@tqbf Doesn't no RC4 mean making communications with older clients vulnerable to BEAST? I mean, a better choice, but still a tradeoff.
-
-
-
@abscondment@tqbf@onepercentfunk so people have to upgrade their clients. About time, no? -
@afcowie@tqbf@onepercentfunk Until then, which is worse: BEAST for some, or RC4 for more (i.e. http://hynek.me/articles/hardening-your-web-servers-ssl-ciphers/ …)? A 3rd way? -
@abscondment@afcowie@onepercentfunk I think RC4 is worse. - View other replies
-
@tqbf@afcowie@onepercentfunk Awesome. And Looks like Qualys just removed BEAST from their ratings, so it no longer caps a site to "B".
-
-
@tqbf Sadly it seems absurdly difficult to configure common environments to totally avoid RC4, or at least I haven't found a way out. -
@tqbf rot13 for life yo! I wonder how interesting the timing behavior of js crypto in current engines is -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Thomas Ptacek
Brendan Ribera
Andrew Cowie
Chris Siebenmann
Oliver Hunt
Perry E. Metzger