TLS 1.0 and 1.1 deprecation.
Moderator: satrow
Forum rules
This General Discussion board is meant for topics that are still relevant to Pale Moon, web browsers, browser tech, and related, but don't have a more fitting board available.
Please stick to the relevance of this forum here, which focuses on everything around the Pale Moon project and its user community. "Random" subjects don't belong here, and should be posted in the Off-Topic board.
This General Discussion board is meant for topics that are still relevant to Pale Moon, web browsers, browser tech, and related, but don't have a more fitting board available.
Please stick to the relevance of this forum here, which focuses on everything around the Pale Moon project and its user community. "Random" subjects don't belong here, and should be posted in the Off-Topic board.
TLS 1.0 and 1.1 deprecation.
https://www.ghacks.net/2019/10/02/tls-1 ... -warnings/
Seems google is planning issuing warnings in it's browser about TLS 1.0 and 1.1.
Judging from this these will be deprecated at some point but i would imagine thousands of sites on the web still use these protocols.
Good idea...?.
I know i can simply turn these off in pale moon but would it be prudent to do this now or wait until the googleplex decides it is time.
Any thoughts.?
Seems google is planning issuing warnings in it's browser about TLS 1.0 and 1.1.
Judging from this these will be deprecated at some point but i would imagine thousands of sites on the web still use these protocols.
Good idea...?.
I know i can simply turn these off in pale moon but would it be prudent to do this now or wait until the googleplex decides it is time.
Any thoughts.?
Xenial puppy linux 32-bit.
Tahrpup 6.0.5.32 bit.
Pale moon 28.7.2
Tahrpup 6.0.5.32 bit.
Pale moon 28.7.2
Re: TLS 1.0 and 1.1 deprecation.
You might break lots of sites but that's up to you after all.
Also keep in mind that for many sites you visit, support for a modern cryptographic algorithm isn't even an imperative.
Re: TLS 1.0 and 1.1 deprecation.
Does TLS 1.0 or 1.1 have any known vulnerabilities?
Linux Mint 19.2 Cinnamon (64-bit), Windows 7 (64-bit), Windows 10 build 1803 (64-bit)
"As long as there is someone who will appreciate the work involved in the creation, the effort is time well spent." ~ Tetsuzou Kamadani, Cave Story
"As long as there is someone who will appreciate the work involved in the creation, the effort is time well spent." ~ Tetsuzou Kamadani, Cave Story
Re: TLS 1.0 and 1.1 deprecation.
If the protocols are still secure then i see no reason to not use them but the eggheads in california deem them insecure by default.
Seeing as google has more or less muched the entire web up and gives the mere user it's marching orders or face the consequences then thank god for independant browsers like pale moon.
Does this have long term implications for forks and non google browsers...?
time will tell but considering the web must consist of a large majority of websites using this protocol then maybe not.!!
Google are even dictating drafts and standards on the W3C.
Free and open web...???..not on your nellie and what google says must go.
.
Seeing as google has more or less muched the entire web up and gives the mere user it's marching orders or face the consequences then thank god for independant browsers like pale moon.
Does this have long term implications for forks and non google browsers...?
time will tell but considering the web must consist of a large majority of websites using this protocol then maybe not.!!
Google are even dictating drafts and standards on the W3C.
Free and open web...???..not on your nellie and what google says must go.

Xenial puppy linux 32-bit.
Tahrpup 6.0.5.32 bit.
Pale moon 28.7.2
Tahrpup 6.0.5.32 bit.
Pale moon 28.7.2
- New Tobin Paradigm
- Off-Topic Sheriff
- Posts: 6281
- Joined: 2012-10-09, 19:37
- Location: Sector 001
Re: TLS 1.0 and 1.1 deprecation.
Off-topic:
They have redefined the terms "free" and "open". Please see your political handler for the day's official definition.
They have redefined the terms "free" and "open". Please see your political handler for the day's official definition.

