Live data from Hacker News

Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

ghacks.net

11–20 of 37 posts

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#11
post #6

>"The preference change will be remotely applied to Firefox 74" No thanks. How do they do this, and how do I stop people from being able to remotely "manage" my Firefox install?

While I agree with the pragmatic choice of keeping older TLS enabled a while longer, I am very much at unease of Firefox remote updates and management (pushing code fixes as studies etc), disrespecting preferences in local configs and proliferation of services and multitude of background service connections.

Mozilla, please, I want a browser that I, as a "power user" can manage. Not an idiot-proof remotely managed on-prem SaaS.

Note: I and I'm sure many others would donate meaningful amount of money, if it could be restricted to categories of use, such as Firefox development or Rust development. You don't have to become a service vendor to wean off Google.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#12
post #5

Seems to indicate it wasn't as urgent to disable these as professed. I think browser vendors are sometimes a little too quick to break things, glad to see this pragmatism.

In the interest of security you can't wait for every last site to upgrade. But yes, reverting this is the right priority for the moment.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#13
post #6

>"The preference change will be remotely applied to Firefox 74" No thanks. How do they do this, and how do I stop people from being able to remotely "manage" my Firefox install?

I think they just push it as a "study" try turning those off

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#14
post #5

Seems to indicate it wasn't as urgent to disable these as professed. I think browser vendors are sometimes a little too quick to break things, glad to see this pragmatism.

I’m not sure anyone ever indicated that it was urgent... it’s taken a long time for them to take this step!

There’s an element of carrot and stick here, the browser vendors sometimes have to push people in the right direction. I think they’ve made the right call both in pushing for deprecation and altering their plans when circumstances have changed.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#15
post #6

>"The preference change will be remotely applied to Firefox 74" No thanks. How do they do this, and how do I stop people from being able to remotely "manage" my Firefox install?

You can't; Firefox is malware. Try an alternative web browser.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#16
post #7

I was in charge of ensuring the TLS 1.2 compliance of hundreds of old sites in my organization. 2 weeks ago I was well on track to have it finished in time. Now I'm tasked to just keep up essential systems that are straining under the work from home onslaught, with two suddenly homeschooled kids needing my support I'm also so overstressed and worried that can only sleep on Xanax and have an asthma flare-up that looks…

Why do you have to do it alone? Cant you ask for another colleague to help you out on this?

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#17
post #8

And this highlights how Google and the Chrome ecosystem is strangling web tech. The fact they were afraid of making a move that isn't in lockstep with Chrome means Chrome has too damn much influence.

Decade-old versions of TLS are flat-out bad for users. TLS 1.0 is from 1999! The points of standards are to get the entire industry to adopt them. When the browser vendors come together and agree to all do the same thing, that's not one vendor flexing its muscles, that's standards working as intended.

> Decade-old versions of TLS are flat-out bad for users. TLS 1.0 is from 1999!

no, bad standards are flat-out bad for users.

lots of text files being written in ascii, for example, and 'ASCII is from 1963!'

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#19
post #16
post #7

I was in charge of ensuring the TLS 1.2 compliance of hundreds of old sites in my organization. 2 weeks ago I was well on track to have it finished in time. Now I'm tasked to just keep up essential systems that are straining under the work from home onslaught, with two suddenly homeschooled kids needing my support I'm also so overstressed and worried that can only sleep on Xanax and have an asthma flare-up that looks…

Why do you have to do it alone? Cant you ask for another colleague to help you out on this?

If you were to ask a room full of developers what are TLS versions or TLS ciphers and which ones should be disabled? You'd be luckly if any of them raise their hands.

Consider an old organization with hundreds of old systems, that can be fairly critical. Nobody understand or is willing to do the work. To their credit, TLS and cryptography is really difficult.

So don't be surprised that things will be fixed... after they're noticeably broken.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#20
post #6

>"The preference change will be remotely applied to Firefox 74" No thanks. How do they do this, and how do I stop people from being able to remotely "manage" my Firefox install?

Always disable studies. It will also prevent the next Mr. Robot ad extension (or anything like that) from being automatically installed.
Post reply on HN