Re: Proposal to Remove legacy TLS Ciphersuits Offered by Firefox

2013-12-15 Thread Kurt Roeckx
On Sat, Dec 14, 2013 at 05:41:55PM -0800, Brian Smith wrote: Fx26Fx27 Change Cipher Suite 0.00% 14.15% +14.15% TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (new) 0.00% 8.30% +8.30% TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (new) Are you sure you didn't switch those 2? At least your

Re: Proposal to Remove legacy TLS Ciphersuits Offered by Firefox

2013-12-15 Thread Julien Vehent
On 2013-12-14 19:47, Kosuke Kaizuka wrote: Camellia is widely reviewed and chosen as a recommended cipher by several independent committees. If CAMELLIA_CBC is dropped by security reason, AES_CBC should be also dropped. There is another reason to drop CAMELLIA: AES with AES-NI is 8 times

Re: Proposal to Remove legacy TLS Ciphersuits Offered by Firefox

2013-12-15 Thread Julien Vehent
On 2013-12-15 11:13, Kurt Roeckx wrote: On Sun, Dec 15, 2013 at 10:46:04AM -0500, Julien Vehent wrote: On 2013-12-14 19:47, Kosuke Kaizuka wrote: Camellia is widely reviewed and chosen as a recommended cipher by several independent committees. If CAMELLIA_CBC is dropped by security reason,

Re: Proposal to Remove legacy TLS Ciphersuits Offered by Firefox

2013-12-15 Thread Kurt Roeckx
On Sun, Dec 15, 2013 at 11:22:32AM -0500, Julien Vehent wrote: On 2013-12-15 11:13, Kurt Roeckx wrote: On Sun, Dec 15, 2013 at 10:46:04AM -0500, Julien Vehent wrote: On 2013-12-14 19:47, Kosuke Kaizuka wrote: Camellia is widely reviewed and chosen as a recommended cipher by several

Re: Proposal to Remove legacy TLS Ciphersuits Offered by Firefox

2013-12-15 Thread Brian Smith
On Sun, Dec 15, 2013 at 8:46 AM, Kurt Roeckx k...@roeckx.be wrote: But some people are also considering disabling it by default, as I think all other where talking in this thread, not just reduce the preference. For the same reason, the server ciphersuite that we recommend at