3 ms·
That's why it should be disabled by default but also be overridable. Those users would have to mess with browser flags to re-enable older versions. And if a use
by jake_the_third 8y ago
That's why it should be disabled by default but also be overridable. Those users would have to mess with browser flags to re-enable older versions. And if a user is willing to mess with advanced browser settings without understanding them, there are far worse security settings to mess with than outdated tls protocols.
Users MUST have ultimate control over software and not the other way around; even if it such control is used to do something very stupid. Software deliberately designed to go against the wishes of its users is defective, malicious, or both.
PS: point (d) is a non-point.
- dagenix 8y ago> Software deliberately designed to go against the wishes of its users is defective, malicious, or both. I think its quite a stretch to say that Mozilla choosing not to support a technology makes their product "defective" or "malicious". They get to choose what they support. They beauty of open source software, is that if someone disagrees with that decision, they are free to support it themselves. That is unlikely to happen in this case - and that just validates Mozilla's decision. Point D) is highly relevant - if it's hard for users to present a rational reason that a feature should exist, it further justifies Mozilla not wanting to support it. The IETF, NIST, browser vendors, PCI security standards, vendors such as Cloudflare, etc have all moved away from TLS 1.0 or recommended no longer using it as described in https://tools.ietf.org/html/draft-ietf-tls-oldversions-deprecate-00 https://tools.ietf.org/html/draft-ietf-tls-oldversions-depre.... That document also lays out various technical reasons to no longer use TLS 1.0. TLS 1.2 has been the recommended version of TLS since 2008 - 10 years ago and it will be 12 years by 2020 when Mozilla stops supporting it. That is all overwhelming evidence that anyone that thinks that they are the special exception for whom using TLS 1.0 makes sense, is almost certainly wrong. People have the right to be wrong, but, it's hardly Mozilla's ethical obligation to enable them.
- jake_the_third 8y agoI understand the point you're making, but I still stand by my opinion. Software that goes out of its way to subvert the wishes of the user is defective, malicious, or both.
- sgift 8y agoSpoken like someone who never had to support some old feature because "maybe there is one user who still uses it". Features have a cost. Disabling features and removing them if they are no longer useful for the majority is a valid response to limited resources. I'd rather see Mozilla work on features that are useful and secure than garbage from yesteryear.
- pjc50 8y ago> Users MUST have ultimate control over software and not the other way around You can build your own Firefox. You can even download the source and build an old version. What more control do you want?