Bug#654764: Apache and BEAST

2012-09-17 Thread Christoph Anton Mitterer
Hi Stefan :) On Sun, 2012-09-16 at 10:31 +0200, Stefan Fritsch wrote: > Browsers now have a workaround that splits/inserts TLS records that > cause the IV to be changed. So this works also with CBC ciphers. Yeah I new,... > This > is basically the same what openssl does since before 0.9.6. ..

Bug#654764: Apache and BEAST

2012-09-16 Thread Stefan Fritsch
On Saturday 15 September 2012, Christoph Anton Mitterer wrote: > I wondered about the status of the BEAST attack in Debian, > especially: > > 1) Can I use any cipher suite and still be secure (e.g. use AES and > disable RC4; the later which is often claimed to secure things... > while there are ho

Bug#654764: Apache and BEAST

2012-09-14 Thread Christoph Anton Mitterer
Hi. I wondered about the status of the BEAST attack in Debian, especially: 1) Can I use any cipher suite and still be secure (e.g. use AES and disable RC4; the later which is often claimed to secure things... while there are however sources on the web claiming it would be even more vulnerable tha