Skip to content

Comment on OpenSSL in Debian Unstable drops TLS 1.0/1.1 supportparent

Comments

And those hosts ought to up their game or disappear.

The other way to look at it is that you have security vulnerabilities because a portion of the internet is stuck in a decade old obsolete world.

It's not just about hosts. In developing countries, old generation mobile phones running Android 4.x are extremely common. Google's own metrics show 26% of Android phones are pre-5.0, and that's without the unknown number that don't have Google Services installed.

EDIT: Seems the last version of Android 4 does support TLS 1.2, but there's still a non-zero amount of users on older versions.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.