5 ms·
This site uses insecure 1024 bit Diffie-Hellman parameters for Diffie-Hellman key exchange! Please fix!
by pinjiz 11y ago
This site uses insecure 1024 bit Diffie-Hellman parameters for Diffie-Hellman key exchange! Please fix!
- pinjiz 11y agoWhy was this comment downvoted? The NSA has built custom hardware to crack 1024 bit DH in a few days[1], so the site owner really should regenerate the DH parameters and use 2048 bits. It would also be nice to disable 3DES ciphers and only allow ciphers with forward secrecy. [1] http://blog.erratasec.com/2013/09/tor-is-still-dhe-1024-nsa-crackable.html#.UipD1z9Bx8E http://blog.erratasec.com/2013/09/tor-is-still-dhe-1024-nsa-...