Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's a very sudden change. A lot of sites started using RC4 recently because it's immune to BEAST and Lucky13.


Really: no. There is nothing "very sudden" about RC4 exhibiting biases indicating it is weaker than it should be: ask any cryptographer. The break that's about to be disclosed in March is simply a new practical twist on a weakness published more than 10 years ago!

A lot of sites got bad advice. (One might wonder about whether all that advice was truly given in good faith. Maybe.) The real fix for BEAST and Lucky13 is, and always was, to use TLSv1.2 with AEADs like AES_GCM, or CHACHA20_POLY1305. So do that.


Which this site does. They put RC4 at the bottom probably because it is faster than 3DES.


So's NULL, but that doesn't mean you should use it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: