Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you're having to support devices that old then I'd be more worried about how you're going to take payment details on your e-commerce website over a "secure" connection that would fail most PCI DSS vulnerability scans.

The security of TLS has come a long long way since XP and so has research into breaking XP-era ciphers.



Deprecation of old stuff is going incredibly slowly even in rich countries (to the intense frustration of a lot of security teams). Check out the incredible true story, told over years on cabfpub, of the attempt to get rid of SHA-1 in TLS authentication. Notably, the attacks that led to experts' recommendation to move away from SHA-1 immediately were published back in 2005. Meanwhile, Microsoft's "effective date of the SHA-1 deprecation" is tomorrow (!), February 14, 2017.

https://social.technet.microsoft.com/wiki/contents/articles/...

(Let's have a party!)

Figuring out how people are going to get upgraded when problems of some sort are discovered (including software vulnerabilities, not just cryptographic protocol issues) is a major security challenge of our day, maybe the biggest information security problem overall in the world.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: