Closed i-rme closed 9 years ago
Stay tuned ;)
Yup I am already using Cloudflare patch along with patched OpenSSL 1.0.2 with chacha20_poly1305 support at https://sslspdy.com/ works nice :)
@centminmod Is there an updated ChaCha_Poly patch for the 1.0.2 branch? I spoke the OpenSSL team last week and was told AGL's patch to implement those two ciphers was "out of date".
@DomT4 I am using Peter Mosmans OpenSSL 1.0.2 patched maintained repo version https://www.onwebsecurity.com/cryptography/openssl and https://github.com/PeterMosmans/openssl
See https://github.com/cloudflare/sslconfig/pull/5, it's a faster implementation than can be found in Chrome or BoringSSL.
@centminmod Thanks. He did actually email me the link off-list, but I hadn't checked it out yet.
This cypher suite triples the speed on smartphones compared to AES_128_GCM, it is implemented in stable Chrome releases (both mobile and desktop) and I hope Firefox will implement it too.
Chrome is been used by 49% of all internet users worldwide so this cipher would benefit at least half of Clouflare´s hits.
http://googleonlinesecurity.blogspot.com.es/2013/11/a-roster-of-tls-cipher-suites-weaknesses.html