Attacks against RC4 have recently been reported as plausible, and Microsoft, among other groups, have recommended avoiding RC4 for symmetric-key encryption. I would recommend blacklisting cipher suites that rely upon RC4 so that other stronger algorithms, such as AES, will be preferred instead, so as to avoid these attacks. For example, I have disabled 0x9c, 0x35, 0x5, 0x4, 0x2f, and 0xa in Chromium because they do not provide perfect forward secrecy, and 0xc007, 0xc011, and 0x66 because they rely on RC4 but do provide perfect forward secrecy.

I support this. The setting is: security.ssl3.*_rc4_* = false

I agree. That should be high priority& corrected quickly.

When you visit, you literally obtain "BAD".

That is just not acceptable for Tor Browser.

Both and do not list RC4 as supported by the current Tor Browser. Also #17369 disabled RC4 fallback.

So this issue is now fixed?

No! #17369 disabled unrestricted fallback only, but restricted by Mozilla's whitelist fallback still persists (~1058 sites), Mozilla cleared it in FF 44 (

Other Mozilla devs said that the whitelist had never been used. User-defined list is empty too. It's not right to depend on all that. We need to disable RC4 completely.

Our nightlies already ship fixes for that and our alphas are about to do so, too. Let's close this ticket then.

