top of page


TLS 1.3 hasn't become TLS 1.4.
It has become less tolerant of the past. This month, the IETF published RFC 9846, which replaces RFC 8446 while keeping the protocol as TLS 1.3. On the surface, it looks like a minor revision. It isn't. One change stands out: Implementations MUST NOT negotiate TLS 1.0 or TLS 1.1. Not "SHOULD NOT." Not "avoid where possible." MUST NOT. That matters because we're reaching a tipping point. For years, organisations carried obsolete cryptography because "it still works." Increasin
Brian Couzens
Jul 252 min read
bottom of page
