• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / NSA does not use SSL 2.0, SSL 3.0, TLS 1.0 and TLS 1.1

NSA does not use SSL 2.0, SSL 3.0, TLS 1.0 and TLS 1.1

20/01/2021 19:11 by giorgos

The US National Security Agency (NSA) issued a security statement [PDF] this month urging system administrators in federal services and beyond to stop using outdated TLS protocols.

"The NSA recommends using only TLS 1.2 or TLS 1.3 and not using SSL 2.0, SSL 3.0, TLS 1.0 and TLS 1.1," the agency said.

"Using outdated encryption provides a false sense of security, because it seems that sensitive data is protected, even though it is not really so."nsa - NSA do not use SSL 2.0, SSL 3.0, TLS 1.0 and TLS 1.1

Even though the service recommends TLS 1.2 and TLS 1.3, the NSA warns you not to configure these two protocols with weak cryptographic parameters.

"Particularly weak encryption algorithms in TLS 1.2 are defined as NULL, RC2, RC4, DES, IDEA and TDES / 3DES. The cryptographic suites that use these algorithms should not be used ", the service continues.

"TLS 1.3 removes these encryption suites, but implementations that support both TLS 1.3 and TLS 1.2 should be checked for obsolete encryption suites."

The U.S. Department of Homeland Security has released a list of tools on her GitHub profile to help system administrators detect systems on their internal networks that still use outdated TLS protocols

The NSA statement, released on January 5, was repeated yesterday by its counterpart in the Netherlands, the National Cyber ​​Security Center in the Netherlands.

In a similar alert [PDF], the Dutch NCSC also recommends to all Dutch government agencies and private companies to move to TLS 1.3.

In the middle of 2020, the major browsers stopped supporting TLS 1.0 and TLS 1.1, citing security reasons. In March 2020, security company Netcraft reported that some 850.000 websites were still using TLS 1.0 and TLS 1.1 to encrypt traffic with HTTPS, a number that has since declined slowly.

NSA does not use SSL 2.0, SSL 3.0, TLS 1.0 and TLS 1.1 was last modified: 20 January, 2021, 9: 27 mm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: NewsDay: nsa:, TLS

You May Also Like

Ghidra: Free Reverse Engineering from NSA
TLS 1.3 - Windows 10: enabled by default
Linux malware: hackers change targets

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Blender 2.90.0 free 3D drawing program
Next Post: jSQL Injection: Automatic SQL database injection with Java »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.