Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The title was editorialized. TLS 1.3 is a working draft and Chromium is just doing field trial with it.

A few days ago there were other issues with this causing Chromium to stop working on *.google.com so it's not just about middle-boxes.

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855434

https://bugs.chromium.org/p/chromium/issues/detail?id=693943



TLS1.3 may be a working draft, correctly implementing TLS version negotiation on the other hand is not as it already is a requirement of previous versions.


Sure, it's a working draft, but companies are actively working to develop and test their server side integrations. Having to disable it like this harms those efforts as fewer users are making connections (by default).


While there was a secondary issue with the deployment regarding unofficial builds/derivatives, the field trial was primarily rolled back due to the number of affected customers due to the middle-box issues in their enterprise/edu networks.


Not necessarily just a field trial. AFAIK it was bundled with a recent ChromeOS update, causing logon to fail when MITM'd




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: