浏览代码

Use utls.EnableWeakCiphers

Rod Hynes 7 年之前
父节点
当前提交
ef53249ff7
共有 1 个文件被更改,包括 7 次插入0 次删除
  1. 7 0
      psiphon/tlsDialer.go

+ 7 - 0
psiphon/tlsDialer.go

@@ -515,3 +515,10 @@ func verifyServerCerts(conn *utls.UConn, hostname string) error {
 	}
 	}
 	return nil
 	return nil
 }
 }
+
+func init() {
+	// Favor compatibility over security. CustomTLSDial is used as an obfuscation
+	// layer; users of CustomTLSDial, including meek and remote server list
+	// downloads, don't depend on this TLS for its security properties.
+	utls.EnableWeakCiphers()
+}