On Fri, 15 Mar 2013 14:25:10 +0100
Erwann Abalea <erwann.aba...@keynectis.com> wrote:

> Drop RC4 when possible, add AES-GCM with TLS1.1+ wherever you can, 
> upgrade software ASAP.

AES-GCM needs TLS 1.2 - supported by pretty much zero browsers (but at
least some activity recently in the mozilla bugtracker).

But I agree - going to AES-GCM is the only sane solution at the moment
and everyone should migrate as soon as possible - everything else is
really too broken to rely on it for the medium term.

-- 
Hanno Böck              mail/jabber: ha...@hboeck.de
GPG: BBB51E42           http://www.hboeck.de/

Attachment: signature.asc
Description: PGP signature

Reply via email to