Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Same here. So i checked what ciphersuits they use.

TLS_RSA_WITH_RC4_128_SHA

Too bad they cant correctly set up their servers ...



Funny the blog post is about bad crypto and its all they support.


Funny how I had just disabled RC4 and DES in my browser... I wonder how can that be your only supported crypto in 2014!


For a while, RC4 was recommended because it's immune to the BEAST attack.


A new theoretical attack was published in 2013 that showed that RC4 was still weak in TLS. While the attack was more academic, it did raise questions of what else would be possible.

We often forget that RC4 is a fundamentally broken algorithm.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: