5 ms·
They just enabled forward secrecy today: https://twitter.com/duckduckgo/status/349948709418696706 https://twitter.com/duckduckgo/status/349948709418696706 This
by Mithrandir 13y ago
They just enabled forward secrecy today: https://twitter.com/duckduckgo/status/349948709418696706 https://twitter.com/duckduckgo/status/349948709418696706
This link has a nice rundown of why RC4 is no longer recommended for SSL/TLS: http://blog.cryptographyengineering.com/2013/03/attack-of-week-rc4-is-kind-of-broken-in.html http://blog.cryptographyengineering.com/2013/03/attack-of-we...
Basically:
"According to AlFardan, Bernstein, Paterson, Poettering and Schuldt (a team from Royal Holloway, Eindhoven and UIC) the RC4 ciphersuite used in SSL/TLS is broken. If you choose to use it -- as do a ridiculous number of major sites, including Google -- then it may be possible for a dedicated attacker to recover your authentication cookies. The current attack is just on the edge of feasibility, and could probably be improved for specific applications."
- jmillikin 13y agoA frustrating problem with ssllabs.com and RC4 is that it appears there is no way to achieve a 100% score. Sites are penalized for supporting RC4 if RC4 is placed above AES-CBC, and penalized as being vulnerable to BEAST if AES-CBC is placed above RC4. If CBC and RC4 are both disabled then no major browser can successfully negotiate a cipher. The BEAST penalty applies even if the preferred AES-CBC ciphers are defined by TLSv1.2 and thus shouldn't be vulnerable to BEAST. https://www.ssllabs.com/ssltest/analyze.html?d=john-millikin.com https://www.ssllabs.com/ssltest/analyze.html?d=john-millikin...
- ivanr 13y agoIt is actually possible to achieve 100%, but you have to run only TLS 1.2, IIRC. But that would also make your web site inaccessible to most users. But don't blame us, that's just the current situation with SSL/TLS. We're only reporting it. BTW, we used to show scores in the result, but too many people were trying to game the system (rather than be reasonable). As a result, we're showing only the grades now. In the future, the numerical scoring will be probably removed completely (switching to rule-based scoring). As for BEAST, our test tests SSL 3.0 and TLS 1.0 specifically, but not TLS 1.1+. So, the way to go with BEAST is to force RC4 with TLS 1.0 and earlier, some CBC suite with TLS 1.1, and GCM suites with TLS 1.2.
- jmillikin 13y ago> So, the way to go with BEAST is to force RC4 with TLS > 1.0 and earlier, some CBC suite with TLS 1.1, and GCM > suites with TLS 1.2. Since most browsers now include mitigations for BEAST, don't you think that the proven insecurity of RC4 is more dangerous to users than BEAST?
- ivanr 13y agoBoth (BEAST and RC4) are proven to be real. The only question is which is worse, and if the attacks are practical. In my view, both are equally unlikely to be a threat for an average web site. I'd love to get rid of the BEAST penalty, but there are no good (high-volume) stats on what percentage of "all" users is vulnerable to the BEAST attack. Because Apple is not yet deploying 1/n-1 in their browsers, the vulnerable BEAST percentage is still quite high. On SSL Labs, about 15%. Given that attacks against RC4 are not very practical (yet), one possible direction is to focus on supporting TLS 1.2 (without RC4, obviously), at which point both RC4 and BEAST attacks will become irrelevant.
- nknighthb 13y ago> I'd love to get rid of the BEAST penalty Please don't. The more attention is paid to it, the more ammo I have in pressuring the manufacturers of certain embedded systems I'm stuck dealing with to upgrade their ancient browser codebases.
- 13y ago
- tptacek 13y agoIt's hard to believe that anyone could play with that attack (Bernstein/Paterson is a refinement of an older variant) and come away being OK with using RC4. Adam Langley suggested on HN a few months ago that he was more comfortable with RC4 than with AES-CBC, which TLS unfortunately (due to its '90s heritage) specified in a MAC-then-encrypt construction that leaks timing, but the RC4 attack is scarily simple. Both attacks are extremely noisy, though; with what we understand about the flaws now, you'd surely notice if either attack was being directed at you.
- marshray 13y agoDid Paypal notice when Duong and Rizzo demoed BEAST against them?
- tptacek 13y agoI don't know what is or isn't public about the BEAST demo, but stand by my original point regarding the (unrelated) Lucky 13 and RC4 attacks. The RC4 attack takes, like, a day to run.
- marshray 13y agoRight. Beast has been demonstrated live on stage. It's on Youtube. Paypal couldn't block it in time even though they probably heard it was coming. RC4 is broken and the bias attack is very bad, but the attack requires a lot more connections.
- dhruvbird 13y agoOr you could just watch this video to see what's wrong with RC4! https://class.coursera.org/crypto-007/lecture/7 https://class.coursera.org/crypto-007/lecture/7