Ukwakhiwa kwasebusuku kweFirefox kukhubaze ukusekelwa kwe-TLS 1.0 ne-TLS 1.1

Π’ yakha ebusuku IFirefox ngokuzenzakalelayo kukhutshaziwe usekelo lwezivumelwano ze-TLS 1.0 kanye ne-TLS 1.1 (ukulungiselelwa kwe-security.tls.version.min kusethelwe ku-3, osetha i-TLS 1.2 njengenguqulo encane). Ekukhishweni okuzinzile, i-TLS 1.0/1.1 ihlelelwe ukuthi ikhutshazwe ngoMashi 2020. Ku-Chrome, usekelo lwe-TLS 1.0/1.1 luzokwehliswa ku-Chrome 81, okulindeleke ngoJanuwari 2020.

Ukucaciswa kwe-TLS 1.0 kwashicilelwa ngoJanuwari 1999. Eminyakeni eyisikhombisa kamuva, isibuyekezo se-TLS 1.1 sakhululwa ngokuthuthukiswa kokuvikeleka okuhlobene nokukhiqizwa kwama-vector okuqalisa kanye nama-padding. Njengamanje, ikomidi le-IETF (Internet Engineering Task Force) elibambe iqhaza ekuthuthukisweni kwezivumelwano nezakhiwo ze-inthanethi,
kuyaqala ukucaciswa okusalungiswa okwehlisa iphrothokholi ye-TLS 1.0/1.1. Ngokusho kwenkonzo I-SSL Pulse kusukela ngoSepthemba 3, iphrothokholi ye-TLS 1.2 isekelwa amawebhusayithi angama-95.8% avumela ukusungulwa kokuxhumana okuvikelekile, kanye ne-TLS 1.3 - ngo-17.7%. Ukuxhumeka kwe-TLS 1.1 kwamukelwa ngu-75.5% wamasayithi e-HTTPS, kuyilapho ukuxhumeka kwe-TLS 1.0 kwamukelwa ngo-65.5%.

Izinkinga eziyinhloko ze-TLS 1.0/1.1 ukuntuleka kokusekelwa kwama-ciphers esimanje (isibonelo, i-ECDHE ne-AEAD) kanye nemfuneko yokusekela ama-ciphers amadala, ukuthembeka kwawo okubuzwayo kulesi sigaba samanje sokuthuthukiswa kobuchwepheshe bekhompyutha (isibonelo. , usekelo lwe-TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA luyadingeka, i-MD5 ne-SHA zisetshenziselwa ukuhlola ubuqotho kanye nokuqinisekisa -1). Ukusekelwa kwama-algorithms aphelelwe yisikhathi sekuvele kuholele ekuhlaselweni okufana
I-ROBOT, MINZA, BEAST, I-Logjam ΠΈ I-FREAK. Kodwa-ke, lezi zinkinga azizange zibhekwe ngokuqondile njengobungozi bephrothokholi futhi zaxazululwa ngezinga lokusetshenziswa kwayo. Amaphrothokholi e-TLS 1.0/1.1 ngokwawo awanawo ubungozi obubalulekile obungasetshenziswa ukuze kuhlaselwe okwenzekayo.

Source: opennet.ru

Engeza amazwana