Re: Remove Legacy TLS Ciphersuites from Initial Handshake by Default

2015-03-02 Thread Kurt Roeckx
On 2015-03-02 13:32, Hubert Kario wrote: Not true. In Alexa top 1 million I found at least 439 servers which support only 3DES and have valid certificates. If Firefox removes RC4, I'm sure that this will make this number effectively only larger (80% of servers still support RC4, 15% prefer RC4 o

Re: Remove Legacy TLS Ciphersuites from Initial Handshake by Default

2015-03-02 Thread Hubert Kario
On Saturday 28 February 2015 01:03:39 nellie.pet...@safe-mail.net wrote: > I am using Marlene Pratt's "Proposal to Remove legacy TLS Ciphersuits > Offered by Firefox" from 13 Dec 2013 on dev-tech-crypto mailing list as a > guideline. > > I present a proposal to remove some legacy ciphersuites from

Re: Remove Legacy TLS Ciphersuites from Initial Handshake by Default

2015-03-02 Thread Kurt Roeckx
On 2015-02-28 04:15, Kosuke Kaizuka wrote: I also propose removing the following ciphersuit: 000A TLS_RSA_WITH_3DES_EDE_CBC_SHA because 3DES is a cipher that requires too much computing power compared to AES, much more computer memory, lacks hardware acceleration on servers, is rarely negoti