Get a Pentest and security assessment of your IT network.

News

Ivan Risti: Is RC4 safe for use in SSL?

Pawe Krawczyk says RC4 is still safe to use in SSL. He says it’s the default preferred cipher in most versions of IIS and MD5 are fastest and least CPU-intensive. But some pentesting tools and teams say it’s “weak” because of known cryptoanalytic attacks against both RC4. PCI-DSS v1.2 now doesn’t list any specific algorithms for SSL but instead just says you should use “strong” ones. NIST SP 800-52 doesn’t allow neither RC4 or MD5 because they’re not FIPS-approved algorithms.”]

Source: https://blog.ivanristic.com/2009/08/is-rc4-safe-for-use-in-ssl.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2