Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Every time a browser loads a padlocked page, it and the server agree on how to scramble the traffic before a single byte of it moves. That agreement comes from a list of ciphers, and the list on your server is whatever it shipped with unless someone changed it. Here's what a cipher is, how to read the cipher suite names your vulnerability scanner flags, and how to retire the weak ones without breaking the app nobody warned you about.

What Is a Cipher?

A cipher is a method for turning readable data (plaintext) into unreadable data (ciphertext), and back again. It has two parts: the steps, and a secret value called the key. Anyone who knows the steps but not the key sees noise.

The textbook example is the Caesar cipher. Shift every letter three places down the alphabet, and "ATTACK" becomes "DWWDFN". It falls apart fast, because there are only 25 possible shifts to try. AES, the cipher behind BitLocker, FileVault and HTTPS today, follows the same idea with math on bits instead of letters, and a key space too large to try one by one.

Three words get mixed up here:

  • Code: swaps whole words or phrases using a codebook, so "the eagle has landed" means "we arrived". It works on meaning.
  • Cipher: works on letters or bits, whatever they mean. It needs a key, not a codebook.
  • Encryption: the act of scrambling. The cipher is the algorithm that does it, so "AES encryption" means encrypting with the AES cipher.

Types of Ciphers You'll Meet at Work

Two splits cover the ciphers an IT team touches.

Symmetric vs asymmetric. A symmetric cipher uses one key to lock and unlock. AES and ChaCha20 are symmetric. They're fast, so they carry the bulk of the data: disk encryption like BitLocker and FileVault on Macs, VPN tunnels, and the body of every HTTPS session.

An asymmetric cipher uses a key pair. The public key locks, and only the matching private key unlocks. RSA and elliptic-curve algorithms work this way. They're slow, so they do small jobs: proving a server is who it says it is (certificates), and agreeing on a symmetric key without sending it in the clear.

Block vs stream. A block cipher encrypts fixed-size chunks. AES uses 128-bit blocks. 3DES uses 64-bit blocks, and that small block size is exactly what later got it retired. A stream cipher encrypts a continuous flow of bits. RC4 was the famous one and is now banned in TLS. ChaCha20 is the modern one, popular on phones without AES hardware.

HTTPS uses both halves. Asymmetric crypto sets up the connection, then a symmetric cipher moves the data.

What Is a Cipher Suite?

A cipher suite is the bundle of algorithms a client and server agree on at the start of a TLS connection. The client sends every suite it supports. The server picks one from its own list, usually the first match in its preferred order.

A TLS 1.2 suite name reads left to right:

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

ECDHE is the key exchange, how both sides agree on a shared key. The E stands for ephemeral: a fresh key per session, so a stolen server key can't decrypt recordings of old traffic. That property is called forward secrecy. RSA is the authentication, the type of certificate the server proves itself with. AES_256_GCM is the symmetric cipher and its mode. SHA384 is the hash used in the handshake.

TLS 1.3, published as RFC 8446 in August 2018, cut this down. Key exchange and authentication are negotiated separately, and only five suites exist, all of them modern authenticated ciphers. A TLS 1.3 name looks like TLS_AES_256_GCM_SHA384. There's nothing weak left in the list to switch off.

This walkthrough from Practical Networking covers the same anatomy with the handshake on screen.

Which Ciphers to Turn Off

Weak ciphers don't fail loudly. They keep working, and the risk sits there until someone with the right position on the network decides to use it. Each item below has a named reason and a date.

TLS 1.0 and 1.1 (and every SSL version). RFC 8996, March 2021, says both "MUST NOT be used." Microsoft started disabling them by default in Windows 11 Insider builds in September 2023.

RC4. Banned from TLS by RFC 7465 in February 2015. Clients must not offer it, and servers must not pick it.

3DES. Its 64-bit block is too small for long connections. The Sweet32 researchers recovered a secure HTTPS cookie from 610 GB of captured traffic in 30.5 hours, published in 2016 as CVE-2016-2183.

NULL, EXPORT and anonymous suites. No encryption, deliberately weakened 1990s encryption, or no server authentication. Nothing legitimate needs them.

Static RSA key exchange (suites that start TLS_RSA_WITH_). They still encrypt, but without forward secrecy.

