4 ms·
If a browser does not support modern TLS (SSL), it probably also has unpatched security flaws. Unpatched browsers should never be used on the Internet because
by StressedDev 2y ago
If a browser does not support modern TLS (SSL), it probably also has unpatched security flaws. Unpatched browsers should never be used on the Internet because they will get hacked.
- Spivak 2y agoSure but as a server operator, who cares? I already have zero trust in the client and it's not my job to punish the user for not being secure enough. If they get pwned, that's their problem. Unless I'm at work where there's compliance checkboxes to disallow old SSL versions I'll take whatever you have.
- o11c 2y agoIf you serve insecurely, that means allowing downgrade attacks and malware injection for clients who are trying to do the right thing. At least if you use HTTP it is blatantly insecure.