4 ms·
There are still some essential government, military and corporate websites relying on these protocols that will not be updated any time soon - it should always
by amoshi 8y ago
There are still some essential government, military and corporate websites relying on these protocols that will not be updated any time soon - it should always be possible for a user to override this block.
I really dislike this "browser smarter than the user" design.
- pfschell 8y agoEssential has nothing to do with it. Upgrading to a ten year old standard as a minimum is not burdensome. If these services are so critical, they have far bigger problems due to these gaping security holes.
- JoshTriplett 8y agoThis isn't the browser acting smarter than the user; this is the browser trying to push the web forward that last little bit so that everyone is more secure. I'm sure that alternatives will exist for people who know they need to deal with TLS 1.0 for a while longer.
- paxys 8y agoOlder versions of the browser aren't going anywhere. Users are free to keep them as long as they want.
- zabuni 8y agoThis will give the techies a reason to give to their bosses to pay off that technical debt that has accrued with these systems. Every system that uses outdated websites will need to upgrade. And they will have two years to do it. It makes the argument go from the nebulous "it will make us safer" to the concrete "things will not work". And yes, it's a heavy handed way, but the fact there are "There are still some essential government, military and corporate websites relying on these protocols that will not be updated any time soon" shows the soft touch isn't working.
- notatcomputer68 8y ago> military But uh isn't it better that it breaks in peacetime* than in wartime?
- dagenix 8y agoHow many users: a) Know what TLS is b) and, have a secure channel to their destination website that allows them to determine that it intends to serve TLS 1.0 c) and, aren't in a position to just upgrade the darn thing to at least TLS 1.2? d) and, know that there are no undisclosed weaknesses in the outdated design of TLS 1.0 or in the outdated cryptography that it mandate Most users fail a). Basically the only way to pass b) is to be the website operator or someone that knows that person or group in real life. But, to pass c), you can't be the operator. Then, finally, no one can really pass d), but, the closest you could get would be to be a part of a sophisticated government sponsored security agency, probably working as a cryptographer and definitely being kept up to date on pretty sensitive intelligence. And for reasons that aren't clear, you are totally fine with the website in question running on outdated crypto - so, in addition, you are probably bad at your job. How many people fit that description? Those are the people that have a right to consider this a user hostile change. I'm willing to bet its a pretty small group. Everyone else benefits since they either know they can't make a good choice as to whether to accept TLS 1.0 from a website, or, mistakenly think they can.
- Groxx 8y agoTo add to this: Supporting old stuff costs time. If the company (or a group of companies) believes they know better, they can contribute the code to change this. And maintain it. Or pay someone else to. It's perfectly viable and it accurately reflects the cost of the business's decision to not change something. Otherwise no, most browsers must be safe for the lowest common denominator, and they do know better than most.
- jake_the_third 8y agoThat's why it should be disabled by default but also be overridable. Those users would have to mess with browser flags to re-enable older versions. And if a user is willing to mess with advanced browser settings without understanding them, there are far worse security settings to mess with than outdated tls protocols. Users MUST have ultimate control over software and not the other way around; even if it such control is used to do something very stupid. Software deliberately designed to go against the wishes of its users is defective, malicious, or both. PS: point (d) is a non-point.
- lousken 8y agoif military and government sites rely on old encryption schemes i think there's much bigger problem than that And even as a person who wants to have toggle for everything i don't think this is a good option in this particular case. If someone wants legacy, they can stick with an old browser instead.
- colemickens 8y agoGovernment, military, and corporations. Exactly the people I want pushing critical data (or my data) over insecure channels. /s Besides, we all know there will be plenty of organizations that issue convoluted instructions that are the equivalent of "reset your clock to before the cert expiration". As someone who had to deal with fallout from Equifax, I'm all in favor of smarter, yes smarter, parties acting in the collective security benefit of us all. As you point out, some will drag their feet otherwise.
- userbinator 8y agoNot to mention "fringe" websites that still contain much useful information, are occasionally found in search engines, and more frequently in bookmarked site lists... gov/mil/corp have plenty of resources to add new TLS versions, but just not always the willingness to, and that isn't so bad since "adding willingness" is not impossible; it's really the "small players" out there which will be most affected, those who have personally maintained sites or even sites abandoned on servers for a long time. Fortunately most of those sites still use "not secure" plain HTTP (I wonder if they're going to remove that too!?), but this feels to me like yet another sad sacrifice of freedom for security, and in this case it's almost --- but not quite --- book-burning. The Internet used to be a much more diverse and interesting place, if perhaps more dangerous; but in encouraging the dominance of this "safe and secure" censorship, sites run by large corporations and centralisation of power into them and the CAs that essentially act as access gatekeepers, I feel like we've lost a lot of what made the Internet a really unique and fun (including the risk) experience. I think an appropriate real-world analogy is https://en.wikipedia.org/wiki/Slum_clearance https://en.wikipedia.org/wiki/Slum_clearance
- creatonez 8y agoThis will almost certainly have an `about:config` option (it has one right now)
- mrweasel 8y agoHonestly if you still need something that clearly deprecated, and you're given a two year warning (if not more) then you can just fork Firefox and put the old TLS versions back. With open source software you have every opportunity to customize it to your needs. The question that remains of cause is: Which is more expensive, upgrading the outdated software or maintaining your own Firefox branch.
- rythie 8y agoWhy wouldn't they just put a TLS1.2 reverse proxy infront of whatever legacy system is there? or use cloudflare? that'd be way easier than telling people to reconfigure their browsers to be insecure everywhere on the web.
- TheCoelacanth 8y agoIf you can afford to spend $1 trillion on a fighter plane that is marginally better than the previous ones that you already had, you can afford to spend $100k on basic network security.
- tinus_hn 8y agoThen don’t upgrade the browser. Don’t jeopardize my security just so you can keep living in the Stone Age.