nitter
L. David Baron @dbaron@w3c.social
@davidbaron
24 Feb 2017
Dropped ciphersuites with SHA1 from
dbaron.org/
which
ssllabs.com/ssltest/analyze.…
suggests (newly) breaks only IE11/Win Phone 8.1.
Feb 24, 2017 · 7:31 AM UTC
1
3
L. David Baron @dbaron@w3c.social
@davidbaron
24 Feb 2017
I haven't seen much commentary on what today's SHA1 news implies about HMACs using SHA1, but figured it was about time to disable it anyway.
2
1
L. David Baron @dbaron@w3c.social
@davidbaron
24 Feb 2017
Next step (for later) is dropping non-AEAD ciphersuites (i.e., CBC-mode), and thus un-supporting Safari 6 (iOS) and Safari 7-8 (iOS & Mac).