Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Unable to Connect Securely

Very odd. I'm using Chrome with chrome://flags/#ssl-version-min set to TLS 1.2, and I can connect just fine, although the certificate is signed with SHA-1.



I've disabled all 128 bit ciphers as well as RC4.


Why disable 128 bit ciphers?


It's a question of choice, as a user. My original question was - why? Saving Earth, that's one way to look at the thing. Why then, amazon.com connects just fine with 256 bit cipher, but then fails when one goes to personal recommentations section. Most likely, of course, it's a misconfiguration issue, but is it possible that there exist more sinister reasons?

Recall RC4. We now consider it broken. But it is still allowed on many servers, and even on 34.0.5 Firefox.

I agree, when one goes to disable legacy functionality, one should be prepared to suffer consequences. That's why my original question was "why".


AES-128 is not 'legacy' though. AES-256 is not any more secure, and it is computationally more expensive.

Anyone who prefers AES-256 over AES-128 should take a basic cryptography course.


When both AES-256 and AES-128 are enabled, many servers prefer AES-128 because "it's faster".


As they should... AES-128 is the objectively better choice. AES-256 is more computationally expensive, and provides no security benefit.

In fact, there are _more_ attacks against AES-256 thanks to the extended key schedule.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: