All times are UTC + 1 hour




Post new topic Reply to topic  [ 6 posts ] 
Author Message
 Post subject: Jondonym Security Certificate
PostPosted: Tue Nov 08, 2011 15:10 

Joined: Mon Jan 24, 2011 18:59
Posts: 191
The certificate to this site use to be AES 256 (if I am not mistaken). Now it is RC4, 128 bit keys.

What happened? and Why the change?


Top
 Profile  
 
 Post subject: Re: Jondonym Security Certificate
PostPosted: Tue Nov 08, 2011 15:29 
User avatar

Joined: Thu Dec 04, 2008 18:02
Posts: 1049
The BEAST ran into our way. See e.g. http://ssl.entrust.net/blog/?p=977 or for a more technical article http://www.educatedguesswork.org/2011/0 ... zzodu.html.


Top
 Profile  
 
 Post subject: Re: Jondonym Security Certificate
PostPosted: Tue Nov 08, 2011 17:09 
User avatar

Joined: Mon Dec 29, 2008 15:58
Posts: 1836
RC4+RSA, 128 bit keys is a high secure encryption.

-AES-CBC- ciphers are not high secure anymore because of the BEAST attack. But the insecure part is CBC, not AES.

You may check our SSL encryption and compare it with other SSL webservers at: https://www.ssllabs.com/ssldb/


Top
 Profile  
 
 Post subject: Re: Jondonym Security Certificate
PostPosted: Tue Nov 08, 2011 18:47 

Joined: Mon Jan 24, 2011 18:59
Posts: 191
cane wrote:
RC4+RSA, 128 bit keys is a high secure encryption.

-AES-CBC- ciphers are not high secure anymore because of the BEAST attack. But the insecure part is CBC, not AES.

You may check our SSL encryption and compare it with other SSL webservers at: https://www.ssllabs.com/ssldb/


I get it. To avoid CBC, some companies have been using XTS, which, from what I understand, is more secure.


Top
 Profile  
 
 Post subject: Re: Jondonym Security Certificate
PostPosted: Tue Nov 08, 2011 18:48 

Joined: Mon Jan 24, 2011 18:59
Posts: 191
Georg Koppen wrote:
The BEAST ran into our way. See e.g. http://ssl.entrust.net/blog/?p=977 or for a more technical article http://www.educatedguesswork.org/2011/0 ... zzodu.html.


Funny way of phrasing it!

If this is the case, then what about for the mix servers? I know they are 128 bit but are they vulnerable to the BEAST? Is Jondonym using RC4 128 bits for the mix server cascades?


Top
 Profile  
 
 Post subject: Re: Jondonym Security Certificate
PostPosted: Tue Nov 08, 2011 19:12 
User avatar

Joined: Mon Dec 29, 2008 15:58
Posts: 1836
Quote:
some companies have been using XTS
At the moment this is not supported by the SSL library we are using on our webserver. To keep our maintenance work low, we will stay with the default SSL library of the distributor if it was possible to provide a secure configuration.

Quote:
Is Jondonym using RC4 128 bits for the mix server cascades?
JonDonym does not use SSL encryption for mix server traffic. It is not affected by BEAST or any other known attack to SSL encryption.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC + 1 hour


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
cron
Free Trial for Premium Services
Free Trial for Premium Services
Get your free test code for JonDonym Premium services!
JonDonym News
JonDo Error Message
Fri, 03 Mai 2013
HTTPS Certificate Updates
Fri, 22 Feb 2013
Speaker's Corner
First-Party Cookies
Thu, 09 May 2013
JonDoBrowser 0.6 - Status Report
Tue, 16 Apr 2013
For your web site - free!
Get your free IP check image for your web site or forum here!
Latest software releases
JonDo 0.18.001
Tue, 29 May 2012
JonDoFox 2.6.14
Wed, 15 May 2013
JonDoBrowser 0.6 Beta
Mon, 08 Apr 2013
Live-CD/DVD 0.9.41
Fri, 12 Apr 2013