IAB-PrivSec-program / draft-iab-privsec-confidentiality-mitigations

The Internet Draft recording the program's draft on mitigating confidentiality threats
0 stars 3 forks source link

RSA is no longer king #21

Closed martinthomson closed 8 years ago

martinthomson commented 8 years ago

Firefox telemetry shows ECDH as the current key exchange champion at almost 80% of handshakes. While it's true that that sort of statistic has an over-representation from sites like Facebook and Google, it suggests that maybe this needs tweaking:

The most common ciphersuites used for HTTPS today, for example, are based on using RSA encryption in such a way that if an attacker has the private key, the attacker can derive the session keys from passive observation of a session.

martinthomson commented 8 years ago

17a123d is good.