TLS/SSL
TLS 1.0 and 1.1 are dead: why your old protocols are a liability
TLS 1.0 and 1.1 were retired years ago, but plenty of hosts still accept them. Leaving them on is a quiet liability — here is what to support instead.
Tag
TLS 1.0 and 1.1 were retired years ago, but plenty of hosts still accept them. Leaving them on is a quiet liability — here is what to support instead.
The padlock only means encrypted, not strong. Real TLS security depends on three things: which protocols you accept, which ciphers you offer, and your certificate's health.
You have HTTPS — but the first plain-HTTP request is still a weak point. HSTS closes it by telling the browser to never speak HTTP to your site again.