Dhismayaasha habeenkii ee Firefox waxay curyaamiyeen taageerada TLS 1.0 iyo TLS 1.1

Π’ kulanka habeenimo Firefox sida caadiga ah naafo ah Taageerada borotokoolka TLS 1.0 iyo TLS 1.1 (goobaha security.tls.version.min waxa loo dejiyay 3, kaas oo u dhigaya TLS 1.2 nooca ugu yar). Siideynta xasilloon, TLS 1.0/1.1 waxaa la qorsheeyay in la naafo bisha Maarso 2020. Gudaha Chrome, taageerada TLS 1.0/1.1 waxaa lagu tuurayaa Chrome 81, oo la filayo Janaayo 2020.

Tilmaamaha TLS 1.0 waxaa la daabacay Janaayo 1999. Todoba sano ka dib, cusboonaysiinta TLS 1.1 ayaa la sii daayay iyada oo ay weheliso horumarro xagga amniga ah oo la xidhiidha jiilka bilawga vectors iyo suufka. Hadda, guddiga IETF (Internet Engineering Task Force), kaas oo ku lug leh horumarinta borotokoolka internetka iyo dhismaha,
horumariyo qeexid qabyo ah oo meesha ka saaraysa borotokoolka TLS 1.0/1.1. Sida laga soo xigtay adeegga SSL Pulse laga bilaabo Sebtembar 3, borotokoolka TLS 1.2 waxaa taageera 95.8% ee shabakadaha u oggolaanaya samaynta xiriiro sugan, iyo TLS 1.3 - 17.7%. Xidhiidhada TLS 1.1 waxa aqbala 75.5% ee goobaha HTTPS, halka xidhiidhka TLS 1.0 la aqbalay 65.5%.

Dhibaatooyinka ugu waaweyn ee TLS 1.0 / 1.1 waa taageero la'aanta ciphers casriga ah (tusaale, ECDHE iyo AEAD) iyo baahida loo qabo in la taageero ciphers duug ah, taas oo la isku halleyn karo oo la isweydiiyo marxaladda hadda jirta ee horumarinta tignoolajiyada xisaabinta (tusaale ahaan. , Taageerada TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA ayaa loo baahan yahay, MD5 iyo SHA waxaa loo isticmaalaa hubinta daacadnimada iyo xaqiijinta -1). Taageerada algorithms-ka duugoobay ayaa durba horseeday weeraro sida
ROBOT, QURXOON, DHAQAN, logjam ΠΈ FIICAN. Si kastaba ha ahaatee, dhibaatooyinkan si toos ah looma tixgalinin baylahda hab-maamuuska waxaana lagu xalliyay heerkii fulintooda. Hab-maamuuska TLS 1.0/1.1 laftooda ayaa ka maqan baylahda halista ah ee looga faa'iidaysan karo in lagu qaado weeraro la taaban karo.

Source: opennet.ru

Add a comment