How to block the insecure RC4 cipher in Firefox and Chrome - gHacks Tech News (2024)

Whenever you connect to a secure website using Firefox or any other modern browser, negotiations happen in the background that determine what is being used to encrypt the connection.

ADVERTIsem*nT

RC4 is a stream cipher that is currently supported by most browsers even though it may only be used as a fallback (if other negotiations fail) or for whitelisted sites.

Exploits have come to light in recent time that take advantage of weaknesses in RC4 which allow attackers to run attacks in a reasonable time frame, for instance to decrypt web cookies which often contain authentication information.

Mozilla wanted to remove RC4 from Firefox completely initially in version 38 or 39 of the browser but decided against it based on telemetry data. As it stands right now, RC4 won't be disabled in Firefox 39 or 40.

Tip: you can check if your web browser is vulnerable by visiting this RC4 website. If you see red notifications on the page after the text has been conducted it means that it is vulnerable to attacks.

It needs to be noted that other browsers, Google Chrome for instance, are vulnerable as well. Google is apparently also working on dropping RC4 support completely in Chrome

Disabling RC4 in Firefox

Firefox users can turn off RC4 in the web browser completely. It needs to be noted that some secure sites may fail to work after doing so.

How to block the insecure RC4 cipher in Firefox and Chrome - gHacks Tech News (1)

  1. Type about:config in the browser's address bar and hit enter.
  2. Confirm you will be careful if you receive a prompt.
  3. Search for RC4 and double-click on the following preferences to set them to false.
  4. security.ssl3.ecdhe_ecdsa_rc4_128_sha
  5. security.ssl3.ecdhe_rsa_rc4_128_sha
  6. security.ssl3.rsa_rc4_128_md5
  7. security.ssl3.rsa_rc4_128_sha

Once you have made the changes reload the test page linked above. You should get connection failure messages instead of warnings when you do that.

If you run into issues connecting to secure sites after making the changes you may need to restore support for RC4. To do that repeat the steps above and make sure the values of the preferences are set to true afterwards.

Disabling RC4 in Chrome

How to block the insecure RC4 cipher in Firefox and Chrome - gHacks Tech News (2)

The process is complicated in Chrome as you cannot simply switch a couple of preferences in the web browser to disable RC4 in it.

The only valid option is to run Chrome with command line parameters that block RC4. Here is how this is done (instructions for Windows).

  1. Right-click on the Chrome shortcut in the taskbar of the operating system, and right-click again on Chrome, and select properties from the context menu that opens up.
  2. This should open the properties of the executable file.
  3. Add --cipher-suite-blacklist=0x0004,0x0005,0xc011,0xc007 as a parameter to the end of the Target line. Make sure there is a space in front of the parameter.
  4. The target line looks like this on my computer after adding the parameter: C:\Users\Martin\AppData\Local\Chromium\Application\chrome.exe --cipher-suite-blacklist=0x0004,0x0005,0xc011,0xc007
  5. Note: yours will vary based on your username and the version of Chrome you have installed.

The command adds RC4 to the cipher blacklist so that it won't be used by the browser. If you rerun the test, you will notice that it will fail (which is good).

Summary

How to block the insecure RC4 cipher in Firefox and Chrome - gHacks Tech News (3)

Article Name

How to block the insecure RC4 cipher in Firefox and Chrome

Description

Find out how to block the insecure RC4 cipher that may be used to establish secure connections in Chrome and Firefox.

Author

Martin Brinkmann

Advertisem*nt

How to block the insecure RC4 cipher in Firefox and Chrome - gHacks Tech News (2024)
Top Articles
Transaction History
Are There Any Benefits of Cheating in Relationships?
Radikale Landküche am Landgut Schönwalde
Is Paige Vanzant Related To Ronnie Van Zant
Is Sam's Club Plus worth it? What to know about the premium warehouse membership before you sign up
7 Verification of Employment Letter Templates - HR University
فیلم رهگیر دوبله فارسی بدون سانسور نماشا
Sportsman Warehouse Cda
Nation Hearing Near Me
Tv Schedule Today No Cable
Weather Annapolis 10 Day
Caroline Cps.powerschool.com
Programmieren (kinder)leicht gemacht – mit Scratch! - fobizz
Shuiby aslam - ForeverMissed.com Online Memorials
Dutchess Cleaners Boardman Ohio
iOS 18 Hadir, Tapi Mana Fitur AI Apple?
7 Fly Traps For Effective Pest Control
Apus.edu Login
Napa Autocare Locator
Clear Fork Progress Book
Boston Gang Map
Richland Ecampus
Sizewise Stat Login
Jet Ski Rental Conneaut Lake Pa
Kamzz Llc
Purdue 247 Football
How To Tighten Lug Nuts Properly (Torque Specs) | TireGrades
Safeway Aciu
Weather Underground Durham
Rainfall Map Oklahoma
Log in or sign up to view
Craigslist Sf Garage Sales
Salemhex ticket show3
Walter King Tut Johnson Sentenced
Luciipurrrr_
Σινεμά - Τι Ταινίες Παίζουν οι Κινηματογράφοι Σήμερα - Πρόγραμμα 2024 | iathens.gr
How does paysafecard work? The only guide you need
Chattanooga Booking Report
Mp4Mania.net1
Iban's staff
John F Slater Funeral Home Brentwood
Mid America Clinical Labs Appointments
Lima Crime Stoppers
Gopher Hockey Forum
Gotrax Scooter Error Code E2
Embry Riddle Prescott Academic Calendar
Amy Zais Obituary
Doe mee met ons loyaliteitsprogramma | Victoria Club
Lesson 5 Homework 4.5 Answer Key
Home | General Store and Gas Station | Cressman's General Store | California
Pulpo Yonke Houston Tx
Latest Posts
Article information

Author: Laurine Ryan

Last Updated:

Views: 6136

Rating: 4.7 / 5 (57 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Laurine Ryan

Birthday: 1994-12-23

Address: Suite 751 871 Lissette Throughway, West Kittie, NH 41603

Phone: +2366831109631

Job: Sales Producer

Hobby: Creative writing, Motor sports, Do it yourself, Skateboarding, Coffee roasting, Calligraphy, Stand-up comedy

Introduction: My name is Laurine Ryan, I am a adorable, fair, graceful, spotless, gorgeous, homely, cooperative person who loves writing and wants to share my knowledge and understanding with you.