3 ms·
I get your point about the security of the system as a whole: my point isn't that the algorithms are on the list, just that they're at the top of the list. RC4
by redcap 13y ago
I get your point about the security of the system as a whole: my point isn't that the algorithms are on the list, just that they're at the top of the list.
RC4 may have helped TLS to succeed, but it's 2013 - surely there's something that is robust enough to be used instead by now?
Of course the simple explanation could just be for performance reasons.
- aidenn0 13y agoNo, the simple explanation is backwards compatibility. There was a client-side mitigation to the MtE vulnerability, but it broke some tiny fraction of servers in the wild so it never made it to the stable release of NSS.