Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

https://mozilla-old.badssl.com/ negotiates to TLS1.2 ECDHE RSA AES128 GCM SHA256 for me (FF54) which is fine.

There may well be obsolete stuff that server does support; but as negotiated, that's pretty much as good as it gets. It even has the new downgrade-prevention extensions on, so support for the old stuff shouldn't be a problem even if your client accepts it (which it need not).



Yeah I see, this one is more of a server-side problem since it still allow SSLv3 connections.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: