Website Security & Threat Management
Why TLS 1.3 isn't in browsers yet

Why TLS 1.3 isn't in browsers yet

12/26/2017 · Nick Sullivan

What this post added

This post details the challenges and technical reasons behind the delayed adoption of TLS 1.3 in major browsers. It explains the historical context of TLS version negotiation, the impact of the POODLE vulnerability and insecure downgrade attacks, and how these issues led to middlebox ossification and incompatibility with TLS 1.3's design. The post highlights the need for correct implementation of version negotiation and the role of middleboxes in hindering protocol upgrades.

Read the original post ↗