Re: Example of revoked SSL Sites

2015-03-08 Thread Dirkjan Ochtman
On Fri, Mar 6, 2015 at 8:32 PM, cneberg christopher.neberg...@gmail.com wrote: Does anyone know of any good test SSL websites which have been revoked where I can determine revocation 1) by OCSP and 2) by CRL's? I'd like to be able to test revocation features in a browser. You could look at

Re: Curve25519 and/or Curve41417 and/or Alternatives in Gecko/Firefox (was Re: Road to RC4-free web (the case for YouTube without RC4))

2014-07-10 Thread Dirkjan Ochtman
On Thu, Jul 10, 2014 at 7:35 PM, Kurt Roeckx k...@roeckx.be wrote: I would like to hear what others think about this, including what people think Gecko should do. I think it looks promosing. But like the paper indicates it needs time for other people to review it before it's going to see any

Re: ChaCha20-Poly1305 in Gecko/Firefox (was Re: Road to RC4-free web (the case for YouTube without RC4))

2014-07-10 Thread Dirkjan Ochtman
On Thu, Jul 10, 2014 at 6:41 PM, Brian Smith br...@briansmith.org wrote: So, what initially looked like a minor amount of effort turned into a more significant effort. If there is somebody interested in taking this on, I would be very happy to help them with it. Are there bugs, with some

Re: Proposal to Change the Default TLS Ciphersuites Offered by Browsers

2013-09-09 Thread Dirkjan Ochtman
On Mon, Sep 9, 2013 at 5:16 PM, Gervase Markham g...@mozilla.org wrote: This proposal promotes ECC. http://www.theguardian.com/world/2013/sep/05/nsa-how-to-remain-secure-surveillance Schneier: Prefer conventional discrete-log-based systems over elliptic-curve systems; the latter have