End of the road for RC4 (2024)

2015-02-23

  • John Graham-Cumming

3 min read

End of the road for RC4 (2)

Today, we completely disabled the RC4 encryption algorithm for all SSL/TLS connections to CloudFlare sites. It's no longer possible to connect to any site that uses CloudFlare using RC4.

Over a year ago, we disabled RC4 for connections for TLS 1.1 and above because there were more secure algorithms available. In May 2014, we deprecated RC4 by moving it to the lowest priority in our list of cipher suites. That forced any browser that had a good alternative to RC4 to use it. Those two changes meant that almost everyone who was using RC4 to connect to CloudFlare sites switched to a more secure protocol.

Back in May, we noted that some people still needed RC4, particularly people using old mobile phones and some Windows XP users. At the time, 4% of requests using RC4 came from a single phone type: the Nokia 6120.

At the time, we noted that roughly 0.000002% of requests to CloudFlare were using the RC4 protocol. In the last 9 months, that number is halved and so, although some people are still using RC4, we have decided to turn off the protocol. It's simply no longer secure.

The remaining users are almost all on old phones and Windows XP (those two groups make up 80% of the RC4-based requests). But we are still seeing some connections from SSL-intercepting proxy software that's using RC4. To repeat what we said in May:

Digging into the User-Agent data for the US, we see the following web browser being used to access CloudFlare-powered sites using RC4:

Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.137 Safari/537.36

That's the most recent version of Google Chrome running on Windows 7 (you can see the presence in Windows 7 in the chart above). That should not be using RC4. In fact, most of the connections from Windows machines that we see using RC4 should not be (since we prioritize 3DES over RC4 for older machines).

It was initially unclear why this was happening until we looked at where the connections were coming from. They were concentrated in the US and Brazil and most seemed to be coming from IP addresses used by schools, hospitals, and other large institutions.

Although the desktop machines in these locations have recent Windows and up to date browsers (which will not use RC4) the networks they are on are using SSL-based VPNs or firewalls that are performing on-path attacker monitoring of SSL connections.

This enables them to filter out undesirable sites, even those that are accessed using HTTPS, but it appears that the VPN/firewall software is using older cipher suites. That software likely needs updating to stop it from using RC4 for secure connections.

Since May, that situation has remained largely unchanged: there are some institutions doing SSL-interception (probably for IDS or policy enforcement reasons) that use RC4 for outbound connections, and many apparent individuals running software that does the same.

We've been continually tracking what's happening in the academic community around RC4 attacks and the slow death of RC4 as people switch from old devices to newer ones.

With both a decline in RC4 connections to CloudFlare and whispers of another, easier attack on RC4 in the academic community, we've decided the time is right to disable RC4 completely.

CloudFlare SSL Week

Cloudflare's connectivity cloud protects entire corporate networks, helps customers build Internet-scale applications efficiently, accelerates any website or Internet application, wards off DDoS attacks, keeps hackers at bay, and can help you on your journey to Zero Trust.

Visit 1.1.1.1 from any device to get started with our free app that makes your Internet faster and safer.

To learn more about our mission to help build a better Internet, start here. If you're looking for a new career direction, check out our open positions.

Discuss on Hacker News
RC4EncryptionTLSSSLSecurityCrypto Week

Related posts

August 08, 2024 2:05 PM

Introducing Automatic SSL/TLS: securing and simplifying origin connectivity

This new Automatic SSL/TLS setting will maximize and simplify the encryption modes Cloudflare uses to communicate with origin servers by using the SSL/TLS Recommender....

    By
  • Alex Krivit,

  • Suleman Ahmad,

  • J Evans,

  • Yawar Jamal

SSL,TLS,Network Services,Encryption,Research

July 29, 2024 1:00 PM

Avoiding downtime: modern alternatives to outdated certificate pinning practices

The number of outages caused by certificate pinning is increasing. We’ll explore why certificate pinning hasn’t kept up with modern standards and recommend alternatives to improve security while reducing management overhead...

