ืžืื’ืจ NPM ืžื‘ื˜ืœ ืืช ื”ืชืžื™ื›ื” ื‘-TLS 1.0 ื•-1.1

GitHub ื”ื—ืœื™ื˜ื” ืœื”ืคืกื™ืง ืืช ื”ืชืžื™ื›ื” ื‘-TLS 1.0 ื•-1.1 ื‘ืžืื’ืจ ื”ื—ื‘ื™ืœื•ืช ืฉืœ NPM ื•ื‘ื›ืœ ื”ืืชืจื™ื ื”ืžืฉื•ื™ื›ื™ื ืœืžื ื”ืœ ื”ื—ื‘ื™ืœื•ืช ืฉืœ NPM, ื›ื•ืœืœ npmjs.com. ื”ื—ืœ ืžื”-4 ื‘ืื•ืงื˜ื•ื‘ืจ, ื—ื™ื‘ื•ืจ ืœืžืื’ืจ, ื›ื•ืœืœ ื”ืชืงื ืช ื—ื‘ื™ืœื•ืช, ื™ื“ืจื•ืฉ ืœืงื•ื— ื”ืชื•ืžืš ื‘-TLS 1.2 ืœืคื—ื•ืช. ื‘-GitHub ืขืฆืžื•, ื”ืชืžื™ื›ื” ื‘-TLS 1.0/1.1 ื”ื•ืคืกืงื” ื‘ืคื‘ืจื•ืืจ 2018. ื”ืžื ื™ืข ืืžื•ืจ ืœื”ื™ื•ืช ื“ืื’ื” ืœืื‘ื˜ื—ืช ืฉื™ืจื•ืชื™ื” ื•ืœืกื•ื“ื™ื•ืช ื ืชื•ื ื™ ื”ืžืฉืชืžืฉื™ื. ืœืคื™ GitHub, ื›-99% ืžื”ื‘ืงืฉื•ืช ืœืžืื’ืจ NPM ื›ื‘ืจ ืžื‘ื•ืฆืขื•ืช ื‘ืืžืฆืขื•ืช TLS 1.2 ืื• 1.3, ื•-Node.js ื›ืœืœื” ืชืžื™ื›ื” ื‘-TLS 1.2 ืžืื– 2013 (ืžืื– ืฉื—ืจื•ืจ 0.10), ื›ืš ืฉื”ืฉื™ื ื•ื™ ื™ืฉืคื™ืข ืจืง ืขืœ ื—ืœืง ืงื˜ืŸ ืฉืœ ืžืฉืชืžืฉื™ื.

ื”ื‘ื” ื ื–ื›ื™ืจ ื›ื™ ืคืจื•ื˜ื•ืงื•ืœื™ TLS 1.0 ื•-1.1 ืกื•ื•ื’ื• ืจืฉืžื™ืช ื›ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ืžื™ื•ืฉื ื•ืช ืขืœ ื™ื“ื™ IETF (Internet Engineering Task Force). ืžืคืจื˜ TLS 1.0 ืคื•ืจืกื ื‘ื™ื ื•ืืจ 1999. ืฉื‘ืข ืฉื ื™ื ืžืื•ื—ืจ ื™ื•ืชืจ, ืขื“ื›ื•ืŸ TLS 1.1 ืฉื•ื—ืจืจ ืขื ืฉื™ืคื•ืจื™ ืื‘ื˜ื—ื” ื”ืงืฉื•ืจื™ื ืœื™ืฆื™ืจืช ื•ืงื˜ื•ืจื™ ืืชื—ื•ืœ ื•ืจื™ืคื•ื“. ื‘ื™ืŸ ื”ื‘ืขื™ื•ืช ื”ืขื™ืงืจื™ื•ืช ืฉืœ TLS 1.0/1.1 ื”ื™ื ื”ื™ืขื“ืจ ืชืžื™ื›ื” ื‘ืฆืคื ื™ื ืžื•ื“ืจื ื™ื™ื (ืœืžืฉืœ, ECDHE ื•-AEAD) ื•ื”ื™ืžืฆืื•ืช ื‘ืžืคืจื˜ ืฉืœ ื“ืจื™ืฉื” ืœืชืžื™ื›ื” ื‘ืฆืคื ื™ื ื™ืฉื ื™ื, ืฉืืžื™ื ื•ืชื ืžื•ื˜ืœืช ื‘ืกืคืง ื‘ืฉืœื‘ ื”ื ื•ื›ื—ื™ ืฉืœ ืคื™ืชื•ื— ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ืžื—ืฉื•ื‘ (ืœื“ื•ื’ืžื”, ื ื“ืจืฉืช ืชืžื™ื›ื” ื‘-TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื”ืฉืœืžื•ืช ื•ื”ืื™ืžื•ืช ืžืฉืชืžืฉ ื‘-MD5 ื•ื‘-SHA-1). ืชืžื™ื›ื” ื‘ืืœื’ื•ืจื™ืชืžื™ื ืžื™ื•ืฉื ื™ื ื›ื‘ืจ ื”ื•ื‘ื™ืœื” ืœื”ืชืงืคื•ืช ื›ืžื• ROBOT, DROWN, BEAST, Logjam ื•-FREAK. ืขื ื–ืืช, ื‘ืขื™ื•ืช ืืœื• ืœื ื ื—ืฉื‘ื• ื™ืฉื™ืจื•ืช ืœืคื’ื™ืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ ื•ื ืคืชืจื• ื‘ืจืžืช ื”ื”ื˜ืžืขื•ืช ืฉืœื”. ืคืจื•ื˜ื•ืงื•ืœื™ TLS 1.0/1.1 ืขืฆืžื ื—ืกืจื™ื ืคืจืฆื•ืช ืงืจื™ื˜ื™ื•ืช ืฉื ื™ืชืŸ ืœื ืฆืœ ืœื‘ื™ืฆื•ืข ื”ืชืงืคื•ืช ืžืขืฉื™ื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”