3 ms·
It's possible in some cases. For example, most sites continue to support SSL v3, even though only very old clients do not support TLS v1. So now would be a good
by ivanr 13y ago
It's possible in some cases. For example, most sites continue to support SSL v3, even though only very old clients do not support TLS v1. So now would be a good time to tell those clients that they need to upgrade. If we don't do it now, SSL v3 might become too insecure for error messages. (Like, for example, SSL v2 is today.)
With regards to BEAST, the problem is that a server has no way of telling if a client implements the mitigation technique. The only 100% safe assumption you can make is that the client negotiating TLS 1.0 is vulnerable.
- blueskin_ 13y agoThe server can make an educated guess based on the useragent. If someone is spoofing UA to an older browser, all bets are off, but then they presumably know what they are doing.
- deleted 13y ago[deleted]