3 ms·
I guess that some decisions are easier to make than others. It's quite clear, for example, that protocols before TLS 1.2 are inadequate. Forward Secrecy, on the
by ivanr 13y ago
I guess that some decisions are easier to make than others. It's quite clear, for example, that protocols before TLS 1.2 are inadequate. Forward Secrecy, on the other hand, is supremely important for some sites (e.g., Google) and not at all important for others (e.g., SSL Labs).
Also relevant is that these new rules are added on top of the 2009 rating guide, which does not offer an adequate framework for them. Just as an illustration, there is currently no meaning behind the A-F grades. A is good, and F is bad, clearly, but we don't know what the grades in between mean.
Same response to your ciphers question. I can't stretch the current approach to go handle those small differences. The calculations made some sense at the time, but they no longer work for everything we want to take into account.
I currently working a new version of the rating guide--from scratch--and it's going to solve all those problems, and a few more.