Ending support for RC4 cipher in Microsoft Edge and Internet Explorer

Brink

Administrator
Staff member
Local time
1:11 PM
Messages
74,883
Location
Oklahoma
Today, Microsoft is announcing the end-of-support of the RC4 cipher in Microsoft Edge and Internet Explorer 11. Starting in early 2016, the RC4 cipher will be disabled by-default and will not be used during TLS fallback negotiations.

There is consensus across the industry that RC4 is no longer cryptographically secure. Our announcement aligns with today’s announcements from Google and Mozilla, who are ending support for RC4 in Chrome and Firefox.

What is RC4?

RC4 is a stream cipher that was first described in 1987, and has been widely supported across web browsers and online services. Modern attacks have demonstrated that RC4 can be broken within hours or days. The typical attacks on RC4 exploit biases in the RC4 keystream to recover repeatedly encrypted plaintexts. In February 2015, these new attacks prompted the Internet Engineering Task Force to prohibit the use of RC4 with TLS.

Microsoft Edge and Internet Explorer 11 only utilize RC4 during a fallback from TLS 1.2 or 1.1 to TLS 1.0. A fallback to TLS 1.0 with RC4 is most often the result of an innocent error, but this is indistinguishable from a man-in-the-middle attack. For this reason, RC4 will be entirely disabled by default for all Microsoft Edge and Internet Explorer users on Windows 7, Windows 8.1 and Windows 10 starting in early 2016.

How can I prepare?

We expect that most users will not notice this change. The percentage of insecure web services that support only RC4 is known to be small and shrinking.

If your web service relies on RC4, you will need to take action. Since 2013, Microsoft has recommended that customers enable TLS 1.2 in their services and remove support for RC4. For additional details, please see Security Advisory 2868725.

– David Walp, Senior Program Manager, Microsoft Edge


Source: Ending support for the RC4 cipher in Microsoft Edge and Internet Explorer 11 | Microsoft Edge Dev Blog
 

My Computer My Computer

At a glance

64-bit Windows 11 Pro for WorkstationsIntel i7-8700K OC'd to 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built custom
OS
64-bit Windows 11 Pro for Workstations
CPU
Intel i7-8700K OC'd to 5 GHz
Motherboard
ASUS ROG Maximus XI Formula Z390
Memory
64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz
Graphics Card(s)
ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
Sound Card
Integrated
Monitor(s) Displays
2 x Samsung Odyssey G7 27"
Screen Resolution
2560x1440
Hard Drives
1TB Samsung 990 PRO M.2,
4TB Samsung 990 PRO PRO M.2,
TerraMaster F8 SSD Plus NAS
PSU
Seasonic Prime Titanium 850W
Case
Thermaltake Core P3
Cooling
Corsair Hydro H115i
Keyboard
Logitech wireless K800
Mouse
Logitech MX Master 4
Internet Speed
2 Gb/s Download and 100 Mb/s Upload
Antivirus
Malwarebyte Anti-Malware Premium
Browser
Google Chrome
Other Info
Logitech Z625 speaker system,
Logitech BRIO 4K Pro webcam,
HP Color LaserJet Pro MFP M477fdn,
APC SMART-UPS RT 1000 XL - SURT1000XLI,
Galaxy S23 Plus phone
Does this means IE11 will get a patch for this?
I'll wait for the KB in that case...
 

My Computer My Computer

At a glance

Microsoft Windows 7 Home Premium SP1 64-bit B...AMD Athlon 64 X2 5200+ Dual Core CPU @ 2.7 Gh...2x2 GB DDR2 PC-5300 (667 Mhz) Kingston ValueRAMXFX ATI Radeon HD 4350 GPU (512 MB + 512 MB HM)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Assembled Desktop PC
OS
Microsoft Windows 7 Home Premium SP1 64-bit Build 7600
CPU
AMD Athlon 64 X2 5200+ Dual Core CPU @ 2.7 Ghz (Brisbane)
Motherboard
PCChips A13G+ v3.0
Memory
2x2 GB DDR2 PC-5300 (667 Mhz) Kingston ValueRAM
Graphics Card(s)
XFX ATI Radeon HD 4350 GPU (512 MB + 512 MB HM)
Sound Card
Realtek High Definition Audio Driver ALC660 @ MCP61S
Monitor(s) Displays
HP S2031 20" LED HD Widescreen Display Monitor
Screen Resolution
1600 x 900 px
Hard Drives
Maxtor Diamond Max 10 (160 GB, 7200 RPM, SATA-II Hard Disk)
Western Digital Scorpion Blue (250 GB, 5400 RPM, SATA-II External Hard Disk - Personal Data)
Toshiba MQ01ABD050 (500 GB, 5400 RPM, SATA-II External Hard Disk - Software & ISOs)
PSU
Pixxo Transformer 850W 80+ Certification PSU
Case
Compaq 5BW353 Case
Cooling
Many solutions, see other info...
Keyboard
Green Leaf (Mitzu) Standard Keyboard
Mouse
Microsoft USB Lasser Pointing Device
Internet Speed
10 MB
Antivirus
Avast Antivirus Free
Browser
Firefox, Chrome, Internet Explorer
Other Info
Windows Experience Index Result: 3.8 of 7.9.

Cooling solutions:
- AVC @ 2000/5000 RPM Copper Heatpipes (For Athlon 64 X2 6000+ CPU used in an Athlon 64 X2 5200+)
- Rear Fan 80 mm @ 2700 RPM for heat extraction
- Manhatan Chipset Cooler @ 4700/7200 RPM (For nVidia Chipset in MoBo)
- Foxconn @ 2500 RPM (Old Pentium III heatsink fan) in XFX ATI Radeon HD 4350
RC4 during a fallback from TLS 1.2 or 1.1 to TLS 1.0 in IE11

Does this means IE11 will get a patch for this?
I'll wait for the KB in that case...

