Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on sh.itjust.works

5 replies

Were we outdated? I see we're using TLS 1.3 right now, and at least the certificate was last created/renewed before this post (created July 16, post on Aug 6). I know that's not really a metric, but my browser at least has the minimum TLS version set to 3, so I would absolutely have noticed if SJW used anything older.

I guess it's possible we allowed older TLS versions, but at least the version I'm connecting with is completely fine.

1

Not really, here's why:

  • weak ciphers
  • SCSV (protocol fallback)

That's why I didn't go for that thankless job.

2

You reached the end

Please stop using TLS v1.0 and 1.1 | Spyke