At the IETF 101 meeting, which took place in London last week, the Internet Engineering Task Force (IETF) approved the latest version of the Transport Layer Security Protocol, namely TLS 1.3.
You may know that TLS is the successor to the SSL protocol, which adds a layer of encryption to connections between your device and HTTPS websites or other HTTPS services you visit over the Internet.
The final evolution comes after 27 designs that were created over the past four years through development and discussion. The final 28th design of the protocol improves network security by removing MD5 encryption and SHA-224 hashing algorithms for more secure options such as ChaCha20, Poly1305, Ed25519, x448 and x25519.
TLS 1.3 will reduce connection time by facilitating faster interactions between client and server devices. Additionally, it implements features such as TLS False Start and 0-RTT (Zero Round Trip Time) to reduce latency and connection time for devices that have previously been in contact.
The latest version of the TLS protocol also comes with countermeasures against protocol downgrade attacks. These are carried out by hackers to trick servers that use an older (and more vulnerable) version of the protocol.
The IETF recently released TLS 1.3, but earlier designs of the security protocol have already found support in popular browsers such as Chrome, Firefox, etc. However, incompatibility with middleboxes (like the Blue Coat web proxy) that users encounter was the reason TLS 1.3 was deprecated as the default protocol.
At the moment, various browsers are awaiting the final «token» to add support for the new security protocol in the near future.
