11 ms·
Removing Old Versions of TLS
- notimetorelax 8y agoThat’s awesome. Server side software should also be actively removing those old protocols.
- themew 8y agoSo if we remove TLS 1.1 from our servers and just offer 1.2, we fail on fallback when testing through Qualys.
- JoshTriplett 8y agoMozilla and Chrome and others will need to work with the various sites testing TLS (and "SSL") to make sure their tests stop asking for this.
- jarfil 8y agoAs far as security goes, that sounds like a good thing.
- regecks 8y agoThere's no reason to remove TLS 1.1 from your server. This change is about the minimum protocol version supported by the browser. Your server can advertise SSLv3 support alongside TLS 1.2, and Chrome 70 will still happily connect to it.
- notatcomputer68 8y ago1. Downgrade attacks. 2. Preventing people from shooting themselves in the foot.
- deleted 8y ago[deleted]
- toast0 8y ago> There's no reason to remove TLS 1.1 from your server. I posit there's no reason to support TLS 1.1 on your server. There are very few clients that support TLS 1.1, but not TLS 1.2. So, either you are willing to support clients on TLS 1.0 (or SSLv3), or you aren't.
- jwilk 8y agoPeople also thought that there's no reason to remove SSLv2 from your server, and then the DROWN attack happened: https://drownattack.com/ https://drownattack.com/ DROWN shows that merely supporting SSLv2 is a threat to modern servers and clients. It allows an attacker to decrypt modern TLS connections between up-to-date clients and servers by sending probes to a server that supports SSLv2 and uses the same private key.
- petecooper 8y agoWhat web server are you using? I'm running numerous servers with just TLS v1.2 and get A+ at Qualys [1]. Not bragging, just curious where you fall down. [1] https://www.ssllabs.com/ssltest/analyze.html?d=tractor.textpattern.com&s=2a03%3ab0c0%3a3%3ad0%3a0%3a0%3ace8%3a2001&hideResults=on https://www.ssllabs.com/ssltest/analyze.html?d=tractor.textp...
- jsjohnst 8y agoYour link shows all the clients you’re blocking. Expand the “unsupported clients” section. You’re currently blocking a lot of clients some folks care about (I say good riddance to them, but not everyone can).
- jsjohnst 8y agoYou don’t “fail” due to lack of 1.1, you can still get an A+ as evidenced by Pete’s link. That said, you’ll notice that his server is blocking a bunch of clients that maybe you care about.
- JoshTriplett 8y agoMost of the pushback here isn't going to be on the web. It's going to be in corporate systems and proxies that haven't upgraded, and reject anything they don't understand. For instance, some corporate proxies will parse TLS and drop connections they don't understand. Theoretically, they do this to combat things like Heartbleed; in practice, they do it because the same tools will (with the flip of a switch) do termination and interception.
- amoshi 8y agoThere are still some essential government, military and corporate websites relying on these protocols that will not be updated any time soon - it should always be possible for a user to override this block. I really dislike this "browser smarter than the user" design.
- pfschell 8y agoEssential has nothing to do with it. Upgrading to a ten year old standard as a minimum is not burdensome. If these services are so critical, they have far bigger problems due to these gaping security holes.
- JoshTriplett 8y agoThis isn't the browser acting smarter than the user; this is the browser trying to push the web forward that last little bit so that everyone is more secure. I'm sure that alternatives will exist for people who know they need to deal with TLS 1.0 for a while longer.
- paxys 8y agoOlder versions of the browser aren't going anywhere. Users are free to keep them as long as they want.
- zabuni 8y agoThis will give the techies a reason to give to their bosses to pay off that technical debt that has accrued with these systems. Every system that uses outdated websites will need to upgrade. And they will have two years to do it. It makes the argument go from the nebulous "it will make us safer" to the concrete "things will not work". And yes, it's a heavy handed way, but the fact there are "There are still some essential government, military and corporate websites relying on these protocols that will not be updated any time soon" shows the soft touch isn't working.
