4 ms·
I think the only reliable way to prevent downgrade attacks in the face of potentially arbitrarily broken old versions is to have a field in the server certifica
by bcoates 9y ago
I think the only reliable way to prevent downgrade attacks in the face of potentially arbitrarily broken old versions is to have a field in the server certificate promising that the server supports particular protocol versions.
If that were in place, if a client that supports TLS 1.3 received a cert that says "all servers on example.org support TLS 1.3 (and also possibly older or newer versions)" then the client would refuse to downgrade even if the server needed to offer old protocols for old clients.
Otherwise whatever mechanism you use to send old clients to legacybrowser.example.com could (potentially) be corrupted to trick non-legacy browsers into going there.
- sitkack 9y agoI was also thinking that the connection terminator would only let legacy clients use the legacy endpoint, at at least known-non-legacy clients would be forced to communicate with the TLS 1.3 endpoint.