CBC-mode suites are the grey area. Scanners like SSL Labs mark them weak because of older padding attacks on some TLS stacks. In a 2025 r/sysadmin thread, the author of IIS Crypto explained that Windows' own TLS stack isn't affected, but the scanner can't tell which stack you run. The same thread shows the usual trap: turning off two suites made the scanner complain about forward secrecy instead.

What to keep: TLS 1.3, plus TLS 1.2 with ECDHE key exchange and AES-GCM or ChaCha20. A weakness on its own is only half the problem, and our explainer on what an exploit is covers the other half.

How to Disable Weak Ciphers

Where you make the change depends on what's doing the TLS.

Windows Server. Windows handles TLS through a component called Schannel. PowerShell's TLS module lists and removes suites:

powershell
# What this server offers, in preference order
Get-TlsCipherSuite | Format-Table Name

# Remove one suite
Disable-TlsCipherSuite -Name 'TLS_RSA_WITH_3DES_EDE_CBC_SHA'

Protocol versions live in the registry, under HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols, with a Server and Client key per version and Enabled set to 0. Suite order can go out by Group Policy, under Computer Configuration > Administrative Templates > Network > SSL Configuration Settings. IIS Crypto, a free tool from Nartac, sets all of it with templates. Schannel changes need a reboot.

Linux web servers. In nginx, ssl_protocols TLSv1.2 TLSv1.3; plus an ssl_ciphers line. In Apache, SSLProtocol -all +TLSv1.2 +TLSv1.3. Mozilla's SSL Configuration Generator produces a vetted cipher string per server and version.

Appliances. Firewalls, printers, NAS boxes, UPS network cards and out-of-band management like iDRAC and iLO. Their cipher list often lives in firmware. The fix is an update or an admin setting, and for old enough hardware, a replacement.

Before you flip anything, find what still talks the old way. Windows logs Event 36871 when a TLS connection can't be set up, which is how apps that depend on TLS 1.0 show up. The classic casualty is a line-of-business app on an old SQL client driver, like this one:

The fix in that thread was updating the client driver, not the server. Pilot on one server, watch the event log for a week, then roll out. OpenFrame runs scripts across a fleet with approval gates, so the same check and change can reach every Windows server once a tech signs off.

How to Test What Your Server Offers

Test from outside the server, the way a client sees it.

  • nmap --script ssl-enum-ciphers -p 443 host lists every suite per protocol version and grades each one. It works on internal hosts.
  • openssl s_client -connect host:443 -tls1_1 tries one protocol. If the handshake completes, TLS 1.1 is still on.
  • testssl.sh gives a full report from any Linux or Mac machine.
  • Qualys SSL Labs' server test grades public websites, with no install.

Don't stop at port 443. RDP, LDAPS on 636, SMTP with STARTTLS, and SQL Server all negotiate TLS and all show up in scans. A penetration test will check them too, so you may as well get there first.

The Short Version

A cipher is the algorithm that scrambles data with a key. A cipher suite is the set of ciphers a client and server agree on for one connection. Keep TLS 1.3 and TLS 1.2 with ECDHE and AES-GCM, retire everything older, find the old clients first, and test from outside.

Next, read how a known weakness turns into an attack in our guide to what an exploit is.

Kristina Shkriabina

Content Marketing Lead

Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.
A cipher is a method for scrambling readable data into unreadable data using a secret key, and unscrambling it again with the right key. The Caesar cipher shifts letters; modern ciphers like AES do the same kind of thing with math on bits.
Encryption is the process of scrambling data. A cipher is the algorithm that does the scrambling. When people say AES encryption, they mean encryption performed with the AES cipher. A code is different again: it swaps whole words or phrases using a codebook.
A cipher suite is the set of algorithms a client and server agree on at the start of a TLS connection. A TLS 1.2 name such as TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 lists the key exchange, authentication, bulk cipher and hash. TLS 1.3 names list only the cipher and hash.
Disable SSL, TLS 1.0 and TLS 1.1, plus RC4, 3DES, NULL, EXPORT and anonymous suites. Static RSA key exchange (TLS_RSA_WITH_ suites) lacks forward secrecy. Keep TLS 1.3 and TLS 1.2 with ECDHE and AES-GCM or ChaCha20, and check for old clients before switching anything off.