Live data from Hacker News

Why SSL was renamed to TLS in late 90s (2014)

tim.dierks.org

81–90 of 237 posts

Re: Why SSL was renamed to TLS in late 90s (2014)

#81
post #27

Curious, when you tell someone they need to access a website securely (or any other case where you might use the term TLS or SSL), do you: 1. Say SSL or TLS? 2. How old are you (or did you start working before 1999?) I'll reply with my answer too.

SSL, 27. I would call it `tls` in code, though (and maybe “SSL/TLS” in docs, for clarity).

Re: Why SSL was renamed to TLS in late 90s (2014)

#82
post #27

Curious, when you tell someone they need to access a website securely (or any other case where you might use the term TLS or SSL), do you: 1. Say SSL or TLS? 2. How old are you (or did you start working before 1999?) I'll reply with my answer too.

I think most people call it SSL because they use OpenSSL library to deal with secure communication have SSL in their names. Openssl being the most dominant one). Other libraries are BoringSSL, LibreSSL, wolfSSL etc. Libraries with TLS in their names are less frequently used GnuTLS, mbedTLS, s2n-tls and RustTLS.

SSL is used in websites. TlS is used in other applications, as in mTLS

Re: Why SSL was renamed to TLS in late 90s (2014)

#83
post #27

Curious, when you tell someone they need to access a website securely (or any other case where you might use the term TLS or SSL), do you: 1. Say SSL or TLS? 2. How old are you (or did you start working before 1999?) I'll reply with my answer too.

TLS: Rolls off the tounge easier. Feels nicer in mouth. Easier to slur smoothly. Flows better on keyboard.

It's the ergonomic choice (;

Re: Why SSL was renamed to TLS in late 90s (2014)

#84
post #61

The situation is additionally confused by the fact that the version numbers do not give a good clue to how different the protocols were. Specifically: SSLv2 was the first widely deployed version of SSL, but as this post indicates, had a number of issues. SSLv3 is a more or less completely new protocol TLS 1.0 is much like SSLv3 but with some small revisions made during the IETF standardization process. TLS 1.1 is a r…

> Each of these protocols has been designed so that you could automatically negotiate versions, thus allowing for clients and servers to independently upgrade without loss of connectivity.

And ensuring decades of various downgrade attacks

Re: Why SSL was renamed to TLS in late 90s (2014)

#85

Wouldn't it be appropriate now to call the next version SSL again? It's still widely used by everyone, so let them keep using it.

“TLS” is also used in a bunch of places already, too. Updating config file formats and function signatures will be a PITA.

I would like to see it called SSL again, but agree the cure would be worse than the disease.

Re: Why SSL was renamed to TLS in late 90s (2014)

#86
post #27

Curious, when you tell someone they need to access a website securely (or any other case where you might use the term TLS or SSL), do you: 1. Say SSL or TLS? 2. How old are you (or did you start working before 1999?) I'll reply with my answer too.

SSL, 40s

Re: Why SSL was renamed to TLS in late 90s (2014)

#87
post #83
post #27

Curious, when you tell someone they need to access a website securely (or any other case where you might use the term TLS or SSL), do you: 1. Say SSL or TLS? 2. How old are you (or did you start working before 1999?) I'll reply with my answer too.

TLS: Rolls off the tounge easier. Feels nicer in mouth. Easier to slur smoothly. Flows better on keyboard. It's the ergonomic choice (;

Aside: I think this shared preference for efficiency/comfort/laziness is big part of why master -> main spread quickly while JavaScript -> ECMAScript never had a chance.

I guess it follows that Twitter/X might never be able to pull off a rebrand again.

Re: Why SSL was renamed to TLS in late 90s (2014)

#88
post #27

Curious, when you tell someone they need to access a website securely (or any other case where you might use the term TLS or SSL), do you: 1. Say SSL or TLS? 2. How old are you (or did you start working before 1999?) I'll reply with my answer too.

SSL. Working as a sysadmin since 2010. It just feels more right to me, and honestly, it hasn’t been until recently that I’ve noticed more of a concerted effort to rebrand it to TLS — not sure if that’s just my perception or not.

Re: Why SSL was renamed to TLS in late 90s (2014)

#89
post #27

Curious, when you tell someone they need to access a website securely (or any other case where you might use the term TLS or SSL), do you: 1. Say SSL or TLS? 2. How old are you (or did you start working before 1999?) I'll reply with my answer too.

SSL - In my 40s, over 20 plus years.

When do I say TLS, when that one annoying guy joins the call that always corrects you. Everyone hates him, and he doesn’t care.

Re: Why SSL was renamed to TLS in late 90s (2014)

#90

Earlier quoted context omitted.

They are not. But a Chicago dog is meaningfully the same as a New York Dog (just with some more vegetables).

A Chicago dog is literally a hamburger with a different surface area. Same obscure ground beef, same vegetables, same bread. Just different dimensions. Who cares about the details, right?

Very weird assertion, and happy to be dragged into a sub-post wasteland with you. <3
Post reply on HN