Reply to post: Good

These truly are the end times for TLS 1.0, 1.1: Firefox hopes to 'eradicate' weak HTTPS standard by blocking it

Drefsab_UK

Good

For all those skating them for this I applaud them, the standards for security evolve hell all the estate I look after have been tls 1.2 for years now. But to many sys admins are lazy when it comes to patching and keeping up to date. The average Joe doesnt know the the different between tls v1.3 using ECDH chacha ciphers and ssl v3 using rc4. But there's a world of difference and when some old granny gets her details compromised on a site and she says but the padlock was in the top bar it should be secure it's the browsers that will get blamed.

You should be telling the users if a sites not secure etc. You should be protecting users who don't understand. Giving a false illusion of protection is worse than no protection etc.

If you work in in or are a dev then you are not an average Joe, you should be able to use older version or use the override flags in the browser or setup a work around I personally use haproxy as a dmz in the vlan old devices are in (ilo's and such), I terminate tls v1.3 to that then it's backends speak to the devices on what ever protocol they support.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon