5 ms·
I wish that too. I don't like the idea of having a demonstratively weak cipher in my SSL configuration, either. On the other hand, RC4 remains the only reliable
by ivanr 13y ago
I wish that too. I don't like the idea of having a demonstratively weak cipher in my SSL configuration, either. On the other hand, RC4 remains the only reliable way to defend against BEAST. Modern browsers might have addressed this issue, but there remain large numbers of users who are using older (unpatched) browsers and have (unpatched) Java enabled too. Plus, RC4 weaknesses are (as far as we know) not practical to exploit.
I am not afraid about BEAST, but I felt it would be wrong to penalize those who have legitimate reasons to be worried. In the end, it's all about context.
That said, perhaps the penalty for using RC4 with TLS 1.1 and better (which are not vulnerable to BEAST) should have been harsher. I'll consider it for a future update.
- jvehent 13y agoI agree. Unfortunately, there is currently no way to configure different ciphersuites for different versions of TLS. With issues like BEAST, it would be highly beneficial if Apache, Nginx & others would supports ciphers preferences per TLS versions. That still wouldn't help old clients. For them, only one solution: upgrade!
- ivanr 13y agoYes, that would be nice. I've heard that PolarSSL has per-protocol suite selection. It's really something the underlying SSL library needs to support. With OpenSSL, the best we can do right now is prioritize suites so that SHA2 ones are on top. By doing that, you know that TLS 1.2 capable clients are going to use good suites. The rest will fall back to whatever is below.
- blueskin_ 13y ago>Modern browsers might have addressed this issue, but there remain large numbers of users who are using older (unpatched) browsers and have (unpatched) Java enabled too. At some point, the world will have to tell them "you're on your own" like it finally did with IE6. Perhaps give them helpful informative messages to upgrade - I bet if Facebook and Twitter redirected old browsers to such a page, their market share would shrink to negligible levels overnight.
- omh 13y agoIs it possible to give an 'upgrade' message to old browsers in this case though? If they fail the SSL handshake then they'll see a browser error before it loads anything from your site. I agree with the principal of pushing people towards upgrading, but it's harder if you can't show them a helpful message to explain things.
- ivanr 13y agoIt's possible in some cases. For example, most sites continue to support SSL v3, even though only very old clients do not support TLS v1. So now would be a good time to tell those clients that they need to upgrade. If we don't do it now, SSL v3 might become too insecure for error messages. (Like, for example, SSL v2 is today.) With regards to BEAST, the problem is that a server has no way of telling if a client implements the mitigation technique. The only 100% safe assumption you can make is that the client negotiating TLS 1.0 is vulnerable.
- blueskin_ 13y agoThe server can make an educated guess based on the useragent. If someone is spoofing UA to an older browser, all bets are off, but then they presumably know what they are doing.
- deleted 13y ago[deleted]