Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Once these middlebox vendors catch up to TLS 1.3, what's to stop them from breaking the supported versions extension the same way they broke the client version field? Anyone know if Chrome is using/planning to use GREASE with this extension? (Couldn't find anything about it on Google.)


Hopefully efforts like this will make further ossification harder:

https://www.ietf.org/mail-archive/web/tls/current/msg26385.h...


> Once these middlebox vendors catch up to TLS 1.3, what's to stop them from breaking the supported versions extension the same way they broke the client version field

Nothing. It will happen just the same, so TLS 1.4 will have a “actually, this is the extension to use to determine the version”-extension




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: