4 ms·
Unable to Connect Securely Firefox cannot guarantee the safety of your data on digitalsecurity.intel.com because it uses SSLv3, a broken security protocol. Adv
by java-man 12y ago
Unable to Connect Securely
Firefox cannot guarantee the safety of your data on digitalsecurity.intel.com because it uses SSLv3, a broken security protocol.
Advanced info: ssl_error_no_cypher_overlap
For some reason, many sites, including amazon recommendations, fail to support 256 bit ciphers. I don't understand why.
- freehunter 12y agoNot to mention that the site is so broken that here is what I see on the Hacker News Window 8 app: http://i.imgur.com/tZ3IcwJ.png http://i.imgur.com/tZ3IcwJ.png The left side is what the app picks up as the text of the article. The right side is the page itself loaded in a browser, after it has finished loading all of the scripts and automatically scrolled itself past some contest thing. I'm on a dual-core Atom with 2GB of RAM and the site lags the entire thing. I mean, it's not as impressive as if it were the latest MacBook like some sites lag on, but still. Pretty shitty.
- JshWright 12y ago> For some reason, many sites, including amazon recommendations, fail to support 256 bit ciphers. I don't understand why. I assume you mean AES-256 vs AES-128. If a site is preferring AES-128 ciphers (particularly in combination with other modern cipher suite choices (ECHDE, SHA2, etc)) that's actually a pretty good indication they know what they are doing. AES-256 offers no practical advantage over AES-128. There are no known practical attacks against AES-128, and stretching the key to 256 bits just wastes CPU cycles. In fact, most of the attacks out there that weaken AES to any meaningful degree are those that attack the key schedule used in the 192 and 256 bit versions. tl;dr; Save the planet. Use AES-128.
- deleted 12y ago[deleted]
- tetrep 12y ago>Unable to Connect Securely Very odd. I'm using Chrome with chrome://flags/#ssl-version-min set to TLS 1.2, and I can connect just fine, although the certificate is signed with SHA-1.
- java-man 12y agoI've disabled all 128 bit ciphers as well as RC4.
- Buge 12y agoWhy disable 128 bit ciphers?
- java-man 12y agoIt's a question of choice, as a user. My original question was - why? Saving Earth, that's one way to look at the thing. Why then, amazon.com connects just fine with 256 bit cipher, but then fails when one goes to personal recommentations section. Most likely, of course, it's a misconfiguration issue, but is it possible that there exist more sinister reasons? Recall RC4. We now consider it broken. But it is still allowed on many servers, and even on 34.0.5 Firefox. I agree, when one goes to disable legacy functionality, one should be prepared to suffer consequences. That's why my original question was "why".
- JshWright 12y agoAES-128 is not 'legacy' though. AES-256 is not any more secure, and it is computationally more expensive. Anyone who prefers AES-256 over AES-128 should take a basic cryptography course.
- paralelogram 12y agoWhen both AES-256 and AES-128 are enabled, many servers prefer AES-128 because "it's faster".
- JshWright 12y agoAs they should... AES-128 is the objectively better choice. AES-256 is more computationally expensive, and provides no security benefit. In fact, there are _more_ attacks against AES-256 thanks to the extended key schedule.
- rasz_pl 12y agoSecure connection: fatal error (40) from server. I disabled RC4 long time ago.
- PhantomGremlin 12y agoThe confusion of SSL gets worse by the day. I'm running Firefox 36.0.4 on OS X 10.8.5. I see a "grey warning triangle" using Mozilla parlance. Clicking on that says "the connection to this website is not fully secure ...". Firefox refuses to show me Intel's certificate at all. It does say "This website does not supply identity information". How is an average user to know what to do if even a single application, e.g. Firefox, presents different messages to different users? IMO the message you received: "cannot guarantee the safety of your data" is much different than the one I got: "not fully secure". So which is it, and what is the difference? Bah. Right now I switch to a separate OS X user for my banking and credit card sites. But it's probably better to devote an entire computer (not a VM) to access just those few sites. It's 2015 and things are worse and more confusing than ever.