
Microsoft announced yesterday that it will delay disabling the insecure Transport Layer Security (TLS) 1.0 and 1.1 protocols in its web browsers due to the current global situation. Support for disabling by default will likely be in the second half of 2020, most likely in July.
"For the new Microsoft Edge (based on Chromium), TLS 1.0 and 1.1 protocols will not be disabled by default before the release of Microsoft Edge 84 (currently planned for July 2020)," said Kyle Pflug, lead of the Microsoft Edge Developer team.
“For all supported versions of Internet Explorer 11 and Microsoft Edge Legacy (based on EdgeHTML), TLS 1.0 and TLS 1.1 will be disabled by default on September 8, 2020.”
Users will be able to revert to TLS 1.0 and TLS 1.1 even after disabling, but Microsoft recommends switching to newer, more secure protocols. The latest versions of TLS have more modern encryption and are widely supported by modern browsers .
TLS protocol "retirement" plans
Earlier this month, Mozilla said that support for insecure TLS would be re-enabled in the latest version of Firefox, so that users could access government sites providing information about COVID -19. These sites have not yet been upgraded to newer TLS versions.
A few days earlier, Mozilla had removed support for TLS 1.0 and TLS 1.1 in Firefox 74.0 , which was released on March 10.
The "retirement" of these insecure protocols from the list of supported protocols had already been announced in October 2018 by all major browser manufacturers (Microsoft, Google, Apple, Mozilla).
Microsoft had said at the time that these protocols would be disabled at some point in the first half of 2020.
Over 97% of sites surveyed by Qualys SSL Labs support the insecure TLS 1.2 or TLS 1.3 protocols , making it important to implement new, more secure protocols to protect this vast number of sites.
According to usage statistics shared at the time by Microsoft, Google, Apple and Mozilla, the vast majority of users no longer use these protocols.
On the other hand, Netcraft reported in early March that the insecure TLS 1.0 and TLS 1.1 protocols are still being used on more than 850,000 sites, exposing users to great risk.
“The use of TLS 1.0 on e-commerce sites, as a measure to protect user data, was prohibited by the Payment Card Industry Data Security Standard, as of June 2018, which is why many sites have already switched to other protocols,” Netcraft explained.
