Defense in depth — the Microsoft way (part 25): no secure connections to MSDN, TechNet, …

Posted by Stefan Kanthak on Dec 27

Hi @ll,

the WWW sites msdn.microsoft.com and technet.microsoft.com still
support SSLv3 for HTTPS connections, but neither TLSv1.1 nor TLSv1.2.

Additionally they prefer the weak ciphers TLS_RSA_WITH_RC4_128_MD5
and TLS_RSA_WITH_RC4_128_SHA and offer not a single cipher that
supports “forward secrecy”.

See <https://www.ssllabs.com/ssltest/analyze.html?d=msdn.microsoft.com>
resp. <…

Leave a Reply