How we built it

Remove insecure TLS version fallback (removed)

TLS has a version negotiation mechanism to securely introduce new versions without breaking compatibility. Yet buggy servers implemented this wrong in the past, so browsers were forced to add (non-standard) insecure fallbacks to work around this. Unlike TLS's actual version negotiation, the fallback is insecure. Network attackers can downgrade to weaker versions, despite both client and server supporting newer, more secure versions. Note that this does *not* remove TLS 1.0 and TLS 1.1.

Status in Chromium

Removed (launch bug) in:

  • Chrome for desktop release 50
  • Opera release 37
  • Opera for Android release 37

Consensus & Standardization

  • Shipped
  • No public signals
  • No public signals
  • No signals

Owner

Last updated on 2016-04-25