3 ms·
Apple devices have the same issue. Any device running iOS 8 or lower can’t connect to tls 1.2 sites which is the majority of the internet.
by xacky 6y ago
Apple devices have the same issue. Any device running iOS 8 or lower can’t connect to tls 1.2 sites which is the majority of the internet.
- michalhosna 6y agoHow many devices are running iOS8 or older vs 7.1.1 or older? iOS8 released 2014. Newest iPhone that is stuck on iOS8 or older is iPhone 4 from 2010. Android 7.1.1 released 2016, many devices without any upgrade provided. There are Android phones from 2016 + 2017 that are stuck at 7.1. Apple devices does not have the same problem. (Android upgrade paths are super sad, you almost have to buy new phone every year to stay updated)
- Schnitz 6y agoIt’s really a shame. I had no reason to buy a new phone other than Google ditching support for the Pixel 2, a high priced flagship, after only 3 years. Combine this with how much more Android phones depreciate compared to iPhones (who wants a device you can’t get security updates for) and it’d have been cheaper to buy an iPhone. Needless to say, I didn’t buy another Android. I don’t think the update situation will improve further to be honest, even Google doesn’t care enough to lead by example.
- RinTohsaka 6y agoI have found Lineage OS to be a wonderful solution to this, although I understand this doesn't work easily for the masses.
- cnst 6y ago> Apple devices have the same issue. Let's be real here -- is this a problem with the device, or with site operators? All the major players that promote TLSv1.2 -- Mozilla, Microsoft, Google -- serve their websites over TLSv1.0 just fine. Because they understand that they have to serve old devices to sell products and make money even from such outdated clients, which are still plentiful by the absolute numbers when it's billions of users that we're talking about. In fact, most people aren't even aware of this, but www.google.com itself still works without HTTPS at all. This can easily be verified with curl. Looks like www.bing.com is the same in this aspect; because they gotta make the money from every user as well. But what doesn't work? Wikipedia. Ironically, it's Wikipedia that intentionally engages in planned device obsolescence. Does the read-only access to an encyclopedia editable by anonymous users even require any TLS at all? Really?! And why is noone talking about this? The worst part is that the overwhelming tech community is doing absolutely nothing about this injustice -- about planned device obsolescence by the likes of Wikipedia. Most of these obsoleted TLSv1.0 devices have very fast CPUs and gigabytes of RAM, and are still perfectly capable of browsing most of the internet, and non-technical people are genuinely unaware about these politics w.r.t. TLSv1.2. There's not a single advocacy group that I'm aware of that advocates for the rights of people who cannot use TLSv1.2. Mozilla SSL Configuration Generator is intentionally giving misleading TLS advice that Mozilla itself doesn't adhere to.