Website Security & Threat Management
SSLv3 Support Disabled By Default Due to POODLE Vulnerability

SSLv3 Support Disabled By Default Due to POODLE Vulnerability

10/14/2014 · Matthew Prince

What this post added

This post details Cloudflare's immediate response to the POODLE vulnerability affecting SSLv3. It outlines the decision to disable SSLv3 by default across the network, provides statistics on SSLv3 usage to assess impact, and discusses the technical mitigation strategies being explored, such as implementing fallback SCSV to prevent downgrade attacks. It also highlights the availability of an override option for Business and Enterprise customers.

Read the original post ↗