[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-talk] time to disable 3DES?



On 10/8/13, Yawning Angel <yawning@xxxxxxxxxxxxxxx> wrote:
> * Lee <ler762@xxxxxxxxx> [2013-10-07 21:49:29 -0400]:
>> On 10/7/13, Yawning Angel <yawning@xxxxxxxxxxxxxxx> wrote:
>> > * Lee <ler762@xxxxxxxxx> [2013-10-07 15:58:19 -0400]:
>> >> Isn't it time to quit using DES?
>> >>
>> >> Finally gave TBB a try (version 2.3.25-13), seems to me that the
>> >> firefox component needs a lot of hardening.
>> >
>> > DES != 3DES, and supporting 3DES suites is standard across major
>> > browsers.
>>
>> Right.  But is it still safe to use?
>
> Why wouldn't it be?

It's old, NIST ran a competition to find a successor to DES/3DES &
selected AES about 13 years ago & I haven't read anything
_recommending_ the use of 3DES in I don't know how many years.

To get back on-topic -- isn't it time to disable 3DES in TBB?

If not, why not?

Thanks,
Lee
-- 
tor-talk mailing list - tor-talk@xxxxxxxxxxxxxxxxxxxx
To unsusbscribe or change other settings go to
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk