Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6703283
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 26, 20262026-05-26T07:09:11+00:00 2026-05-26T07:09:11+00:00

Was reading an article in The Register about BEAST which lead me to the

  • 0

Was reading an article in The Register about BEAST which lead me to the SO post about SslStream, BEAST and TLS 1.1

It seems the best way to mitigate the vulnerability is to prefer a non-CBC cipher suite such as rc4-sha.

Is Heroku currently preferring CBC cipher connections? If so, does this mean customer dynos are currently vulnerable to BEAST?

I found OSWAP guide to Testing for SSL-TLS and did some local tests.

I also found Qualys SSL Labs test results for Heroku

Cipher Suites (SSLv3+ suites in server-preferred order, then SSLv2 suites where used)
TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x39)   DH 1024 bits (p: 128, g: 1, Ys: 128)  256
TLS_RSA_WITH_AES_256_CBC_SHA (0x35) 256
TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x33)   DH 1024 bits (p: 128, g: 1, Ys: 128)  128
TLS_RSA_WITH_AES_128_CBC_SHA (0x2f) 128
TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA (0x16)    168
TLS_RSA_WITH_3DES_EDE_CBC_SHA (0xa) 168
TLS_RSA_WITH_RC4_128_SHA (0x5)  128
TLS_RSA_WITH_RC4_128_MD5 (0x4)  128

Since server-preferred order puts TLS_RSA_WITH_RC4_* at the bottom of the list, I’m concluding that Heroku is currently vulnerable to BEAST.

Would love to hear from someone with more experience in this area.

BEAST attack Vulnerable INSECURE (more info)

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-26T07:09:11+00:00Added an answer on May 26, 2026 at 7:09 am

    The best way to defend against the attack demonstrated by BEAST is adopting (both in clients & servers) TLS 1.1. In its absence, the next best thing would be TLS_RSA_WITH_RC4_128_SHA, in my opinion, even if it’s considered “less secure” than AES. Wikipedia has a decent writeup on the known attacks on RC4. Most of them are biases of the output. To give you an idea of the severity of the attacks see the following quotes from the Wikipedia page:

    The best such attack is due to Itsik Mantin and Adi Shamir who showed
    that the second output byte of the cipher was biased toward zero with
    probability 1/128 (instead of 1/256).

    also:

    Souradyuti Paul and Bart Preneel of COSIC showed that the first and
    the second bytes of the RC4 were also biased. The number of required
    samples to detect this bias is 2^25 bytes.

    The following bias in RC4 was used to attack WEP:

    ..over all possible RC4 keys, the statistics for the first few bytes
    of output keystream are strongly non-random, leaking information about
    the key. If the long-term key and nonce are simply concatenated to
    generate the RC4 key, this long-term key can be discovered by
    analysing a large number of messages encrypted with this key.

    However, SSL/TLS does not use a long-term key with a nonce, but establishes a new key for RC4 by hashing (using either MD5 or SHA1, as you’ve seen in Qualys SSL Labs tests) with every connection (and refreshes the key after some period of time).

    You can read some more opinions on this matter in this sci.crypt discussion (if you ignore the trolls).

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I was reading an article referenced by Jeff Atwood about Yahoo's Best Practices for
After reading an article about fonts, i tried the code and i am getting
I was reading an article about how query expressions defer executions. Does that mean
I am reading an article in IEEE Computer magazine about using data mining on
I was reading this article by Brandon Aaron here , about how jquery context
I'm reading an article about an AMD GPU and am confused by a particular
I was reading this article which mentions storing 1Million keys in redis will use
I was reading this article about volatile fields in C#. using System; using System.Threading;
i was reading an article about smartphones and features phones, and i was surprised
I was reading an article here: http://javascriptweblog.wordpress.com/2010/03/16/five-ways-to-create-objects/ It tells about five ways of creating

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.