SSL/TLS and PKI History
feistyduck.com
feistyduck.com
It came in the wake of 'Lucky 13' and the demonstration of RC4 biases exploitable in TLS, and showed the awkward situation that existed at the time: essentially all supported ciphersuites were vulnerable to something, and no mainstream browser supported TLSv1.2 yet in which non-vulnerable ciphersuites were present.
Even if a reference isn't made to the blog post, the timeline should somehow reference the aforementioned ciphersuite conundrum.
[1] https://blog.cloudflare.com/staying-on-top-of-tls-attacks/
As it stands now you have to combine different pieces of information, some already included in the timeline (RC4, Lucky 13, Chrome TLSv1.2), some you have to know by knowing what's in TLSv1.1 and what's not (yet) in it.
This was a very impactful proposal that changed the way browsers preferred ciphersuites. But it also removed some lesser-used ciphersuites based off of telemetry [2], including the block cipher Camellia, which was the only other modern block cipher in TLS after AES.
Many of these items seem correct to include in "A comprehensive history of the most important events that shaped the SSL/TLS and PKI ecosystem”, however it feels very… inconsistent in inclusion.
Dates are given when browser implement protocol support, but not OpenSSL, NSS, etc. (Actually, nothing positive is said about OpenSSL at all.) Also no mention of Nginx, Apache or IIS and their TLS/SPDY support/features?
Brian Smith is mentioned by name working on a Rust crypto library, but no mention of DJB when discussing ChaCha20-Poly1305? (Is Ring actually used by any major projects so far?)
> (Is Ring actually used by any major projects so far?)
So, we're at the beta stage of releasing https://rustup.rs/, which is going to be the official way to download Rust in the future. It uses rusttls, which uses ring.There's also a discussion going on right now on the servo-dev mailing list: https://groups.google.com/forum/#!topic/mozilla.dev.servo/3m...
You'll find several people passionately arguing that Servo should use rustls as its SSL stack, which would make ring be used there as well.
Perhaps the inclusion of ring is a tad premature, but that's because I have very high hopes for this project. Brian is the only one taking a long-term view and doing what we're all supposed to be doing -- minimising the amount of C code we depend upon.