The NPM repository ends support for TLS 1.0 and 1.1.

GitHub has decided to discontinue support for TLS 1.0 and 1.1 protocols in the NPM package repository and on all sites related to the NPM package manager, including npmjs.com. Starting October 4, a client that supports at least TLS 1.2 will be required to connect to the repository, including for package installations. Support for TLS 1.0/1.1 on GitHub was already discontinued in February 2018. The motivation cited is a concern for the security of its services and the privacy of user data. According to GitHub, about 99% of requests to the NPM repository are already made using TLS 1.2 or 1.3, and Node.js has included support for TLS 1.2 since 2013 (starting from version 0.10), so the change will only affect a small number of users.

It is worth noting that the TLS 1.0 and 1.1 protocols were officially classified as obsolete technologies by the IETF (Internet Engineering Task Force). The TLS 1.0 specification was published in January 1999. Seven years later, an update, TLS 1.1, was released with security improvements related to the generation of initialization vectors and padding. Among the main issues with TLS 1.0/1.1 is the lack of support for modern ciphers (such as ECDHE and AEAD) and the presence in the specification of requirements to support old ciphers, the reliability of which is now questioned due to advancements in computing technology (for example, support for TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA is required, and MD5 and SHA-1 are used for integrity and authentication checks). Support for outdated algorithms has already led to attacks such as ROBOT, DROWN, BEAST, Logjam, and FREAK. However, these issues were not considered vulnerabilities of the protocol itself and were addressed at the implementation level. There are no critical vulnerabilities in the TLS 1.0/1.1 protocols that can be exploited for practical attacks.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster