[tor-bugs] #19998 [Core Tor/Tor]: Stop allowing 3DES in TLS ciphersuites

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Aug 29 16:39:39 UTC 2016


#19998: Stop allowing 3DES in TLS ciphersuites
--------------------------+------------------------------------
 Reporter:  nickm         |          Owner:
     Type:  defect        |         Status:  new
 Priority:  Medium        |      Milestone:  Tor: 0.2.9.x-final
Component:  Core Tor/Tor  |        Version:
 Severity:  Normal        |     Resolution:
 Keywords:  tor-spec      |  Actual Points:
Parent ID:                |         Points:  .2
 Reviewer:                |        Sponsor:
--------------------------+------------------------------------

Comment (by nickm):

 AFAICT the RC4 suites are no longer advertised or accepted by any
 supported Tor. The only reason our code still mentions "RC4" is to detect
 versions of the cipher list that are lies.

 So yeah, adding to our spec "no RC4 either" would be a fine thing!

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/19998#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list