3 ms·
SSLab's grades are not stupid. They monitor how solid the SSL implementation is and what needs to be corrected to ensure higher security on the site. Another u
by netik 15y ago
SSLab's grades are not stupid. They monitor how solid the SSL implementation is and what needs to be corrected to ensure higher security on the site.
Another useful tool is SSLScan, which for Hacker News shows that they are accepting of a very strange set of HTTPS cipher and MAC configurations.
SSLv2 should be turned off, as well as the majority of 40-bit and 56-bit ciphers. Their unusual preference of CAMELLIA-256-CBC is pretty amusing to me.
Prefered Server Cipher(s):
SSLv2 168 bits DES-CBC3-MD5
SSLv3 256 bits DHE-RSA-AES256-SHA
TLSv1 256 bits DHE-RSA-AES256-SHA
Whaaaaat?
- tptacek 15y agoAgree to disagree on the grades, and agree to agree on SSLv2 and export ciphers. (I have other complaints about the SSLabs grades, but I'm not getting into it here).
- dfc 15y agoWhy not? I understand you do not have infinite time but if you get the chance I would enjoy hearing your thoughts.
- yuhong 15y ago>Their unusual preference of CAMELLIA-256-CBC is pretty amusing to me. Yea, I noticed it too when I checked this using Firefox and Chrome.