4 ms·
Using RC4 in TLS isn't entirely crazy. People started doing it due to the BEAST vunerability, which was a mistake in how AES was used in older TLS versions. ht
by mnordhoff 13y ago
Using RC4 in TLS isn't entirely crazy. People started doing it due to the BEAST vunerability, which was a mistake in how AES was used in older TLS versions.
https://en.wikipedia.org/wiki/Transport_Layer_Security#BEAST_attack https://en.wikipedia.org/wiki/Transport_Layer_Security#BEAST...
In the ongoing whack-a-mole of TLS vulnerabilities, RC4 was considered the best option. I am the opposite of an expert, so I have no idea if that was true then, or if it's still true now.
- tptacek 13y agoAdam Langley, Google's TLS czar, agrees with you and thinks RC4 is safer than the leaky MAC-then-encrypt construction TLS uses for block ciphers. I'm not sure I agree. The RC4 keystream bias problem is really bad, and it's baked into TLS just like MAC-then-encrypt is. In a nutshell: there are byte offsets into an RC4 stream that are simply predictable. Bernstein and Paterson have an attack that recovers plaintext from it at multiple byte positions. But for the first couple biases, anyone can see how easy it is to recover a byte or two of plaintext from RC4. Clever attackers can shift the plaintext in TLS around to make that byte position more valuable.