Why SSL was renamed to TLS in late 90s (2014)
tim.dierks.org
Why SSL was renamed to TLS in late 90s (2014)
1–10 of 237 posts
Re: Why SSL was renamed to TLS in late 90s (2014)
#2Re: Why SSL was renamed to TLS in late 90s (2014)
#3I still like to occasionally refer to TLS 1.3 as "SSL 3.4" to see whether people are aware of the history.
Re: Why SSL was renamed to TLS in late 90s (2014)
#4Re: Why SSL was renamed to TLS in late 90s (2014)
#5“Transport Layer Security” really is a better name though. I also like to say “TLS”. Two Ses in a row makes you sound like a snake.
Plus, who doesn't like to sound like a snake sometimes? Snakes are badass.
Re: Why SSL was renamed to TLS in late 90s (2014)
#6> Netscape also wanted to address SSL 2 issues, but wasn't going to let Microsoft take leadership/ownership in the standard, so they developed SSL 3.0, which was a more significant departure.
I remember this moment and this is where I realized that Microsoft wasn't always the bad guy here. They had the better implementation and were willing to share it. But Netscape in this instance acted like kids and wouldn't cooperate at all. Which is why this meeting had to occur and by that point it was clear Netscape had lost the browser and it wasn't going to be close.
Hence the quick about face by Netscape to accept what was pretty much Microsoft's proposed solution.
I can't speak to the rest of Microsoft's browser decisions and given the court ruling it's clear they weren't the good guys either but this opened my eyes to the fact that all companies are the bad guys some time:)
Re: Why SSL was renamed to TLS in late 90s (2014)
#7Re: Why SSL was renamed to TLS in late 90s (2014)
#8> As a part of the cutthroat competition, Microsoft decided to revise the SSL 2 protocol with some additions of their own, and specified a protocol called "PCT" that was derived from SSL 2. It was only supported in IE and IIS. > Netscape also wanted to address SSL 2 issues, but wasn't going to let Microsoft take leadership/ownership in the standard, so they developed SSL 3.0, which was a more significant departure. I…
FSF hated Microsoft because they released binaries without source code, they were THE enemy, nowadays, you are lucky if you get a binary to study and modify! The standard from any competitive developer is to hide the binary and source behind a server. Try to study and modify that!
Re: Why SSL was renamed to TLS in late 90s (2014)
#9> As a part of the cutthroat competition, Microsoft decided to revise the SSL 2 protocol with some additions of their own, and specified a protocol called "PCT" that was derived from SSL 2. It was only supported in IE and IIS. > Netscape also wanted to address SSL 2 issues, but wasn't going to let Microsoft take leadership/ownership in the standard, so they developed SSL 3.0, which was a more significant departure. I…
Microsoft was the bad guy in a movie where you have a war right before aliens invade and you figure out that there's bigger enemies. FSF hated Microsoft because they released binaries without source code, they were THE enemy, nowadays, you are lucky if you get a binary to study and modify! The standard from any competitive developer is to hide the binary and source behind a server. Try to study and modify that!
Re: Why SSL was renamed to TLS in late 90s (2014)
#10I've found that certain crowds will get angry about the vernacular vs a crowd that always understood something a particular way.
In any event, we have to stick with the times, especially with new entrants that stick with the new terms.