- petecooper 8y agoIf you want Nginx to use TLS v1.2, this is what you need: ssl_protocols TLSv1.2; …and if you compile a recent Nginx from source and bake in OpenSSL 1.1.1 while you do that, you can have TLS v1.3 with a TLS v1.2 fallback, too: ssl_protocols TLSv1.3 TLSv1.2; See also: https://caniuse.com/#feat=tls1-2 https://caniuse.com/#feat=tls1-2 https://caniuse.com/#feat=tls1-3 https://caniuse.com/#feat=tls1-3
- tialaramex 8y agoThis is a bad design by nginx, how many people configuring a web server are thinking to themselves "I better check which version of OpenSSL I compiled with in order to set the appropriate TLS versions?". I'd guess approximately none. The correct design would be something like: tls_minimum_version 1.2; If they feel a compulsion to do so they could add a maximum version, but with a default of (none) and an explicit warning that this probably isn't what you wanted to change.
- benchaney 8y agotls 1.3 is still very new, so it makes sense that it would have both compile time and runtime concerns. Unless you are specifically trying to use tls 1.3 (which isn't most people), you don't need to turn it on, even if it is compiled in. Of course if you are specifically trying to use it, you probably know how you compiled nginx. So really it isn't bad design at all.
- anderskaseorg 8y agoI reported this four years ago with a patch at https://trac.nginx.org/nginx/ticket/642 https://trac.nginx.org/nginx/ticket/642. Nobody seems to have noticed.
- ploxiln 8y agoThe default includes TLSv1.2 (along with TLSv1.1 and TLSv1). So the default does and will continue to use TLSv1.2 with browsers that support it, and will still work when browsers disable TLSv1 and TLSv1.1
- 8y ago
- nindalf 8y agoSide note unrelated to TLS. Using telemetry Mozilla was able to precisely measure how many connections are actually established with TLS 1.0 and 1.1. Without numbers, they'd have been flying blind, making decisions with no rational basis. That's why I personally choose to leave telemetry on in applications that I trust. It helps the dev makes sensible, data-driven decisions.
- deleted 8y ago[deleted]
- flukus 8y agoThe information from people that explicitly opt-in would have given them the same insight. > That's why I personally choose to leave telemetry on in applications that I trust The problem is that when I have to "leave it on" rather than explicitly enable it then it's no longer an application I trust.
- esrauch 8y agoThe opt-in information would be skewed to the point of uselessness though right, thanks to extreme correlation? In fact, the non-opt out is probably pretty skewed itself so some wrong data driven decisions are inevitable.
- smichel17 8y agoThere's a third, seldom-discussed alternative to opt-in and opt-out: no default. On first launch or after a set period, show a non-dismissable dialog asking users to choose between the two, with no default option selected, so you can't just click through. This strikes me as the best compromise between respect for user privacy and acknowledging that data collection can be useful, with the trade-off that some users will choose not to use the software/website rather than decide on an option (thus, 'no default' must be used sparingly).
- cpeterso 8y ago
- jandrese 8y agoI kind of wish they'd leave the option to re-enable them in extreme circumstances. It's really annoying to try to bring up the web interface on some crusty old piece of hardware and discovering that the SSL/TLS negotiation can't find a workable solution.
- CorpusCalcium 8y agoAssuming that device is actually worth accessing, then you could still keep and use an old version of a browser for that purpose. Newer browser versions should be pushing the web forward where possible.
- jeroenhd 8y agoI agree with you in the case of old encryption methods (plain DES, RC4, NULL cipher) but not all protocol problems are because of the lack of a recent encryption algorithm. There's heaps of old modems that use a weak DH key and will never see a firmware update. You're left with either accessing the device insecurely over HTTP, hoping your ISP will send you a new one (good luck with that) or paying for your own modem which will probably never be allowed on the ISPs network. Weak DH keys should not be that hard to keep in the code base yet still most browsers will present an impassable TLS error screen.
