Ulwakhiwo lwasebusuku lweFirefox luyicimile inkxaso ye-TLS 1.0 kunye ne-TLS 1.1

Π’ yakha ngobusuku Firefox ngokungagqibekanga bakhubazekile inkxaso ye-TLS 1.0 kunye ne-TLS 1.1 iiprothokholi (useto lwe-security.tls.version.min lusetelwe ku-3, oluseta i-TLS 1.2 njengoguqulelo olusezantsi). Kukhupho oluzinzileyo, i-TLS 1.0/1.1 icwangciswe ukuba ingasebenzi ngoMatshi ka-2020. KwiChrome, inkxaso ye-TLS 1.0/1.1 iya kuthotywa kwiChrome 81, ekulindeleke ngoJanuwari 2020.

Inkcazo ye-TLS 1.0 yapapashwa ngoJanuwari 1999. Kwiminyaka esixhenxe kamva, uhlaziyo lwe-TLS 1.1 lwakhutshwa ngophuculo lokhuseleko olunxulumene nokuveliswa kweevektha zokuqalisa kunye nokukhuselwa. Okwangoku, ikomiti ye-IETF (i-Internet Engineering Task Force), ebandakanyeka kuphuhliso lweeprothokholi ze-Intanethi kunye nolwakhiwo,
kuphuhlisa idrafti yenkcazo ethoba i-TLS 1.0/1.1 protocol. Ngokwenkonzo I-SSL Pulse ukususela ngoSeptemba 3, i-TLS 1.2 protocol ixhaswa yi-95.8% yeewebhusayithi ezivumela ukusekwa koqhagamshelwano olukhuselekileyo, kunye ne-TLS 1.3 - nge-17.7%. Udibaniso lwe-TLS 1.1 lwamkelwa yi-75.5% yeendawo ze-HTTPS, ngelixa udibaniso lwe-TLS 1.0 lwamkelwa ngu-65.5%.

Iingxaki eziphambili ze-TLS 1.0/1.1 kukunqongophala kwenkxaso yee-ciphers zanamhlanje (umzekelo, i-ECDHE kunye ne-AEAD) kunye nemfuneko yokuxhasa ii-ciphers ezindala, ukuthembeka okubuzwayo kwinqanaba langoku lophuhliso lwetekhnoloji yekhompyutha (umzekelo. , inkxaso ye-TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA iyafuneka, i-MD5 kunye ne-SHA zisetyenziselwa ukujonga imfezeko kunye nokuqinisekiswa -1). Inkxaso ye-algorithms yakudala sele ikhokelele ekuhlaselweni okunje
I-ROBOT, AMANZI, Irhamncwa, ILogjam ΠΈ YOKOHLEKA. Nangona kunjalo, ezi ngxaki azizange ziqwalaselwe ngokuthe ngqo ukuba buthathaka kweprotocol kwaye zasonjululwa kwinqanaba lokuphunyezwa kwayo. Iiprothokholi ze-TLS 1.0/1.1 ngokwazo azinawo ubuthathaka obubalulekileyo obunokusetyenziswa ukwenza uhlaselo olubonakalayo.

umthombo: opennet.ru

Yongeza izimvo