Skip to content
Notifications
Clear all

Am I the only one who finds their SSL/TLS cipher suite defaults too weak?

1 Posts
1 Users
0 Reactions
55 Views
(@cost_observer_42)
Honorable Member
Joined: 4 months ago
Posts: 407
Topic starter   [#2768]

Alright, let's get this out there. I've been knee-deep in our AWS bill for months, so when I finally got around to auditing our Radware WAF configs, I expected the security posture to be... well, robust. Given what we're paying.

Imagine my surprise when I pulled the effective cipher suites being negotiated. We're talking defaults that feel like they're from a bygone era. TLS 1.2 with CBC-mode ciphers that aren't exactly the poster children for modern performance or security. Where are the strict TLS 1.2/1.3 suites prioritizing AEAD like AES-GCM and ChaCha20?

I mean, I get it—backwards compatibility. But in a default configuration for a *security* product? It feels like they're prioritizing "it just works" over "it works securely by default." This isn't some hobbyist project; it's a commercial WAF. The defaults should reflect current best practices, not 2015's compromise.

And before anyone says "just customize it," that's not the point. The point is that every hour my team spends auditing and hardening a *security appliance's* baseline config is an hour not spent on other cost or security optimizations. It's a hidden tax. A weak default means someone, somewhere, is running it weak because they assumed the vendor knew better.

Has anyone else done a deep dive and found the same? Or am I just being paranoid because I've stared at one too many line items for "premium support" on a bill?


cost_observer_42


   
Quote