[Ach] favor DHE over ECDHE?

Aaron Zauner azet at azet.org
Mon Mar 10 13:35:21 CET 2014

Pepi Zawodsky wrote:
> Our Current Cipher strings prefer DHE over ECDHE to give all major browsers PFS wherever possible but have as many browsers avoid ECC (with NIST curves) as possible. The project is about better crypto, not about betterperformance.org (which is still available :-).
Cryptographers usually seek better security as well as better
performance. But yes, I agree, security should be our main concern. :)


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 801 bytes
Desc: OpenPGP digital signature
URL: <http://lists.cert.at/pipermail/ach/attachments/20140310/7485fedd/attachment.sig>

More information about the Ach mailing list