Well I hardly ever use IE11 (installed on my machine) so it's difficult to comment. Personally my view is that it might be better to disable TLS 1.0 and only re-enable it on as as an when needed basis.

Now here's an interesting result using Cyberfox (Firefox variant)

Configured insecurely the RC4 cipher is indeed used during TLS fallback negotiations:

FF RC4.jpg

However if configured properly that doesn't happen and it doesn't use RC4 cipher suite:

FF RC4 2.jpg

EDIT:

Some more info here that doesn't seem to tie in with the announcement:

Security Advisory 2868725: Recommendation to disable RC4 - Security Research & Defense - Site Home - TechNet Blogs

IE 11 enables TLS1.2 by default and no longer uses RC4-based cipher suites during the >TLS handshake.

I guess that what they are saying is that RC4 is stlll available for the small number of websites that need it. Switching off RC4 entirely will force those sites to support only non RC4 ciphers.
 
Last edited:

My Computer My Computer

At a glance

Microsoft Windows 7 Home Premium 64-bit 7601 ...AMD C-60 APU with Radeon(tm) HD Graphics4.00 GBAMD Radeon HD 6290 Graphics
Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Yep I lost the translation :confused:
Anyone got a decoder ring around :p
 

My Computer My Computer

At a glance

Win-7-Pro64bit 7-H-Prem-64biti7-5930K 2nd i9-9940x both water blocked VRM'...Trident-z 3200C14 2nd Trident-z 3600C16EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom assembled by me :}
OS
Win-7-Pro64bit 7-H-Prem-64bit
CPU
i7-5930K 2nd i9-9940x both water blocked VRM's too
Motherboard
ASUS SABERTOOTH X99 2nd ASUS x299 Apex
Memory
Trident-z 3200C14 2nd Trident-z 3600C16
Graphics Card(s)
EVGA 1080ti ftw3 2nd Titan Xp both water blocked
Sound Card
Built-in Realtek
Monitor(s) Displays
1-AOC G2460PG 24"G-Sync 144Hz/ 2nd 1-ASUS VG248QE 24" 144Hz
Screen Resolution
1920 x 1080 144Hz
Hard Drives
2-Samsung M.2 Evo & Evo Plus
2-Samsung 850 EVO 500GB SSD's/ 3-2.5 W.D. Black 1tb-&3-1tb/3-3.5 WD Black 1tb hdd's
PSU
EVGA SuperNOVA 1000-P2 2nd 1200-P2
Case
2-Corsair Obsidian Series 450D Black ATX Mid Tower
Cooling
Custom water loops
Keyboard
Logitech G710+/ 2nd Logitech G910
Mouse
2-RedDragon M901 Perdition 16400 dpi Gaming mouse = wired
Internet Speed
Comcast Ping 19ms 89.31mbps download speed 6.12mbps upload
Antivirus
Malwarebytes Pro/ Superantispyware Pro
Browser
FireFox & Pale moon
Other Info
2nd ASUS X299 Apex/Intel i9-9940x with Custom water loop/7H-Prem-x64/Corsair 450D case/Ram Trident-z 3600C16 4x8gb / Samsung970Evo plus 500gb SSD/Dual ssd EZ swap evo/PSU EVGA SuperNova 1200w-P2 80+Platinum/GPU Titan Xp /8-ML-140 on push-pull on 2-280GTX rads
I've switch off all RC4 Ciphers a while back now in IE11...Web sites have to do the same and MS will provide a full patch for IE only in early 2016??.
 

My Computer My Computer

At a glance

Windows 7 Professional SP1 - x64 [Non-UEFI Boot]Ivy Bridge Core i5 3570K (Delidded)G.Skill "Ares" DDR3 PC3-12800 - 1600MHz (16Gb)Asus Dual-RX480-O4G
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional SP1 - x64 [Non-UEFI Boot]
CPU
Ivy Bridge Core i5 3570K (Delidded)
Motherboard
Asus P8Z77-V LE PLUS
Memory
G.Skill "Ares" DDR3 PC3-12800 - 1600MHz (16Gb)
Graphics Card(s)
Asus Dual-RX480-O4G
Sound Card
Creative Sound Blaster Z w/5.1 sound system
Monitor(s) Displays
Asus IPS 23"
Screen Resolution
16/9
Hard Drives
Internal:
500Go Sata 6Gb/s (x2)
500Go Sata 3Gb/s (x2)
SSD 60Go Sata 6Gb/s
PSU
In Win C 900W Series 80+ Platinum
Case
Thermaltake Chaser A71
Cooling
Custom Water Cooling Loop
Keyboard
Cooler Master QuickFire XTi
Mouse
Razer Imperator 2012 (4G)
Antivirus
MSE
Browser
IE 11.0.xxx Rtm
Other Info
"Raid0" with Intel Smart Response Technology (HDD/SSD)
Yes I did the same - disabled all RC4 ciphers via registry but that only seems to work with Winows and IE. It doesn't seem to affect other browsers specifically Firefox. In my case I use Cyberfox, FF Portable and Opera 12 mostly.

In my earlier posts I was just testing sites that use that insecure fallback method (utilizing RC4 during a fallback from TLS 1.2 or 1.1 to TLS 1.0.)
 

My Computer My Computer

At a glance

Microsoft Windows 7 Home Premium 64-bit 7601 ...AMD C-60 APU with Radeon(tm) HD Graphics4.00 GBAMD Radeon HD 6290 Graphics
Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Back
Top