The Wayback Machine - https://web.archive.org/web/20130921223213/https://community.qualys.com/people/ivanr
Skip navigation

Ivan Ristic

Does not want to have a tagline.
Login or Sign Up to find out more about ivanr
Name:
Ivan Ristic
Status Level:
Level 4 Level 4 (916 points)
Member Since:
Jul 23, 2010
Company:
Qualys  
Occupation:
Director of Application Security Research  
Groups:
QSC 2012 - Las Vegas   QSC 2011 - London

Recent Activity

Ivan Ristic replied to Is forward secrecy in the protocols section of the report broken?

"No, it's not broken. For Forward Secrecy it does not matter what suites are supported; it matters what suites are actually used. If you look"

in SSL Labs • 1 replies
1 day ago
Ivan Ristic replied to When RC4 is going cause negative Rating ?

"No, not at this time."

in SSL Labs • 1 replies
2 days ago
Ivan Ristic replied to qualys.com / ssllabs.com tested

"I can respond to the second question: on ssllabs.com we're gathering some statistics about the BEAST vulnerability, which requires TLS 1.0 a"

in SSL Labs • 1 replies
2 days ago
Ivan Ristic replied to Assessment failed: Internal error

"You shouldn't be seeing that message; it does not mean anything by itself. But I tried one of the hosts that failed with that message and in"

in SSL Labs • 7 replies
4 days ago
Ivan Ristic modified Updated SSL/TLS Deployment Best Practices Deprecate RC4

"We are releasing an update to our SSL/TLS Deployment Best Practices document, which is our comprehensive guide to running secure servers. Th"

in Security Labs • 0 comments • 0 bookmarks
4 days ago
Ivan Ristic modified Updated SSL/TLS Deployment Best Practices Deprecate RC4

"We are releasing an update to our SSL/TLS Deployment Best Practices document, which is our comprehensive guide to running secure servers. Th"

in Security Labs • 0 comments • 0 bookmarks
4 days ago
Ivan Ristic replied to TLS SNI Support?

"The issue was that your server was returning valid certificates with SNI and without SNI. Before, SSL Labs used the non-SNI response. I have"

in SSL Labs • 2 replies
4 days ago
Ivan Ristic replied to SSL behavior on Windows XP with Firefox - beast mitigation with AES128 ?

"Firefox uses its own SSL/TLS library (NSS), which is why its behaviour does not depend on the operating system. The most recent Firefox on W"

in SSL Labs • 2 replies
5 days ago
Ivan Ristic replied to server cipher order not being obeyed by browser?

"I wouldn't worry about that. The server that does not have an ECDSA key will not enable the corresponding suites.   You can have both keys."

in SSL Labs • 4 replies
1 week ago
Ivan Ristic replied to want to configured Forward Secrecy without SSL

"What happens when you test your web site now? A couple of days we stopped rating the BEAST attack, so you might be happy with your results n"

in SSL Labs • 6 replies
1 week ago
Ivan Ristic replied to server cipher order not being obeyed by browser?

"The problem is that ECDHE-ECDSA-AES128-SHA  works only with a ECDSA key, which you probably don't have. Looking at enabled cipher suites usi"

in SSL Labs • 4 replies
1 week ago
Ivan Ristic replied to Handshake Simulation: Java

"If we assume that the unlimited policy has been applied, there's a danger that only 256-bit AES is configured, and then the site does not wo"

in SSL Labs • 2 replies
1 week ago
Ivan Ristic replied to Scanning a Load Balancer fails

"Talk to the vendor. I have manually verified that your current configuration accepts insecure renegotiation."

in SSL Labs • 16 replies
1 week ago
Ivan Ristic commented on Configuring Apache, Nginx, and OpenSSL for Forward Secrecy

"Unfortunate indeed. Could you please record a PCAP of the CloudFront traffic and send it me? We can look at the capture to determine which s"

in Security Labs • 27 comments • 0 bookmarks
1 week ago
Ivan Ristic modified Is BEAST Still a Threat?

"Yesterday I changed the SSL Labs rating criteria to stop penalizing sites that do not implement server-side mitigations for the BEAST attack"

in Security Labs • 2 comments • 0 bookmarks
1 week ago
Ivan Ristic replied to SSL Server test - how can you determine the server preferred cipher order / smtp support

"Hi Panda,   We will test SMTP, but only in the next major update of the scanning engine. I don't know when that will be, though.   As for"

in SSL Labs • 1 replies
1 week ago
Ivan Ristic modified Is BEAST Still a Threat?

"Yesterday I changed the SSL Labs rating criteria to stop penalizing sites that do not implement server-side mitigations for the BEAST attack"

in Security Labs • 2 comments • 0 bookmarks
1 week ago
Ivan Ristic modified Is BEAST Still a Threat?

"Yesterday I changed the SSL Labs rating criteria to stop penalizing sites that do not implement server-side mitigations for the BEAST attack"

in Security Labs • 2 comments • 0 bookmarks
1 week ago
Ivan Ristic wrote Is BEAST Still a Threat?

"Yesterday I changed the SSL Labs rating criteria to stop penalizing sites that do not implement server-side mitigations for the BEAST attack"

in Security Labs • 2 comments • 0 bookmarks
1 week ago