Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Here's an interesting post about TLS compatibility[1]. I guess it explains why no browsers have had TLS 1.2 on by default for such a long time.

" To add to this discussion about protocol version intolerance, I've been tracking this problem in my SSL Pulse data set (SSL servers from the Alexa top 1 million).

Here's what I have for November:

  Total servers: 163,587

  TLS 1.0 intolerance        9
  TLS 1.1 intolerance    1,388
  TLS 1.2 intolerance    1,448 (~ 0.9%)
  TLS 1.3 intolerance   17,840 (~10.9%)
  TLS 2.98 intolerance 122,698 (~75.0%)

  Long handshake intolerance: 4,795 (~2.9%)
"

1: https://www.ietf.org/mail-archive/web/tls/current/msg10657.h...



There's a trade-off to be made. On the one hand browser users would like every page to "just work". On the other hand they want secure connections to actually be secure.

If those .9% of websites break in the latest versions of firefox, chrome, and IE they are more likely to be fixed than if they are coddled through some workaround or even worse by holding back general progress. The former is better for web security. On the other hand, people who want to go to those websites in the meantime will be inconvenienced.

Perhaps a compromise is to build the workaround, but put in an interstitial scare screen. That might generate the desirable social pressure on the website owner without making it impossible to visit.


> On the other hand, people who want to go to those websites in the meantime will be inconvenienced.

…and they may well move to another browser which doesn't support TLS/1.2, or stay on an out-of-date (insecure!) version of the browser, which doesn't help web security either.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: