Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I predict hereby that this change won't last long.

While cryptographically it's the right move (everything below TLS 1.2 with an AEAD is cryptographically broken), this disables connectivity with half of the Internet. There is a huge number of hosts out there running on legacy hardware that won't do anything beyond TLS 1.0.



We're talking Debian Unstable. That change is at least 2 years out if you're running Testing on your servers or 4 years with Stable. I think that's a reasonable goal.


> That change is at least 2 years out if you're running Testing on your servers or 4 years with Stable. I think that's a reasonable goal.

That's not how the Debian release process works. If everything goes well, that package may hit testing next week[0]; and it may very well be that the next stable release will be in two years.

[0] https://tracker.debian.org/pkg/openssl


If everything goes well, then this change will not have been particularly noteworthy... it is going into Unstable now, and if it causes problems then that is exactly how it works.

Packages are not promoted into (out of?) testing unless they don't have open issues reported against them. If this concerns you, then the right thing to do is to file an issue. Keep it open long enough and this won't make it into the next stable release.


Speaking of, disabling TLS 1.0 is a great way to reduce traffic from unwanted bots. (although I still run TLS 1.1)

If necessary, someone will create a dotdeb-equivalent for an openssl version with TLS 1.0. This is a "dammed if you do, dammed if you don't" type of thing. If they don't disable it, at the next big security issue, everyone will blame openssl/distributions for being negligent.


And those hosts ought to up their game or disappear.

The other way to look at it is that you have security vulnerabilities because a portion of the internet is stuck in a decade old obsolete world.


It's not just about hosts. In developing countries, old generation mobile phones running Android 4.x are extremely common. Google's own metrics show 26% of Android phones are pre-5.0, and that's without the unknown number that don't have Google Services installed.

EDIT: Seems the last version of Android 4 does support TLS 1.2, but there's still a non-zero amount of users on older versions.


Looks like this breaks fetching OpenGraph assets for some popular services, does anyone know which are not compatible? I went TLS 1.2 only a while ago for a personal site, but only tested with Twitter (which does work).

https://twitter.com/AliceWonder32/status/894468549720260608




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: