6 ms·
On a related note, thinking of setting my personal site to TLS 1.3 only. It's still allowing for TLS 1.2 with strong chipers, but except for shutting out anyone
by lazyweb 6y ago
On a related note, thinking of setting my personal site to TLS 1.3 only. It's still allowing for TLS 1.2 with strong chipers, but except for shutting out anyone using older smartphones or operating systems, what's the harm?
Could I fall out of favour with Google & co due to compliance reasons?
Thinking of SSL scan tools like this one [1] which gave me an "F" for how I configure my SSH servers, only allowing for very modern ciphers and kex without backward compatibility.
[1] https://github.com/rbsec/sslscan https://github.com/rbsec/sslscan
- lenish 6y agoRFC7457[1] and Wikipedia[2] offer an overview of many of the attacks on older versions of TLS. Some of those attacks have been mitigated to varying extents in implementations of the affected versions. TLSv1.3 is meant to resolve completely as many of these issues as possible. When using older protocol versions, it can be complicated to validate that the TLS implementation you are using has the necessary mitigations in place. It can be complicated to correctly configure TLS to minimize the effects of known attacks. Doing that properly requires a fair amount of research, threat modelling, and risk assessment both for yourself and on behalf of anyone accessing your website or service. IME, TLSv1.2 is still a big chunk of legitimate web traffic. It has been steadily dropping since standardization, and TLSv1.3 is the majority by a wide margin from what I can see. I wouldn't be surprised to see some websites and services still needing to support it for a couple years more, at least, depending on their target audience. [1] https://tools.ietf.org/html/rfc7457 https://tools.ietf.org/html/rfc7457 [2] https://en.wikipedia.org/wiki/Transport_Layer_Security#Attacks_against_TLS/SSL https://en.wikipedia.org/wiki/Transport_Layer_Security#Attac...
- GoblinSlayer 6y agoMost of those attacks require ssl2 or cooperation from client.
- shaicoleman 6y ago> thinking of setting my personal site to TLS 1.3 only I wouldn't recommend doing that. You might end up blocking users using a proxy (e.g. for privacy reasons), people on corporate networks, people in China [1], and many other non-traditional browsers (e.g. browsers for the blind, game consoles), users on older versions of curl/wget/lynx, older mobile phones, etc. TLS 1.2 when correctly configured is still perfectly fine. And users with modern browsers will connect with TLS 1.3. TLS 1.3 also has protections against downgrade attacks. Another good scanner for SSL is Qualys SSL Server Test [2]. Getting an A+ score there doesn't require disabling TLS 1.2 For secure configuration, you can use Mozilla SSL Configuration Generator [3] 1. https://www.zdnet.com/article/china-is-now-blocking-all-encrypted-https-traffic-using-tls-1-3-and-esni/ https://www.zdnet.com/article/china-is-now-blocking-all-encr... 2. https://www.ssllabs.com/ssltest/ https://www.ssllabs.com/ssltest/ 3. https://ssl-config.mozilla.org/ https://ssl-config.mozilla.org/
- staticassertion 6y ago> perfectly secure. I think you're trying to use 'perfectly secure' here the way one might say 'perfectly fine', which changes the reading a lot from a first pass. That said, I agree, there is a subset of TLS 1.2 that is suitable.
- shaicoleman 6y agoAgreed, updated that
- laurent92 6y agoHonest question but no deep answer requested, why do we have to choose the ciphers? Not only it adds 2^(number of ciphers) ways to misconfigure the server with a gaping security leak, but names are obscure and strings are NEVER the same between nginx and the SSLlabs website which advises what is correct, plus who knows whether SSLLabs is a trustworthy website. Also, 6 months later the ciphers might not be up to date. Why do I have to even choose ciphers? Why isn’t this TLS 1.2.1, then 1.2.2, and so on? It’s like going to Amazon, choosing n resistors by guessing their value, going to m people asking them if it’s 12 ohms, most of them having no clue what they are talking about, and using it for an airport security device that can put people in jail.
