| ▲ | sidewndr46 2 hours ago | |||||||
Couldn't folks just use TLS 1.3? | ||||||||
| ▲ | bawolff 6 minutes ago | parent | next [-] | |||||||
They can and they should, but the world is not a perfect place, so backwards compatibility is neccessary. So long as TLS 1.2 can still be used securely, its really not a big deal. | ||||||||
| ▲ | mjevans an hour ago | parent | prev | next [-] | |||||||
I think the entire point is so that many with devices that will never see updates can still continue to use those devices. | ||||||||
| ||||||||
| ▲ | 0ckpuppet 2 hours ago | parent | prev | next [-] | |||||||
These prescriptions apply only to (D)TLS 1.2, since (D)TLS 1.0 and TLS 1.1 are deprecated by RFC 8996 and (D)TLS 1.3 either does not use the affected algorithms or does not share the relevant configuration options. (There is no DTLS version 1.1.) | ||||||||
| ▲ | ImPostingOnHN 2 hours ago | parent | prev [-] | |||||||
better to break tons of existing installations and require confusing, arcane config file modifications just for folks to get things back to where they were before being broken | ||||||||