3 ms·
[I am the author of SSL Labs.] Not all major browsers implement 1/n-1 record splitting. In particular, the last time I checked, Apple did not in Safari and the
by ivanr 14y ago
[I am the author of SSL Labs.]
Not all major browsers implement 1/n-1 record splitting. In particular, the last time I checked, Apple did not in Safari and the iOS devices. In that light, downgrading the grade to a B is a reasonable way to indicate that your configuration is not secure for a potentially large portion of the user base.
The 1/n-1 split is the main reason that the grade is just reduced and sites are not simply failed (as is the case with insecure renegotiation, for example). The other reason is that the BEAST attack is not exactly easy to execute.
- agwa 14y agoWow, thanks for this reply (esp the info about Safari/iOS). What are your thoughts on the RC4 attack? Do you plan to take it into account in the SSL Labs test?
- ivanr 14y agoKnowing what we know today, attacks against RC4 are not yet practical, and thus there is no reason to panic. But we must act now. Given the huge incentive for researchers to continue to break RC4, it's reasonable to expect that the attacks will continue to improve. Yes, SSL Labs will start to penalize RC4 at some point, but not just yet. Later today we will start warning people about the problems. I've just published the recommendations here: RC4 in TLS is Broken: Now What? https://community.qualys.com/blogs/securitylabs/2013/03/19/rc4-in-tls-is-broken-now-what https://community.qualys.com/blogs/securitylabs/2013/03/19/r...