    By
  • Dina Kozlov

Security,Network Services,Certificate Pinning,TLS,SSL,Certificate Transparency

June 24, 2024 5:06 PM

Helping keep customers safe with leaked password notification

To help protect against account compromise via credential stuffing attacks, Cloudflare will notify dashboard users when we detect that a password was found in an external data breach...

    By
  • Garrett Galow

Passwords,Security

May 30, 2024 12:12 PM

Cloudflare acquires BastionZero to extend Zero Trust access to IT infrastructure

We’re excited to announce that BastionZero, a Zero Trust infrastructure access platform, has joined Cloudflare. This acquisition extends our Zero Trust Network Access (ZTNA) flows with native access management for infrastructure like servers, Kubernetes clusters, and databases...

    By
  • Kenny Johnson,

  • Michael Keane

Acquisitions,Zero Trust,SASE,Security,Cloudflare Access,Product News,Cloudflare One,Connectivity Cloud

End of the road for RC4 (2024)
Top Articles
These are the best 2FA authenticator apps for Android and iOS
Verify it’s you when you complete a sensitive action - Android
#ridwork guides | fountainpenguin
Konkurrenz für Kioske: 7-Eleven will Minisupermärkte in Deutschland etablieren
Prices Way Too High Crossword Clue
shopping.drugsourceinc.com/imperial | Imperial Health TX AZ
Capitulo 2B Answers Page 40
World History Kazwire
Mlb Ballpark Pal
Help with Choosing Parts
Healing Guide Dragonflight 10.2.7 Wow Warring Dueling Guide
Erskine Plus Portal
State HOF Adds 25 More Players
Kiddle Encyclopedia
Classic | Cyclone RakeAmerica's #1 Lawn and Leaf Vacuum
Gentle Dental Northpointe
Loft Stores Near Me
/Www.usps.com/International/Passports.htm
The best firm mattress 2024, approved by sleep experts
Sussur Bloom locations and uses in Baldur's Gate 3
Spn 520211
Terry Bradshaw | Biography, Stats, & Facts
Talkstreamlive
Panola County Busted Newspaper
Bento - A link in bio, but rich and beautiful.
3569 Vineyard Ave NE, Grand Rapids, MI 49525 - MLS 24048144 - Coldwell Banker
WRMJ.COM
Evil Dead Rise Showtimes Near Regal Sawgrass & Imax
Plasma Donation Racine Wi
Club Keno Drawings
Scat Ladyboy
Have you seen this child? Caroline Victoria Teague
Pch Sunken Treasures
Domina Scarlett Ct
Elgin Il Building Department
Td Ameritrade Learning Center
Daily Times-Advocate from Escondido, California
Anhedönia Last Name Origin
Panorama Charter Portal
Dinar Detectives Cracking the Code of the Iraqi Dinar Market
Cl Bellingham
US-amerikanisches Fernsehen 2023 in Deutschland schauen
Courses In Touch
[Teen Titans] Starfire In Heat - Chapter 1 - Umbrelloid - Teen Titans
Catchvideo Chrome Extension
Gabrielle Abbate Obituary
Gary Vandenheuvel Net Worth
Sherwin Source Intranet
Lesly Center Tiraj Rapid
Bonecrusher Upgrade Rs3
Unbiased Thrive Cat Food Review In 2024 - Cats.com
Phumikhmer 2022
Latest Posts
Article information

Author: Fredrick Kertzmann

Last Updated:

Views: 6165

Rating: 4.6 / 5 (66 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Fredrick Kertzmann

Birthday: 2000-04-29

Address: Apt. 203 613 Huels Gateway, Ralphtown, LA 40204

Phone: +2135150832870

Job: Regional Design Producer

Hobby: Nordic skating, Lacemaking, Mountain biking, Rowing, Gardening, Water sports, role-playing games

Introduction: My name is Fredrick Kertzmann, I am a gleaming, encouraging, inexpensive, thankful, tender, quaint, precious person who loves writing and wants to share my knowledge and understanding with you.