Akamai seems to be serving HTTPS content via AES-128-CBC (TLS 1.1)... is it worth trying to reconfigure for RC4 at this point?
@matthew_d_green I guess I'm basically asking "Is AES-CBC a problem worth fixing?"
-
-
@bascule Do you think BEAST is viable on the site? -
@matthew_d_green umm, is there any reason to think it shouldn't be? -
@bascule Doesn't it require some pretty specific same-origin nonsense? -
@matthew_d_green I know quite little about the attack in practice
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.