Live data from Hacker News

RFC 10015: Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2

rfc-editor.org

21–25 of 25 posts

Re: RFC 10015: Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2

#21
post #17

Couldn't folks just use TLS 1.3?

That question is essentially asked "Why can't we just upgrade all of our legacy systems that are more than 15 years old?" 15 years because anything running a network stack from 2011 probably doesn't support TLS1.3 unless the developers were moderately forward looking. Most businesses have systems older than that. Most governments have systems twice as old as that. Upgrading things is hard, expensive, and in a lot of…

TLS1.1 was a few years older than TLS1.2 and was deprecated a few years ago

Re: RFC 10015: Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2

#22
post #6

Couldn't folks just use TLS 1.3?

I think the entire point is so that many with devices that will never see updates can still continue to use those devices.

Nobody is waiting on an RFC to make configuration changes to those devices to disable old cipher suites.

Re: RFC 10015: Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2

#24
post #17

Couldn't folks just use TLS 1.3?

That question is essentially asked "Why can't we just upgrade all of our legacy systems that are more than 15 years old?" 15 years because anything running a network stack from 2011 probably doesn't support TLS1.3 unless the developers were moderately forward looking. Most businesses have systems older than that. Most governments have systems twice as old as that. Upgrading things is hard, expensive, and in a lot of…

Changing 1.2 also makes you upgrade if you want to take advantage of most changes. And 1.2 and 1.3 aren't super different, right? So if you've been willing to backport 1.2 changes, I'm not convinced backporting all of 1.3 is much harder. If you haven't backported anything, I don't think this news affects you.

Re: RFC 10015: Deprecating Obsolete Key Exchange Methods in TLS 1.2 and DTLS 1.2

#25

I don't see much necessity. TLS1.3 is not something that hard or costly to support. I'd suggest just mark TLS1.2 as legacy and make some practical constraints to TLS1.3 applications/implementations to avoid replay attacks.

Do you have slightest idea on how many devices that would brick

They will get bricked sooner or later when some exploit rolls through. If these devices haven't been updated since 2018, they shouldn't be on the internet.
Post reply on HN