RFC 7568 Deprecates SSLv3 As Insecure
AmiMoJo writes: SSLv3 should not be used, according to the IETF's RFC 7568. Despite being replaced by three versions of TLS, SSLv3 is still in use. Clients and servers are now recommended to reject requests to use SSLv3 for secure communication. "SSLv3 Is Comprehensively Broken," say the authors, and lay out its flaws in detail.
Currently, this is a PROPOSED standard. Meaning it still has to be accepted as standard by the IETF.
and what about the tens of thousands of UPSes, printers, KVMs, IP cameras, thermocouples and other embedded crap all which only responds to SSL v3 ? i suppose the IETF is going to come out with special firmware for all those devices still in wide use ? oh wait they arent. typical software "engineers" with no real world experience. go fuck yourselves.
What in the world took so long?
Saying HMAC with SHA1 is 'weak' is a bit too worrisome. Even with MD5 broken, none of the breakage applies to use in HMAC as far as I know.
So yes, if you are using a new implementation, go with the best hash. No reason to chose MD5/SHA1 in a new design. However if you are currently reliant upon some use of HMAC that happens to use SHA1 or even MD5, no need to exactly panic and break things to get away from that in an urgent way.
XML is like violence. If it doesn't solve the problem, use more.
I've got a NAS appliance at work whose "secure" web administration portal not only uses SSLv3 and is vulnerable to Poodle, but accepts SSLv2 (!!!). Why no, no updates from the manufacturer are forthcoming, why do you ask?
This is what we have to look forward to with IoT devices a thousand times over: Insecure software stacks that not only aren't up to date, but CAN'T be kept up to date.
They broke it when they named it TLS. Don't get me wrong. I know the security is better. That's not what they broke.
They broke the name. Instead of just continuing on calling it "SSLv4" and so on, they changed it to "TLS". But everyone is told to "use SSL" meaning, "use SSL or TLS". Certificates are "SSL Certificates" that happen to work for TLS also. SSL is the secure sockets layer, while TLS is just transport layer security. One of them is "secure" in the absolute sense, the other just provides some "security". (This isn't reality, it's just what the name implies to people.)
Now they get to live with the fact that they screwed up their PR on this one and people are responding negatively. Get used to the fact that people will continue to use SSL, and if there's any sense in the decision-makers' heads at all, they'll change the name to match what people expect.
It is sufficient to offer a comprehensive list of reasons for operators to discontinue use of SSL. Declaring "This document requires that SSLv3 not be used" is a pointless assertion.
The market not IETF process decides which protocols will continue to be used going forward.
Doing some some PCI compliance certification stuff and a scan shows that the site is not compliant, the reason being that TLSv1 is supported. Turning TLSv1 off kills off support for a number of older browsers, all types of browsers.....
(nginx)
server { .....
ssl on;
#ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_protocols TLSv1.1 TLSv1.2;
}
}
Now I am trying to figure out what to do about this problem, how to detect the clients that do not support TLSv1 and to redirect them to a simple html page instead of the clients pretty much receiving 'connection reset by server' error.
No dice so far, but I thought this was only supposed to happen a year from now (June 2016, not 2015), oh well.
You can't handle the truth.
"Your hosts file comments are not trustworthy" - by omnichad (1198475) on Friday August 09, 2013 @11:22AM (#44520759)
Oh, really? Ok: MalwareBytes' hpHosts Admin (MalwareBytes employee who has seen & verified its sourcecode too no less as safe) hosts & recommends it -> http://hosts-file.net/?s=Downl...
&
MalwareBytes = BEST antivirus (per this VERY recent testing of them all) -> http://www.av-test.org/en/news...
&
It's GUARANTEED safe & clean (per it being checked by 57 antivirus programs recently) in BOTH its 64-bit model -> https://www.virustotal.com/en/...
+
In its 32-bit model also https://www.virustotal.com/en/...
---
Tells us, omniweasel:
* HOW'S IT TASTE "EATING YOUR WORDS" flavored with your FOOT IN YOUR MOUTH ramming them down spiced with the BITTER TASTE of SELF-DEFEAT"?
LMAO...
APK
P.S.=> Lastly: In the past, You also conceded MANY points on hosts to me & made huge mistakes vs. me here http://tech.slashdot.org/comme...
&
Here too http://tech.slashdot.org/comme...
LMAO @ U, "omniloser"... apk