Weak or risky TLS cipher suites

Weak or risky TLS cipher suites

Description

Explicitly enabling weak cipher suites may reduce TLS confidentiality or integrity. RC4, 3DES, and the discouraged CBC suite below have different weaknesses; AES-CBC does not make every implementation vulnerable to the same attack. An attacker may exploit a weak negotiated combination to recover data or compromise a session.

Potential impact

  • Disclosure of sensitive data or authentication tokens through weaknesses in negotiated encryption
  • Modification of traffic where the selected algorithms or implementation permit an attack
  • Reduced protection despite using TLS, potentially failing security requirements

Remediation

  • Check the setting's scope: tls.Config.CipherSuites controls TLS 1.0–1.2. TLS 1.3 suites such as TLS_AES_128_GCM_SHA256 and TLS_AES_256_GCM_SHA384 cannot be configured with it. For explicit TLS 1.2 choices, consult tls.CipherSuites() and official AEAD guidance.
  • Remove discouraged RC4, 3DES, and CBC suites. Prefer the defaults of a maintained Go release unless an explicit list is needed.
  • Set MinVersion to at least tls.VersionTLS12, or tls.VersionTLS13 where compatible, to exclude older protocols.
  • Review Go release notes and security guidance for changes to supported and recommended suites.

Examples

Before

go
package main

import (
    "crypto/tls"
    "net/http"
)

// Before: explicitly select weak cipher suites
func insecureClient() *http.Client {
    tr := &http.Transport{
        TLSClientConfig: &tls.Config{
            // These RC4, 3DES and CBC suites are weak or discouraged
            CipherSuites: []uint16{
                tls.TLS_RSA_WITH_RC4_128_SHA,
                tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA,
                tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,
            },
            MinVersion: tls.VersionTLS10,
        },
    }

    return &http.Client{Transport: tr}
}

After

go
package main

import (
    "crypto/tls"
    "net/http"
)

// After: use modern cipher suites and TLS versions
func secureClient() *http.Client {
    tr := &http.Transport{
        TLSClientConfig: &tls.Config{
            // Prefer TLS 1.3 where possible; Go maintains default cipher suites
            MinVersion: tls.VersionTLS12,
            // If required, explicitly choose suitable TLS 1.2 cipher suites
            CipherSuites: []uint16{
                tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
                tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
                tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
                tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
                tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305,
                tls.TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305,
            },
        },
    }

    return &http.Client{Transport: tr}
}

Explanation:

  • Before: The list explicitly includes tls.TLS_RSA_WITH_RC4_128_SHA, tls.TLS_RSA_WITH_3DES_EDE_CBC_SHA, and tls.TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256. RC4 has statistical weaknesses, 3DES has a small block size vulnerable to SWEET32, and CBC risks depend on padding handling and implementation. A TLS 1.0 minimum also permits older protocol combinations.
  • After: MinVersion: tls.VersionTLS12 excludes TLS 1.0/1.1. The separate suite list selects AEAD algorithms using GCM or CHACHA20-POLY1305 for TLS 1.2, excluding the discouraged suites shown before. Go manages TLS 1.3 suites separately. These choices reduce weak-negotiation risks without replacing certificate validation.

References