
AES-CBC is going the way of the dodo
4/21/2017
This post details the decline of AES-CBC cipher suites on Cloudflare's edge network, with their share dropping below ChaCha20-Poly1305 and approaching 10%. It also notes the surpassing of RSA by ECDSA for digital signatures and the near-ubiquitous adoption of Perfect Forward Secrecy (PFS). The internal breakdown of AES-CBC connections shows a prevalence of ECDHE-RSA or RSA key exchange, indicating older clients.