- shaicoleman 6y agoDifferent ciphers have different tradeoffs (security/vulnerablities/performance/hardware acceleration/compatibility/newness/etc.). Indeed, more choice means more ways to mess things up, more complexity, more bugs and more vulnerabilities. That's why TLS 1.3 reduces the cipher suite choice to 5 ciphers, down from 37 from TLS 1.2 (in previous versions there were 319 in total) [1] 1. https://owasp.org/www-chapter-london/assets/slides/OWASPLondon20180125_TLSv1.3_Andy_Brodie.pdf https://owasp.org/www-chapter-london/assets/slides/OWASPLond...
- lmm 6y agoBack when TLS (or rather SSL) was originally designed, people were very aware of cipher vulnerabilities - there was a lot of academic attention on them, there was a recent history of ciphers being broken, and US export restrictions forced international programs to support a known-weak cipher (DES). People were much less aware of protocol vulnerabilities - security protocols were nowhere near as widespread and weren't really the subject of academic study. So at the time people expected to need to upgrade ciphers relatively often but upgrade the protocol rarely, if at all, and designing the majority of the protocol to be fixed with the ciphers as a pluggable, swappable part made sense.
- AdrianB1 6y agoBased on the numbers in the other comments, you risk losing ~ 10% of the readers. It is up to you to decide if you want to do it or not.
- oaiey 6y agoIs TLS 1.3 is not rolled out to Windows 10? It rolled out to insider builds during last autumn but did it arrive already to the masses
- walrus01 6y agoWhen I looked into this over 3 years ago, 99%+ of user agents were capable of TLS1.2. I disabled everything below TLS1.2 on all public facing httpd with no negative consequences. I would not recommend going to TLS1.3-only for quite some time yet due to people who are very slow updating their clients.
- rodgerd 6y agoPretty much anyone on the wrong end of middleboxes. A lot of "security" folks and vendors are addicted to MITM of secure network connections. You'll likely find anyone working behind a corporate firewall will be unable to access your site, since most of these folks are determined to break/block 1.3.
- userbinator 6y agoI MITM my own connections too, to do content filtering/adblocking/etc., although in my case the proxy upgrades lower versions to TLS 1.2.
- cmeacham98 6y agoI personally did it recently and it was a breath of fresh air not having to worry about cipher suites or DH params or other garbage as TLS1.3's defaults are secure. Although note that I did see a drop of ~2%-3% in traffic after that. I don't directly make any money of these websites (just my personal blog and similar) and most of my viewers are likely to be technical (i.e. not using IE which doesn't support 1.3), so I decided the sacrifice was worth it for another small reduction in needed sysadmin thought+work.
- gnyman 6y agoI recently did the opposite and re-enabled 1.0 and 1.1 Wrote some thoughts on why here https://blog.nyman.re/2021/02/07/usability-security.html https://blog.nyman.re/2021/02/07/usability-security.html but in short, it's several magnitudes more likely someone will want to check out my blog using a old device vs someone trying to exploit vulnerabilities in the old protocols. Google.com still allows TLS1.0/1.1 https://www.ssllabs.com/ssltest/analyze.html?d=google.com&s=172.217.5.110&hideResults=on&ignoreMismatch=on https://www.ssllabs.com/ssltest/analyze.html?d=google.com&s=...
- lazyweb 6y agoYeah no, that's where I'd draw the line. I have one nginx instance serving my blog and various resources via proxypass (nextcloud, grafana, icinga, kibana etc.). For the sake of keeping things maintainable, there's one wildcard cert for my domain and one global SSL configuration. I'd rather shut out people with Windows XP than enabling < TLS 1.2 globally.
- gnyman 6y agoEveryone has different priorities of course. But note that as long as you use a modern client TLS_FALLBACK_SCSV will ensure you won't be at risk of downgrade attacks or similar. Without that I also don't think I would run it.