Hacker News new | past | comments | ask | show | jobs | submit login

Wow, thanks for this reply (esp the info about Safari/iOS).

What are your thoughts on the RC4 attack? Do you plan to take it into account in the SSL Labs test?




Knowing what we know today, attacks against RC4 are not yet practical, and thus there is no reason to panic. But we must act now. Given the huge incentive for researchers to continue to break RC4, it's reasonable to expect that the attacks will continue to improve.

Yes, SSL Labs will start to penalize RC4 at some point, but not just yet. Later today we will start warning people about the problems.

I've just published the recommendations here:

RC4 in TLS is Broken: Now What? https://community.qualys.com/blogs/securitylabs/2013/03/19/r...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: