Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Isn’t the fact that OpenSSL et al allow so many arbitrary ciphers the reason of a whole load of problems?


Yep: https://en.wikipedia.org/wiki/Downgrade_attack

> Downgrade attacks have been a consistent problem with the SSL/TLS family of protocols; examples of such attacks include the POODLE attack.


Nope, the problem is that software never upgrade their ssl stack to support the newer ciphers. Especially Microsoft that's easily 10 years behind on the current SSL version.

Without the ability to support multiple versions, it would be impossible to upgrade anything at all. That would be a whole load of other problems.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: