4 ms·
I ran this against the slowest SSL website I know of. This site absolutely kills my phone web browser and I've been wondering about this problem for years. The
by beachaccount 15y ago
I ran this against the slowest SSL website I know of. This site absolutely kills my phone web browser and I've been wondering about this problem for years. The site: manager.skype.com. The result? DHE-RSA-AES256-SHA. No wonder! Fix this guys!
In regards to this post, if this is the default configuration of Nginx then I agree that Nginx sucks. This is not a good default configuration for the Internet.
- bdonlan 15y agoThere's nothing wrong with using DHE algorithms, particularly if you're going to be transferring financial secrets around. If your phone can't keep up, well, then it probably should have a better entropy generator.
- tptacek 15y agoAre you sure the problem is entropy generation and not just extra bignum math? Also: there are plenty of major financial apps that are not allowed to use DHE, because DHE makes it impossible for the provider to monitor its own connections ("conventional" SSL/TLS allows for middleboxes that monitor and archive sessions by holding a copy of the server's RSA key).
- burgerbrain 15y agoWhat is best for security in regulated fields and what is mandated or forbidden for security in regulated fields are often almost disjoint sets. Anyway, whether your phone has trouble coming up with the entropy, or preforming the math, you should probably be using something more substantial.
- tptacek 15y agoYou're suggesting that people should pick a different phone so they can get PFS with the small fraction of SSL servers that support it?
- burgerbrain 15y agoI'm suggesting that if for some reason a site thinks that that sort of security is necessary, they shouldn't change their mind for the sake of people using their telephones. Particularly since at the current rate of development, the average phone will be able to do it just fine in a few months.
- beachaccount 15y agoIt maxes has been maxing out my laptop CPU for an inordinate amount of time for years as well. These "financial secrets" are emailed in the clear after every transaction, so your point is moot. Burgerbrain: PayPal.com, CitiCards.com, 2checkout.com, and many payment processors all use RC4-SHA or AES256-SHA. You are wrong.
- burgerbrain 15y agoTheir patchy security doesn't render his argument invalid. Edit: beachaccount: Financial institutions not using DHE is not a logically sound counter to "There's nothing wrong with using DHE algorithms, particularly if you're going to be transferring financial secrets around." While those institutions may chose not to, there is nothing wrong with others choosing otherwise. Additionally, patchy security on the part of one operator certainly is not a logically sound argument against this. Furthermore, in the future, actually reply to a post in order to reply to a post. Not doing so unnecessarily confuses the flow of conversations (posts are not scarce resources).
- tptacek 15y ago"Patchy security"? What are you on about?
- burgerbrain 15y agoI'm refering to the portion of the comment I was responding to: "These "financial secrets" are emailed in the clear after every transaction" The implication being that since they were sending the information in the clear in a separate part of their system, that they were wrong in configuring their https site as they did. I object to that conclusion.
- tptacek 15y agoAh. Patchy works there. I'm sorry about that. Having a hairtrigger day.