• [^] # Re: À vérifier

    Posté par (site web personnel) . En réponse au message Orange ne prend pas (complètement) en charge le TLS - Comment les contacter quand on 'est pas client. Évalué à 2.

    C'est donc bien "de ma faute", il suffirait que je désactive l'option pour que ça remarche !

    Pas du tout.

    TLS 1.1 ne permet pas de garantir l'usage algorithme de chiffrement assez sûrs.
    En gros, tu crois que l'échange est sécurisé, mais il ne l'est pas.

    Il n'y a pas beaucoup de raisons (lesquelles?) pour ne pas passer à TLS 1.2 au minimum. Surtout que ça fait des années que les problèmes de TLS 1.0 et TLS 1.1 sont connus.

    Un extrait de https://github.blog/2017-02-27-crypto-deprecation-notice/

    Cryptographic standards are ever evolving. It is the canonical game of security cat and mouse, with attacks rendering older standards ill-suited, and driving the community to develop newer and stronger standards to take their place. There have been a number of cryptographic attacks over the past of couple of years. These include, but are not limited to, attacks such as POODLE and Logjam . And, while there have been workarounds for some of these attacks, they demonstrated that several cryptographic standards in wide deployment are showing their age and should be retired.

    Notez que ça date de 2017.

    Pourquoi bloquer la publicité et les traqueurs : https://greboca.com/Pourquoi-bloquer-la-publicite-et-les-traqueurs.html