Over the last few years, there have been several major attacks on TLS [RFC5246], including attacks on its most commonly used ciphers and modes of operation. Details are given in Section 2, but a quick summary is that both AES-CBC and RC4, which together make up for most current usage, have been seriously attacked in the context of TLS.

Request for Comments: 7457
February 2015

       Summarizing Known Attacks on Transport Layer Security (TLS)                         and Datagram TLS (DTLS)


   Over the last few years, there have been several serious attacks on    Transport Layer Security (TLS), including attacks on its most    commonly used ciphers and modes of operation.  This document    summarizes these attacks, with the goal of motivating generic and    protocol-specific recommendations on the usage of TLS and Datagram    TLS (DTLS).