- CorpusCalcium 8y agoThose modems should no longer be being used, period. If someone cannot afford a replacement and has an incompetent ISP incapable of providing them with a subsidized replacement, then that is a separate problem that needs addressing as soon as possible. Perpetuating it won't do, and if in doing so we're perpetuating a larger impending security issue, then we need to resolve it stat, not defer everything because there is heaps of old hardware lying around. That may be easy to say and harder to resolve, but there comes a time when problems need to be resolved. Maybe that won't be 2020, if the desired timeline proves unrealistic, but two years is plenty of time to move on it. It generally takes far longer to deprecate and remove protocols from the web than it does to get a replacement modem.
- kccqzy 8y agoApple is doing the same: https://webkit.org/blog/8462/deprecation-of-legacy-tls-1-0-and-1-1-versions/ https://webkit.org/blog/8462/deprecation-of-legacy-tls-1-0-a...
- Ajedi32 8y agoAnd Chrome: https://security.googleblog.com/2018/10/modernizing-transport-security.html https://security.googleblog.com/2018/10/modernizing-transpor... And Edge: https://blogs.windows.com/msedgedev/2018/10/15/modernizing-tls-edge-ie11/ https://blogs.windows.com/msedgedev/2018/10/15/modernizing-t... Seems like this was coordinated.
- mathw 8y agoChrome's seems to be the only announcement that doesn't mention it's coordinated with the other major browser vendors. Dominant position talking :(
- fouc 8y agoDoes anyone think that all this security handling stuff should be kept separate from the browser and moved into a local proxy that handles this? So that people with old browsers or other clients can still access the web.
- devit 8y agoWhat needs to be dropped the most are non-TLS non-localhost http:// http:// URLs.
- mobilemidget 8y agoInteresting, including the comments on HN. But personally I wonder more when we can disable old TLS versions for MTAs
- jeroenhd 8y agoA lot of MTAs are improperly configured. There's still a lot of plain text email sent across the Internet. The secure mail servers often have trouble connecting to anything with a TLS version higher than 1.0 (if even that). Many mail servers also don't have a valid server certificate (self-signed, expired or even from the wrong domain). In my opinion, the email ecosystem is hopeless with regards to TLS security. Gmail started showing red padlocks for plaintext or insecurely sent emails a while back and I still see the red pad lock to this day. Bexause of this, disabling old TLS versions could make your server unreachable for large parts of the Internet or have servers fall back to plain text if they're improperly configured. Nobody wants to be that one company that can't receive your grandma's emails so everybody just keeps accepting improper configuration. Another problem is that a lot of MDA servers share their TLS config with the MTA side. I know from experience (worked at a small company that upgraded their email servers to TLS 1.2, at least on the MDA side) that old Microsoft mail clients (Office 2007 and lower, Windows Live Mail 2012) have trouble with TLS 1.2, especially on older Windows versions. Although these clients have all been deprecated for a long time, a lot of users with few tech skills still use them because that's what their PC was set up with years ago when they bought it, or because they don't want to waste their time learning how to deal with a new UI (you can see this with a lot of elderly people). For programs that use the Windows 7 TLS libraries TLS 1.2 is even disabled by default in Windows 7 because at the time Windows 7 launched, other implementations had major bugs. It can be enabled using a registry key though. This includes Office 2010, which still gets security fixes from Microsoft. So, if a large company would disable TLS 1.0/1.1 on their MTAs it might get a large amount of customer support calls from their least technical customer base. You can tell your customers that their program is out of date and that their program is the reason they're getting errors, but in the end the customer will still blame you for "breaking their mail program". Aside from a massive blow to a company's reputation, this would also overload the customer support desk and cost a lot of man hours. <edit> Actually, I've seen the built in mail app for Samsung smart phones fail on TLS 1.2 for Android versions up to Android 8. Other Android vendors generally have trouble up to Android 5/6. With the lack of system updates on the Android ecosystem, this could be an even bigger problem. </edit> I believe disabling old TLS versions is the right thing, but not until large parties such as Microsoft and Google decide to take the first step if you still want your server to receive any email.
- jaclaz 8y agoAlso, probably it will affect accessing a range of hardware devices that include a web interface (such as routers). A recent example: https://msfn.org/board/topic/177834-modern-browsers-and-legacy-network-devices/ https://msfn.org/board/topic/177834-modern-browsers-and-lega...