Website Security & Threat Management
CloudFlare, PRISM, and Securing SSL Ciphers

CloudFlare, PRISM, and Securing SSL Ciphers

6/12/2013 · Matthew Prince

What this post added

This post addresses concerns about government surveillance programs like PRISM and their potential impact on SSL/TLS security. It explains how Cloudflare's default use of 2048-bit keys and preference for ECDHE cipher suites (which use a different private key for each session) significantly enhances security against potential decryption of historical traffic. The post also discusses the technical feasibility of breaking SSL keys and suggests alternative theories for how surveillance might occur, emphasizing Cloudflare's commitment to trust, security, and transparency.

Read the original post ↗