Anything in this story of concern?

Mark Felder feld at FreeBSD.org
Tue Sep 10 19:09:52 UTC 2013


On Tue, Sep 10, 2013, at 14:05, Darren Pilgrim wrote:
> - Leave SSLv3/TLSv1.0 enabled only for cases where you can't control the 
> remote end's SSL capabilities.

Which is what I routinely run into: public webhosting services.

Customers will scream if their website doesn't work on every moderately
reasonable device/browser.

*sigh* you can't win in this game


More information about the freebsd-security mailing list