[gnutls-devel] rc4 in gnutls 3.3.x

Nikos Mavrogiannopoulos nmav at gnutls.org
Sat Aug 1 10:43:49 CEST 2015


In the latest releases of gnutls (3.4.x) the rc4 (arcfour) cipher is
already disabled. That change was not propagated to 3.3.x release to
keep applications working as expected. However, given the the new
biases found in that cipher I tend to believe that it is more harm done
by keeping rc4 in the default priorities than good.

Are there any objections to dropping rc4 in one of the next 3.3.x point
releases from the default priorities?

regards,
Nikos




More information about the Gnutls-devel mailing list