dcposch / scramble

Secure email for everyone
http://dcposch.github.io/scramble/
226 stars 32 forks source link

SSL and STARTTLS Forward Secrecy #87

Open dcposch opened 10 years ago

dcposch commented 10 years ago

Just in case.

Also, from the Open Technology Fund survey:

If StartTLS is supported, do you enable ciphers that are 
not-forward secret or have fewer than 128 bits?

We should not.

AndrewTheLott commented 9 years ago

According to SSL Report: scramble.io (173.255.244.90) assessed on: Tue Jan 13 06:50:36 PST 2015

On the plus side, Forward Secrecy & HSTS are enabled.