The Web is World-Wide, or who still needs RC4?
In May 2014, John Graham-Cumming discussed the reasons behind Cloudflare's decision to continue supporting the RC4 encryption method despite its vulnerability to attacks. The company had debated whether to turn off RC4 altogether but decided against it due to a small percentage of web browsers still needing it. An analysis revealed that 0.000002% of requests to Cloudflare used the RC4 protocol, with users falling into four main categories: those passing through proxies, older phones, other miscellaneous cases, and software checking for updates or using old email programs and ancient operating systems. The company would like to stop supporting RC4 altogether but continues to offer it for a small number of clients who cannot connect more securely.
Company
Cloudflare
Date published
May 19, 2014
Author(s)
John Graham-Cumming
Word count
1263
Hacker News points
None found.
Language
English