- This is no place for loafers. Join me or die. Can you do any less? -
http://binaryoutcast.com/ | http://thereisonlyxul.org/ | Freenode #binaryoutcast
Re: TLS 1.0 and 1.1 deprecation.
Off-topic:
have all the lexicographers of the world been informed or have google got control of the english language too.!
have all the lexicographers of the world been informed or have google got control of the english language too.!
Xenial puppy linux 32-bit.
Tahrpup 6.0.5.32 bit.
Pale moon 28.7.2
Tahrpup 6.0.5.32 bit.
Pale moon 28.7.2
- Moonchild
- Pale Moon guru
- Posts: 25033
- Joined: 2011-08-28, 17:27
- Location: 58°2'16"N 14°58'31"E
- Contact:
Re: TLS 1.0 and 1.1 deprecation.
I honestly don't get it. these warnings should be sent to server administrators as part of evangelism; what good is it to bother browser users with it?
The protocols themselves are not in any way broken or insecure, merely deprecated, as in something you really shouldn't be using anymore as a server operator. All important financial institutions have already been forced to use TLS 1.2 if they want to be ICS compliant, so...
This is kind of a self-created problem by the https-always-everywhere crowd: servers that might otherwise not have used TLS to begin with, now might be using older server software that doesn't support TLS 1.2 to serve over TLS. Those servers are likely not even in need of https, so what does it matter to the visitor whether they are using an older protocol for stuff that is not critical anyway?
The protocols themselves are not in any way broken or insecure, merely deprecated, as in something you really shouldn't be using anymore as a server operator. All important financial institutions have already been forced to use TLS 1.2 if they want to be ICS compliant, so...
This is kind of a self-created problem by the https-always-everywhere crowd: servers that might otherwise not have used TLS to begin with, now might be using older server software that doesn't support TLS 1.2 to serve over TLS. Those servers are likely not even in need of https, so what does it matter to the visitor whether they are using an older protocol for stuff that is not critical anyway?
"If you want to build a better world for yourself, you have to be willing to build one for everybody." -- Coyote Osborne


Re: TLS 1.0 and 1.1 deprecation.
PR activism meant to be addressed to the clueless user: "Watch out! We care about you and are making the Internet more secure!"
And the worst of it - such kind of cheap PR works! The crowd is buying the bullshit.
However, this time it can be a double-edged sword if some pages won't work and those testing with another browser will realize that the sky isn't falling when accessing those sites.
Re: TLS 1.0 and 1.1 deprecation.
Nobody(website operators, businesses, end users, security experts) cares about anything other than Chrome when it comes to testing or compatibility, these days.
"One hosts to look them up, one DNS to find them and in the darkness BIND them."
Linux Mint 19.2 Xfce x64 on HP i5 laptop with 4 GB RAM, always latest versions of PM & Basilisk unless specified.
Linux Mint 19.2 Xfce x64 on HP i5 laptop with 4 GB RAM, always latest versions of PM & Basilisk unless specified.
- Moonchild
- Pale Moon guru
- Posts: 25033
- Joined: 2011-08-28, 17:27
- Location: 58°2'16"N 14°58'31"E
- Contact:
Re: TLS 1.0 and 1.1 deprecation.
If they test to begin with.
"If you want to build a better world for yourself, you have to be willing to build one for everybody." -- Coyote Osborne


Re: TLS 1.0 and 1.1 deprecation.
This reinforces my earlier comment.This just shows as the web further weaves itself into the future that non google software is going to be in a constant struggle.
Xenial puppy linux 32-bit.
Tahrpup 6.0.5.32 bit.
Pale moon 28.7.2
Tahrpup 6.0.5.32 bit.
Pale moon 28.7.2
-
- Lunatic
- Posts: 312
- Joined: 2015-06-22, 19:48
- Location: USA (North Springfield, Vermont)
- Contact:
Re: TLS 1.0 and 1.1 deprecation.
A good example, IIRC, are images, at least where I come from. At least malware-wise, I normally don't get worried about images hosted on plain-Jane HTTP servers. I remember the internet where images weren't HTTPS.
While I agree about HTTPS being standard, even for images, I suspected that in the past, HTTPS could have caused far more overhead.
- Moonchild
- Pale Moon guru
- Posts: 25033
- Joined: 2011-08-28, 17:27
- Location: 58°2'16"N 14°58'31"E
- Contact:
Re: TLS 1.0 and 1.1 deprecation.
The overhead of TLS has not lessened in any significant way.RJARRRPCGP wrote: ↑2019-10-04, 00:01I suspected that in the past, HTTPS could have caused far more overhead.
"If you want to build a better world for yourself, you have to be willing to build one for everybody." -- Coyote Osborne

