Mozilla brings TLS 1.0/1.1 support back to Firefox

Mozilla Company made a decision temporarily return support for TLS 1.0/1.1 protocols, which were disabled by default in Firefox 74. TLS 1.0/1.1 support will be returned without releasing a new version of Firefox through a system of experiments used to test new features. The reason cited is that due to the coronavirus pandemic COVID-2 people are forced to work from home and cannot access some important government sites that still do not support TLS 1.2.

Let us remind you that in Firefox 74, in order to access sites over a secure communication channel, the server must provide support for at least TLS 1.2. The shutdown was carried out in accordance with recommendations IETF (Internet Engineering Task Force). The reason for refusing to support TLS 1.0/1.1 is the lack of support for modern ciphers (for example, ECDHE and AEAD) and the requirement to support old ciphers, the reliability of which is questioned at the present stage of development of computing technology (for example, support for TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA is required, MD5 is used for integrity checking and authentication and SHA-1). The ability to work with legacy versions of TLS is determined through the security.tls.version.enable-deprecated setting in about:config.

Source: opennet.ru

Add a comment