How we built it

Remove CBC-mode ECDSA ciphers in TLS (removed)

Remove ECDHE_ECDSA_WITH_AES_128_CBC_SHA and ECDHE_ECDSA_WITH_AES_256_CBC_SHA TLS cipher suites. TLS's CBC-mode construction is flawed, making it fragile and very difficult to implement securely. Although CBC-mode ciphers are still widely used with RSA, they are virtually nonexistent with ECDSA.

Status in Chromium

Removed (launch bug) in:

  • Chrome for desktop release 56
  • Chrome for Android release 56
  • Opera release 43
  • Opera for Android release 43

Consensus & Standardization

  • No public signals
  • No public signals
  • No public signals
  • No signals

Owner

Last updated on 2016-10-21