The Death of RC4

I’ve always liked the RC4 cipher. It’s easy to understand and implement and has been in wide use for almost 30 years. Sadly, RC4’s run is over. It’s long been suspected that the NSA could break it and recent attacks are able to break RC4 in a matter of days or even hours.

Now Microsoft, Google, and Mozilla have announced their browsers will stop supporting RC4 in early 2016. The good news is that most servers support other cipher suites so RC4’s demise will go mostly unnoticed. There are, apparently, a few servers that support only RC4. These servers will stop working once the browsers refuse to negotiate its use.

I’m sad to see it go but RC4’s usefulness has clearly come to an end. If you have any apps still using it, it’s time to upgrade or replace those apps.

This entry was posted in General and tagged . Bookmark the permalink.