Bug#654764: Apache and BEAST

2012-09-17 Thread Christoph Anton Mitterer
Hi Stefan :) On Sun, 2012-09-16 at 10:31 +0200, Stefan Fritsch wrote: Browsers now have a workaround that splits/inserts TLS records that cause the IV to be changed. So this works also with CBC ciphers. Yeah I new,... This is basically the same what openssl does since before 0.9.6. ... I

Bug#654764: Apache and BEAST

2012-09-16 Thread Stefan Fritsch
On Saturday 15 September 2012, Christoph Anton Mitterer wrote: I wondered about the status of the BEAST attack in Debian, especially: 1) Can I use any cipher suite and still be secure (e.g. use AES and disable RC4; the later which is often claimed to secure things... while there are however

Bug#654764: Apache and BEAST

2012-09-14 Thread Christoph Anton Mitterer
Hi. I wondered about the status of the BEAST attack in Debian, especially: 1) Can I use any cipher suite and still be secure (e.g. use AES and disable RC4; the later which is often claimed to secure things... while there are however sources on the web claiming it would be even more vulnerable