Skip to content

Comment on The POODLE bites again

Comments

We look forward to TLS 1.2 support being the norm. (And then, hopefully, the ratification and adoption of TLS 1.3)

A 50% adoption rate is excellent news. Still a long way to go, but that's worth toasting over.

What is frustrating is how many such servers have TLS 1.3 intolerance (even PayPal), and often the same servers are also affected by this bug. I wonder what TLS implementation is this.

TLS 1.3 isn't finished yet...

I know, the goal is to prepare.

I'm not sure what you mean then by servers having TLS 1.3 intolerance.

It does not respond properly to clients trying to negotiate TLS 1.3. It should return a ServerHello showing the supported TLS 1.2 version.

I wasn't aware there was a TLS 1.3 PoC that people could use for testing.

It is as simple as setting the version in the ClientHello message.

Oh, I see

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.