Industry Concerns about TLS 1.3
ietf.org
Industry Concerns about TLS 1.3
1–6 of 6 posts
Re: Industry Concerns about TLS 1.3
#2Re: Industry Concerns about TLS 1.3
#3So banks want to continue not supporting PFS. Banks can afford to log the private ECDHE key of every connection to decrypt all captured packets at a later date.
Re: Industry Concerns about TLS 1.3
#4Good response https://www.ietf.org/mail-archive/web/tls/current/msg21278.h...
That's amazing.
Re: Industry Concerns about TLS 1.3
#5Wow. My message to the banks: We are trying to build a more secure internet. Update your servers, libraries, etc every few years like the rest of us. You're not special. It's hard for all of us.
Re: Industry Concerns about TLS 1.3
#6The changes in TLS 1.3 are long overdue. There are some of us who argued vociferously to not include some of those bad ciphers but we were overruled, probably by the same cabal that decided to remove IPsec from mandatory-to-implement for IPv6.