via a protocol revision, which is exactly what they've done in TLS 1.3. Sure, it will take a few years, but it will happen eventually.
I think banks like the RSA key exchange because it allows them to deploy transparent TLS traffic decryption via private key sharing.
- schoen 9y ago> I think SSL Labs could be an option, but its penalty for configurations that don't support forward secrecy is not strong enough. It's amazing how strong a motivation a grade or ranking can sometimes be. We saw this a lot with EFF's privacy practices report https://www.eff.org/who-has-your-back-government-data-requests-2015 https://www.eff.org/who-has-your-back-government-data-reques... where companies were sometimes willing to make real changes to earn an extra star. > I think banks like the RSA key exchange because it allows them to deploy transparent TLS traffic decryption via private key sharing. Oh yeah, that was something they complained about a lot with mandatory PFS in the TLSWG. :-( Why do they need this for their consumer-facing sites, though? The theory over in the working group was about monitoring activities of bank employees on third-party web sites (I thought), rather than about monitoring activities of bank customers on the bank's own web site.