About this tag
Cipher suites are sets of cryptographic algorithms used to secure network connections via TLS. Discussions on WindowsForum.com cover Microsoft updates that add new cipher suites to Internet Explorer and Microsoft Edge, adjust default cipher suite priority order in Windows 7 through Windows Server 2012 R2, and address security vulnerabilities related to TLS and FalseStart. Key topics include enabling stronger encryption, preventing downgrade attacks, and mitigating information disclosure risks. These updates reflect ongoing efforts to improve web security and performance in Windows environments.
  1. News

    Microsoft TLS FalseStart Update Blocks Cipher Suite Downgrades

    Revision Note: V1.0 (May 10, 2016): Advisory published. Summary: FalseStart allows the TLS client to send application data before receiving and verifying the server Finished message. This allows an attacker to launch a man-in-the-middle (MiTM) attack to force the TLS client to encrypt the first...
  2. News

    3155527 - Update to Cipher Suites for FalseStart - Version: 1.0

    Revision Note: V1.0 (May 10, 2016): Advisory published. Summary: FalseStart allows the TLS client to send application data before receiving and verifying the server Finished message. This allows an attacker to launch a man-in-the-middle (MiTM) attack to force the TLS client to encrypt the first...
  3. News

    Windows Cipher Suite Update Strengthens Default Encryption

    Revision Note: V1.0 (May 12, 2015): Advisory published. Summary: Microsoft is announcing the availability of an update to cryptographic cipher suite prioritization in Windows 7, Windows Server 2008 R2, Windows 8, Windows Server 2012, Windows 8.1, and Windows Server 2012 R2. The update adds...
  4. News

    MS12-049 - Important : Vulnerability in TLS Could Allow Information Disclosure (2655992) -...

    Severity Rating: Important Revision Note: V1.1 (July 9, 2013): Bulletin revised to announce a detection change in the Windows Vista packages for the 2655992 update to correct a Windows Update reoffering issue. This is a detection change only. Customers who have already successfully updated their...
  5. News

    MS12-049 - Important : Vulnerability in TLS Could Allow Information Disclosure (2655992) -...

    Severity Rating: Important Revision Note: V1.1 (July 9, 2013): Bulletin revised to announce a detection change in the Windows Vista packages for the 2655992 update to correct a Windows Update reoffering issue. This is a detection change only. Customers who have already successfully updated their...
  6. News

    MS12-006 - Important : Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) - Versi

    Severity Rating: Important Revision Note: V1.1 (January 18, 2012): Added MS10-085 as a bulletin replaced by the KB2585542 update for Windows 7 for 32-bit Systems, Windows 7 for x64-based Systems, Windows Server 2008 R2 for x64-based Systems, and Windows Server 2008 R2 for...
  7. News

    MS12-006 - Important : Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584) - Versi

    Severity Rating: Important Revision Note: V1.0 (January 10, 2012): Bulletin published. Summary: This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0. This vulnerability affects the protocol itself and is not specific to the Windows...