4 ms·
Author here. I'd figured they were big, but I had no idea that big until I did a www-wide TLS scan. Here for questions
by lsb 7y ago
Author here. I'd figured they were big, but I had no idea that big until I did a www-wide TLS scan. Here for questions
- mmalone 7y agoKinda surprised that Google is so much bigger than Amazon...
- lsb 7y agoBlogspot!
- mmalone 7y agoThat's just stupid enough to be the answer :).
- simcop2387 7y agoKeep in mind that Amazon now offers their own free certs for customers that aren't from LE. That probably also has a big impact on things.
- mmalone 7y agoYea that's why I'm surprised that Google has issued more certs than Amazon has :P.
- tialaramex 7y agoYou list the ciphersuite that got chosen for each connection, but I think this could use at least a caveat explaining that the way this works means you'd need to do a LOT more work to figure out what the servers might have agreed to do for some other client. What I mean here is that TLS up until TLS 1.2 goes like this: Client: "Hi, I know ciphersuites A, B, C, D, E, F and G" Server: "OK, let's do C" And so you can't tell whether the server actually knows A, B, D, E, F, G or even I through Z. They just decided to pick C this time for some reason. In TLS 1.3 it's sort of better (all of the ciphersuites you shouldn't use don't exist any more) and sort of worse because now it goes: Client: "Hi, let's do method B, I'll go first, 123456 and a goldfish and the colour yellow" Server: "Cool, method B works for me, I pick 567890, a swan and mauve" Probably all TLS 1.3 servers today are willing to do anything method not just method B, since all the methods are shiny and new. But perhaps not, and you can't tell except by failing the connection which takes more round trips.
- jefftk 7y ago> Probably all TLS 1.3 servers today are willing to do anything method not just method B, since all the methods are shiny and new. But perhaps not, and you can't tell except by failing the connection which takes more round trips. You can have a round trip all the time, or just in the case where the client chooses an ciphersuite the server doesn't support. TLS 1.3 makes the typical cases much better without hurting the worst case much.
- achillean 7y agoWith regards to the supported SSL/ TLS versions you can get that information from Shodan. We do explicit handshakes using each version. For example, here is an overview of servers supporting TLS 1.3: https://www.shodan.io/report/unklm3m7 https://www.shodan.io/report/unklm3m7 Disclaimer: I run Shodan.
- walrus01 7y agoGiven that the population of browser useragents that only understand TLS1.0 and TLS1.1 is under 1% now, I've set all of my public facing apache2 httpd to only speak TLS1.2 and better. Have had things that way for about two years now and with zero reported usability issues.