Kuvaka kwehusiku kweFirefox kwakadzima rutsigiro rweTLS 1.0 uye TLS 1.1

Π’ ungano yousiku Firefox by default kuremara tsigiro yeTLS 1.0 uye TLS 1.1 maprotocol (security.tls.version.min kusetwa kune 3, iyo inogadza TLS 1.2 sedikidiki vhezheni). Mukuburitswa kwakagadzikana, TLS 1.0/1.1 yakarongerwa kuve yakaremara munaKurume 2020. MuChrome, tsigiro yeTLS 1.0/1.1 ichadonhedzwa muChrome 81, inotarisirwa muna Ndira 2020.

Iyo TLS 1.0 yakatarwa yakaburitswa muna Ndira 1999. Makore manomwe gare gare, iyo TLS 1.1 yekuvandudza yakaburitswa nekuvandudzwa kwekuchengetedza zvine chekuita nechizvarwa chekutanga mavheji uye padding. Parizvino, iyo IETF (Internet Engineering Task Force) komiti, iyo inobatanidzwa mukuvandudza kweInternet protocol uye zvivakwa,
inokura dhizaini yakatarwa inobvisa TLS 1.0/1.1 mapuroteni. Maererano neshumiro SSL Pulse kubva munaGunyana 3, iyo TLS 1.2 protocol inotsigirwa ne95.8% yemawebhusaiti anobvumira kugadzwa kwekubatana kwakachengeteka, uye TLS 1.3 - ne17.7%. TLS 1.1 yekubatanidza inogamuchirwa ne75.5% yeHTTPS nzvimbo, ukuwo TLS 1.0 yekubatanidza inogamuchirwa ne65.5%.

Matambudziko makuru eTLS 1.0/1.1 kushaikwa kwerutsigiro rwemaciphers emazuva ano (semuenzaniso, ECDHE neAEAD) uye chinodiwa chekutsigira maciphers ekare, kuvimbika kwacho kunobvunzwa panguva ino yekuvandudza tekinoroji yekombuta (semuenzaniso. , tsigiro yeTLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA inodiwa, MD5 neSHA dzinoshandiswa pakuongorora kuvimbika nekusimbisa -1). Tsigiro yealgorithms yechinyakare yakatotungamira mukurwiswa senge
ROBOT, NYORA, CHIKARA, logjam ΠΈ FREAK. Nekudaro, matambudziko aya haana kutariswa zvakananga kukanganiswa kweprotocol uye akagadziriswa pamwero wekuita kwayo. Iyo TLS 1.0 / 1.1 maprotocol pachawo anoshaya hutete hwakanyanya hunogona kushandiswa kuita kurwisa kunoshanda.

Source: opennet.ru

Voeg