Live data from Hacker News

Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

ghacks.net

21–30 of 37 posts

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#21
post #6

>"The preference change will be remotely applied to Firefox 74" No thanks. How do they do this, and how do I stop people from being able to remotely "manage" my Firefox install?

Is it just being pushed as an update? I don’t understand the semantic difference between an update and a study.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#22
post #5

Seems to indicate it wasn't as urgent to disable these as professed. I think browser vendors are sometimes a little too quick to break things, glad to see this pragmatism.

I assure you the browsers were not quick to disable TLS 1.0. They've dragged down their feet as long as they could and beyond.

TLS 1.0 and previous protocols have been prohibited from usage since around 2017 by PCI DSS and most regulations. Any company that gets a basic security audit or self-submit their website to https://www.ssllabs.com/ssltest/ would have been red flagged for using TLS 1.0 for years.

I've worked on the TLS upgrade in some financial institutions that notoriously always lag behind and even them have been ready for a while.

At this stage websites stuck on TLS 1.0 are either unmaintained for years or purposefully trying to support a Windows XP and Java 7 audience.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#24
post #17
post #8

Earlier quoted context omitted.

Decade-old versions of TLS are flat-out bad for users. TLS 1.0 is from 1999! The points of standards are to get the entire industry to adopt them. When the browser vendors come together and agree to all do the same thing, that's not one vendor flexing its muscles, that's standards working as intended.

> Decade-old versions of TLS are flat-out bad for users. TLS 1.0 is from 1999! no, bad standards are flat-out bad for users. lots of text files being written in ascii, for example, and 'ASCII is from 1963!'

Time to get on the ball and upgrade to Latin-1.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#25
post #5

Seems to indicate it wasn't as urgent to disable these as professed. I think browser vendors are sometimes a little too quick to break things, glad to see this pragmatism.

I assure you the browsers were not quick to disable TLS 1.0. They've dragged down their feet as long as they could and beyond. TLS 1.0 and previous protocols have been prohibited from usage since around 2017 by PCI DSS and most regulations. Any company that gets a basic security audit or self-submit their website to https://www.ssllabs.com/ssltest/ would have been red flagged for using TLS 1.0 for years. I've worked…

> At this stage websites stuck on TLS 1.0 are either unmaintained for years or purposefully trying to support a Windows XP and Java 7 audience.

Or are using Heroku Automated Certificate Management https://help.heroku.com/G0YVUNPG/how-do-i-disable-support-fo...

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#26
post #16
post #7

I was in charge of ensuring the TLS 1.2 compliance of hundreds of old sites in my organization. 2 weeks ago I was well on track to have it finished in time. Now I'm tasked to just keep up essential systems that are straining under the work from home onslaught, with two suddenly homeschooled kids needing my support I'm also so overstressed and worried that can only sleep on Xanax and have an asthma flare-up that looks…

Why do you have to do it alone? Cant you ask for another colleague to help you out on this?

Im of a three person team that completed a similar but smaller company (~30 ish sites,400 heads) and it was just short of a nightmare to even get buy in from devs and maintainers. And even after flipping the switch we found issues, soft killed site wide connectivity a couple times, it was not a pleasant experience. However I dont recall a time in ~11 years in which Id learned more quite as fast as I did.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#27
post #6

>"The preference change will be remotely applied to Firefox 74" No thanks. How do they do this, and how do I stop people from being able to remotely "manage" my Firefox install?

If you opt out of them enabling legacy protocols how would you let them disable legacy protocols?

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#28

Earlier quoted context omitted.

I assure you the browsers were not quick to disable TLS 1.0. They've dragged down their feet as long as they could and beyond. TLS 1.0 and previous protocols have been prohibited from usage since around 2017 by PCI DSS and most regulations. Any company that gets a basic security audit or self-submit their website to https://www.ssllabs.com/ssltest/ would have been red flagged for using TLS 1.0 for years. I've worked…

> At this stage websites stuck on TLS 1.0 are either unmaintained for years or purposefully trying to support a Windows XP and Java 7 audience. Or are using Heroku Automated Certificate Management https://help.heroku.com/G0YVUNPG/how-do-i-disable-support-fo...

As long as you support 1.2 as well (which Heroku does), you're fine; this is about sites that _only_ support 1.0 or 1.1.

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#29

Earlier quoted context omitted.

I assure you the browsers were not quick to disable TLS 1.0. They've dragged down their feet as long as they could and beyond. TLS 1.0 and previous protocols have been prohibited from usage since around 2017 by PCI DSS and most regulations. Any company that gets a basic security audit or self-submit their website to https://www.ssllabs.com/ssltest/ would have been red flagged for using TLS 1.0 for years. I've worked…

> At this stage websites stuck on TLS 1.0 are either unmaintained for years or purposefully trying to support a Windows XP and Java 7 audience. Or are using Heroku Automated Certificate Management https://help.heroku.com/G0YVUNPG/how-do-i-disable-support-fo...

[deleted]

Re: Mozilla re-enables TLS 1.0 and 1.1 because of Coronavirus (and Google)

#30
post #6

>"The preference change will be remotely applied to Firefox 74" No thanks. How do they do this, and how do I stop people from being able to remotely "manage" my Firefox install?

If you opt out of them enabling legacy protocols how would you let them disable legacy protocols?

By issuing a new release with updated defaults via the standard distribution channels. Remotely applied preference change implies a more direct intervention - it means you can't vet firefox to have certain behavior, as they may whimsically change your preferences.

Good for most consumers. Not necessarily so, if you are managing it.

Post reply on HN