Mehaho ea bosiu ea Firefox e sitisitse tšehetso bakeng sa TLS 1.0 le TLS 1.1

В kopano ya bosiu Firefox ka ho sa feleng bokooa tšehetso bakeng sa liprothokholo tsa TLS 1.0 le TLS 1.1 (setting ea security.tls.version.min e behiloe ho 3, e behang TLS 1.2 joalo ka bonyane beshene). Litokollong tse tsitsitseng, TLS 1.0/1.1 e reretsoe ho holofala ka Hlakubele 2020. Ho Chrome, tšehetso ea TLS 1.0/1.1 e tla theoleloa ho Chrome 81, e lebelletsoeng ka Pherekhong 2020.

Tlhaloso ea TLS 1.0 e phatlalalitsoe ka Pherekhong 1999. Lilemo tse supileng hamorao, ntlafatso ea TLS 1.1 e ile ea lokolloa ka lintlafatso tsa ts'ireletso tse amanang le tlhahiso ea li-vector tse qalang le padding. Hajoale, komiti ea IETF (Internet Engineering Task Force), e amehang ho nts'etsopele ea liprothokholo tsa marang-rang le meaho,
ntshetsa pele Litlhaloso tsa moralo tse nyenyefatsang liprothokholo tsa TLS 1.0/1.1. Ho ea ka tšebeletso Pulse ea SSL ho tloha ka la 3 September, protocol ea TLS 1.2 e tšehetsoa ke 95.8% ea liwebsaete tse lumellang ho thehoa ha likhokahano tse sireletsehileng, le TLS 1.3 - ka 17.7%. Likhokelo tsa TLS 1.1 li amoheloa ke 75.5% ea libaka tsa HTTPS, ha likhokahano tsa TLS 1.0 li amoheloa ke 65.5%.

Mathata a ka sehloohong a TLS 1.0 / 1.1 ke khaello ea tšehetso bakeng sa li-ciphers tsa morao-rao (mohlala, ECDHE le AEAD) le tlhokahalo ea ho tšehetsa li-ciphers tsa khale, ho tšepahala ha tsona ho belaelloang nakong ea hona joale ea tsoelo-pele ea theknoloji ea k'homphieutha (mohlala. , tšehetso bakeng sa TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA ea hlokahala, MD5 le SHA li sebelisetsoa ho hlahloba botšepehi le ho netefatsa -1). Tšehetso ea li-algorithms tsa khale e se e lebisitse ho litlhaselo tse kang
ROBOT, KHAHLILE, QETELLO, logjam и QETELLO. Leha ho le joalo, mathata ana ha aa ka a nkoa ka ho toba e le bofokoli ba protocol 'me a rarolloa boemong ba ts'ebetsong ea eona. Liprothokholo tsa TLS 1.0/1.1 ka botsona ha li na bofokoli bo boholo bo ka sebelisoang hampe ho etsa litlhaselo tse sebetsang.

Source: opennet.ru

Eketsa ka tlhaloso