[Operators] upgrade xmpp.net
moonchild at palemoon.org
Sat Aug 23 17:45:39 UTC 2014
-----BEGIN PGP SIGNED MESSAGE-----
On 2014-08-22 23:33, Skhaen wrote:
> Ohai everybody!
> We need an upgrade for xmpp.net: if a server is running with SSLv3 or
> without PFS, the score *must* be downgraded to B.
I also wanted to chime in and say that you shouldn't be punishing operators
who support SSLv3. It should be considered in the same class as TLS 1.0
since it suffers from the same potential issues for the most part.
The same goes for FS (I prefer to leave out the P since there is no such
thing ;) ) since offering ciphers and methods that do not have FS is just
being flexible. We do want to keep the federation flexible enough for
everyone in the world to use it, I hope.
Just my $0.02.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (MingW32)
-----END PGP SIGNATURE-----
More information about the Operators