9 ms·
How odd, your website gives me "ERR_SSL_VERSION_OR_CIPHER_MISMATCH" on Win64 > Chrome.
by deburo 5y ago
How odd, your website gives me "ERR_SSL_VERSION_OR_CIPHER_MISMATCH" on Win64 > Chrome.
- LinuxBender 5y agoThey have a good cert rating but ipv6 is not responding [1] and some clients will be denied based on cipher policy. I would be surprised if that applied to Chrome but one can always check. The DNS entry for ipv6 should be removed if not used. [1] - https://www.ssllabs.com/ssltest/analyze.html?d=egbert.net&hideResults=on https://www.ssllabs.com/ssltest/analyze.html?d=egbert.net&hi...
- egberts1 5y agoThank you for the input. I really don’t care for Chrome users and their inability to do pure TLSv1.3. Also, my server decides the selection of algorithms in TLSv1.3, not the web browsers: and that’s ChaCha/Poly. Yeah, it’s also a JS-free website. Migration to IPv6 is a work-in-progress. Hurricane Electric ISP also has a weird login condition; they want you to create a second account so you can pass your IPv6 certification (first was for DNS/IPv4). So I am looking for a secondary DNS provider for IPv6.
- LinuxBender 5y agoalso a JS-free website That's great. I would love to see more JS-free sites and more lightweight sites.
- lazyweb 5y ago> I really don’t care for Chrome users and their inability to do pure TLSv1.3. You "don't really care" for a majority of users, based on what? TLS 1.2 is perfectly fine to use with strong ciphers. I salute your static website which is free of JS/cookies/bloat/external stuff (similar to my own blog), but at the same time you're actively sabotaging accessibility.
- egberts1 5y agoNot concerned with accessibility as opppsed to security. If they are astute in cybersecurity, they will be using other (and secured) browsers.
- oynqr 5y agoWhat is your threat model here? Also, I use Vanadium with JS disabled, which is already decently hardened imho. Yet, your choice of key exchange bars me from your site.
- egberts1 5y agoMeanwhile, https://arstechnica.com/gadgets/2022/03/googles-topics-advertising-system-starts-rolling-out-to-chrome-canary/ https://arstechnica.com/gadgets/2022/03/googles-topics-adver...
- oynqr 5y agoThank god I don't use Chrome then.
- egberts1 5y agoChoose a better set of keys.
- egberts1 5y agoOf course, it’s Chromium-based which in turn is Chrome-based, or something.
- tetromino_ 5y ago> I really don’t care for Chrome users and their inability to do pure TLSv1.3. I am confused why even provide a link to a website which is configured to be inaccessible to most readers. May as well say "My work: an unpublished manuscript; message me for a copy".
- egberts1 5y agoBecause a real cybersecurity aficionado would use the right tools. And my website is for those who do do use the right tools.
- NavinF 5y agoDude your config is FUBAR. Why enforce TLS1.3 when you don’t understand that the way cipher suites are negotiated changed in TLS 1.3? > Also, my server decides the selection of algorithms in TLSv1.3, not the web browsers SMH. Either use Caddy with an empty config file or follow Mozilla’s recommendation: https://ssl-config.mozilla.org/#server=nginx&version=1.17.7&config=modern&openssl=1.1.1k&guideline=5.6 https://ssl-config.mozilla.org/#server=nginx&version=1.17.7&... # modern configuration ssl_protocols TLSv1.3; ssl_prefer_server_ciphers off; Also lol are you trying to host your site via HE’s free tunnel?
- deburo 5y agoWould the cypher negotiation be the problem? I checked that Chrome supports Chacha/Poly, and it seems it does. - https://chromestatus.com/feature/5355238106071040 https://chromestatus.com/feature/5355238106071040 Chrome seems to support TLS 1.3 since v70, and I'm on 99. There's only the 0-RTT/EarlyData as far as I can tell that may be messing things up, is it required for TLS 1.3? It's not enabled by default yet (still in dev?). - https://chromestatus.com/feature/5447945241493504 https://chromestatus.com/feature/5447945241493504 - https://developers.cloudflare.com/ssl/edge-certificates/additional-options/tls-13/ https://developers.cloudflare.com/ssl/edge-certificates/addi...
- NavinF 5y agoYes, you’re not supposed to specify the cipher suites with TLS1.3 This guy also forces secp521r1 (the NSA curve which is impossible to implement correctly, is unsupported by Chrome and eventually by Firefox, and is dog slow) instead of using DJB’s x25519. This is what roleplaying as an SRE looks like.
- deburo 5y agoThanks for the details!
- egberts1 5y agodog slow does not necessarily mean less secured. https://bugzilla.mozilla.org/show_bug.cgi?id=1128792 https://bugzilla.mozilla.org/show_bug.cgi?id=1128792 so far, absolutely no justification for Google to drop P-521: https://bugzilla.mozilla.org/show_bug.cgi?id=1129077 https://bugzilla.mozilla.org/show_bug.cgi?id=1129077 https://security.stackexchange.com/questions/100991/why-is-secp521r1-no-longer-supported-in-chrome-others https://security.stackexchange.com/questions/100991/why-is-s...
- egberts1 5y agoKnocked the IPv6 from its DNS records … for now.
- deleted 5y ago[deleted]