Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

18
FYI: Notes on TLS/SSL of newsservers
Post Body

I sometimes run a tool to check the TLS/SSL state of well known usenet servers. I post that on a website, but alas my posts with that URL get banned by moderators (because of "backdoor promoting" ... ?).

Overall statistics:

243 known newsservers, of which:

  • 229 provide TSL1.3
  • 14 provide TLS1.2

Nice!

But then: how good is the SSL/TLS they offer? https://github.com/ssllabs/research/wiki/SSL-Server-Rating-Guide offers a guide for "SSL Server Rating Guide", and the tool testssl.sh determines that rating per server.

A reason for a lower rating is still offering TLS1.1 and TLS1, or being vulnerable to well-known attacks like POODLE or providing low ciphers.

The statistics

  • 10  Overall Grade                A    
  • 224  Overall Grade                B     
  • 8  Overall Grade                C     
  • 4  Overall Grade                F

Those B grades are caused by offering TLS1.1 and TLS1 ... so why are usenet providers still offering that? TLS1.2 was introduced in 2008 (14 years ago), and starting from Windows 7 (SP1) and OpenSSL 1.0.1 (2012) it has been supported, so I would say deprecating TLS1.1 and lower would be OK?

Comments
[not loaded or deleted]

Holy sh***, great save!

Author
Account Strength
100%
Account Age
8 years
Verified Email
Yes
Verified Flair
No
Total Karma
140,194
Link Karma
6,938
Comment Karma
132,664
Profile updated: 1 day ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
2 years ago