Thirteen years ago, a vulnerability was discovered in the widely used RC4 encryption algorithm and received almost no further attention. Now, on its 13th birthday, when boys in Jewish tradition become adults and accountable for their actions, this old threat has resurfaced in earnest. Under the name 'Bar Mitzvah', the old vulnerability poses a new threat to the already troubled security of SSL.
What is RC4?
RC4 is one of the world's most widely used encryption technologies and currently protects at least 30% of SSL traffic. That translates into billions of TLS connections every day. Yet the method contains an old, long-known vulnerability called the 'Invariance Weakness'.

Following BEAST, POODLE, CRIME and other familiar SSL threats, Bar Mitzvah is a vulnerability in SSL communications. It allows a hacker to access information believed to be secure when it is not. Unlike earlier SSL threats, Bar Mitzvah does not use fragments of communication to exploit the vulnerability, but a so-called 'hit': an infrequent yet recurring moment of vulnerability in the communication stream. The attack does not require a man-in-the-middle either, making it even easier.
This vulnerability provides more than access to temporary session tokens: it exposes valuable permanent data, such as login credentials and payment details, when transmitted over HTTPS.
How is RC4 used?
RC4 is used in the TLS protocol through which servers and clients conduct their SSL communications. In the current TLS 1.2 implementation, RC4 is only a small part of the available encryption choices and is not the default. A few years ago, RC4 was still needed because most browsers did not support TLS 1.2. That situation has since changed, and every browser now supports more modern, secure encryption methods. TLS 1.3, currently still in development, further reduces the use of RC4.
Although RC4 no longer needs broad support, research in February 2015 found that 74.5% of 150,000 websites examined still supported it. A January 2015 study of 400,000 leading Alexa sites even found 3,712 sites offering only RC4, while almost 9% enforced RC4 with TLS 1.1 and TLS 1.2. There is therefore considerable danger in the fact that at least 30% of sites secured with SSL/TLS still support RC4.
Microsoft has for some time provided guidance through Microsoft Security Advisory 28687251 on disabling RC4 for Windows 7 and 8 and Windows Server 2008 and 2012, among others. CloudFlare, a widely used global CDN provider2 used by NOS and Security.NL to improve site continuity, has now removed RC4 from all its services.
