It's time to upgrade to TLS 1.3 already, says CDN engineer

Discussion in 'privacy technology' started by ronjor, Jun 23, 2017.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,072
    Location:
    Texas
  2. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://www.helpnetsecurity.com/2017/07/03/tls-security/
     
  3. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    World celebrates, cyber-snoops cry as TLS 1.3 internet crypto approved
    https://www.theregister.co.uk/2018/03/23/tls_1_3_approved_ietf/
     
  4. RockLobster

    RockLobster Registered Member

    Joined:
    Nov 8, 2007
    Posts:
    1,812
    That's good, last minute concerns about networking nightmares represent the infiltrators that have in the past conspired to weaken and subvert internet security one of the ways they do that is by claiming quite falsely that upgrades will break the internet, when in fact all it takes is a software update. I would hope the honest members of IETF were aware of that and did not allow them to get their way this time.
     
  5. guest

    guest Guest

    Deprecating TLS 1.0 and TLS 1.1 … kill them now!
    June 19, 2018
    https://securityaffairs.co/wordpress/73678/security/tls-10-1-1-deprecation.html
     
  6. guest

    guest Guest

    PayPal reminds users: TLS 1.2 and HTTP/1.1 are no longer optional
    Insecure connections will break after June 30th. And it's acquired Hyperwallet, too
    June 20, 2018
    https://www.theregister.co.uk/2018/06/20/paypal_security_upgrade/
     
  7. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    The PayPal test:

    https://tlstest.paypal.com/

    Even with IE8 it is OK.

    100.JPG
     
  8. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Appear the test is either bogus or Paypal is still accepting TLS 1.1 and 1.2 connections. I am using IE11 and the max. TLS level supported by it is 1.2.

    Thought the test was for TLS 1.3.
     
  9. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    It would be interesting to PayPal test with a non TLS 1.2 browser.
     
  10. guest

    guest Guest

    Preparing for Transport Layer Security 1.3
    The long-awaited encryption standard update is almost here. Get ready while you can to ensure security, interoperability, and performance.
    July 2, 2018

    https://www.darkreading.com/endpoint/preparing-for-transport-layer-security-13-/a/d-id/1332163
     
  11. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    With Firefox,Basilisk and I.E.8 it is easy to remove the Insecure Cipher Suites.
    I can't do it with Chrome:


    Immagine.jpg

    Did someone make it?
     
  12. guest

    guest Guest

    Facebook open sources library to enhance latest Transport Layer Security protocol
    August 06, 2018
    https://techcrunch.com/2018/08/06/f...-up-latest-transport-layer-security-protocol/
     
  13. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,072
    Location:
    Texas
    IETF Publishes TLS 1.3 as RFC 8446
     
  14. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
  15. sdmod

    sdmod Shadow Defender Expert

    Joined:
    Oct 28, 2010
    Posts:
    1,162
    I'm an xp sp3 user. How do I update my machine to this new standard TLS 1.3?
     
  16. sdmod

    sdmod Shadow Defender Expert

    Joined:
    Oct 28, 2010
    Posts:
    1,162
    I use xp sp 3 and this browser is Firefox 6.0 in Paypal test page.

    This is what I get




     

    Attached Files:

  17. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    Update your browser:

    1) Firefox ESR 52.9.0

    2) about:config

    security.tls.version.max set to 4

    3) KB4019276 adds TLS 1.2 support to Windows XP POS READY2009.

    TLS 1.3 support is not yet available for the OS POSReady 2009.

    We confirm that Microsoft engineers are working on it.
     
  18. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    1) No version of Firefox supports Windows XP that also supports TLS 1.3
    2) Firefox uses it's own implementation of TLS, not Windows, lol.
    Even if your "POSReady" does get TLS 1.3 (which I can basically guarantee it won't because mainstream support for every version of POSReady has ended) that won't make Firefox work. You'd have to use IE.

    Firefox 52 ESR ends in 3 weeks.
     
  19. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,366
    Location:
    Italy
    After 3 weeks XP users will be able to use both Basilisk fork for XP and New Moon.

    https://forum.palemoon.org/viewtopic.php?t=19881


    Read MaryRose answers, from Microsoft support, to FranceBB:


    https://msfn.org/board/topic/177693-tls13-xp-and-firefox/
     
    Last edited: Aug 15, 2018
  20. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Neither Pale Moon nor Basilisk support XP.
    If you're relying on trusting unofficial forks then you should just go on random websites and start downloading and running random .exe files.

    LOL. Wow, you're right. A random support staff from web chat said it, so it must be true.

    Good luck buddy.
     
  21. sdmod

    sdmod Shadow Defender Expert

    Joined:
    Oct 28, 2010
    Posts:
    1,162
    I run Windows XP sp3 32 bit
    I have a Firefox Portable 52.4.0 which I tried with the settings below.
    FirefoxPortableESR_52.4.0_English.paf.exe
    I read on https://msfn.org/board/topic/177693-tls13-xp-and-firefox/
    that I could enter about:config in my browser and change
    security.tls.version.max setting from "3" to "4" in about:config
    Although it didn't work for the person on the forum, it seems to have worked for me
    As now I can go to the test sites like https://www.ssllabs.com/ssltest/analyze.html?d=tls13.cloudflare.com
    and the paypal TLS 1.3 test site https://tlstest.paypal.com/ and get the green light A1 passes or an accept rather than a decline.
    I think that he very last version of Firefox that you can get is Firefox Portable 52.9.0 for XP FirefoxPortableLegacy52_52.9.0_English.paf.exe

    As I said it seems to work but I don't know much about these things.
     
    Last edited: Aug 15, 2018
  22. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,072
    Location:
    Texas
    TLS 1.3 Won't Break Everything
     
  23. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    164,072
    Location:
    Texas
  24. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,658
    Thanks Ron.
    See also:
    OpenSSL 1.1.1 Is Released
    https://www.openssl.org/blog/blog/2018/09/11/release111/

    Lots of info there.
    Just these quotes:
     
  25. guest

    guest Guest

    TLS 1.3 updates from Chrome
    October 12, 2018
    https://www.ietf.org/mail-archive/web/tls/current/msg27066.html
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.