Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I agree that there is the absolute need for advocacy. I agree that we need to get rid of old TLS. But I disagree that it’s up to the OSes to make this a compile time issue.

If Debian comes out in 2019 in a state where 30% of the internet can’t talk to it without recompiling the daemon packages, then people will switch to „more compatible“ distros.

I have the infrastructure to quickly deploy patched packages, so for me this is just an annoyance (also because these self-built packages I have to security-patch myself, which is actually putting me at risk), but others don’t. For them this will be a reason to switch distros



thing is chrome and firefox are almost certainly going to disable it well before then, and thats gonna make a shitload of people enable it, not everyone granted, but its going to be a lot lower than 30%


The internet doesn't just consist of Firefox and Chrome. There's mail servers, mail clients, FTP clients, etc.

And Firefox and Chrome can be behind middleboxes and/or personal firewalls that only talk TLS 1.1 on the public-facing side.

And finally, there's a lot of android devices running Android < 5 which all don't support TLS 1.2 and never will.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: