
5/21/2015 · Filippo Valsorda
What this post added
This post explains the Logjam vulnerability, a novel downgrade attack against the TLS protocol that exploits EXPORT cryptography. It highlights how Cloudflare customers are protected because Cloudflare does not support non-EC Diffie-Hellman cipher suites or EXPORT-grade cryptography, and instead relies on Elliptic Curve Diffie-Hellman (ECDHE) for forward secrecy. The post details the technical workings of Diffie-Hellman and the Logjam attack, emphasizing the importance of strong, non-reused cryptographic parameters and the server's role in accepting weak parameters.