
Microsoft's silence is either due to poor communication or because this isn't a priority.
Outguess 1.3 software#
And yes, this also results in improved load time timesĤ) all software has vulnerabilities. This is called a “zero round trip.” (0-RTT). The global average RTT latency seen by users of Slack is reported as 200ms after they implemented their all-traffic cdn.Īnother advantage of is that in a sense, it remembers! On sites you have previously visited, you can now send data on the first message to the server. The TLS component is halved.įor customers in Australia connecting to a US Server, that typically means about 200ms cut off the TTFB.Īnd 200ms latency is common. It makes as 50% improvement in setup time for a TLS connection because only 2 instead of 3 total roundtrips are needed.
Outguess 1.3 windows#
Windows keeping an incorrect implementation of TLS out of the operating system which opens up exploits that never existed before, in place of a TLS 1.2 that currently cannot be exploited is foolhardy at best.ġ) TLS1.2 was announced and available to insiders to use within 6 months.Ģ) Responsible maintenance of a community that use your product should include announcing timelines for major updates like this.ģ) the speed difference, as per plenty of real life benchmarks from the companies using it in production today is not insignificant. The two have absolutely NOTHING to do with each other. In other words, EXTREME low end satellite service or extraordinarily busy site to site microwave links.Ĥ. Your part about latency is correct, but in order for latency to come into play in speed - which would manifest only through avoiding some packet loss - you will have to be into latencies of 600-700 milliseconds with high jitter, or 800-900 milliseconds or higher with consistent latency. It doesn't matter how much you insist there will be a measurable difference between 1.3 and 1.2, it wont be there. Mathematical differences in speed are not measurable differences in speed. TLS 1.2 is also not yet exploitable and is better than every incorrect implementation of 1.3 out there.ģ. If you are fine with settling for exploit-ridden, incorrect implementations of 1.3 currently available, then you cannot claim to care about anything you claim to care about in the implementation. Correctly implementing it will take time.
Outguess 1.3 update#
TLS 1.3 is a radical update to the protocol, so much so that it was nearly named TLS 2.0. TLS 1.3 is not the same thing as TLS 1.2. You will see no difference in performance, other than perhaps at low power client No MS did not release support for TLS 1.2 within 6 months. Most (other than the ones where the protocol was fundamentally broken) of the famous SSL and TLS exploits have been created by bad open source solutions that incorrectly implemented SSL/TLS. In addition, these open source projects have also carelessly introduced exploits into TLS 1.3 that do not exist in 1.2, and simply having 1.3 enabled enables downgrade attacks against weaker protocols that can be completely broken.

Outguess 1.3 code#
All efforts so far are based on code written before the standard was ratified and have extreme likelihood of containing legacy code that will provide a vector for exploit. In addition, TLS 1.3 was only ratified a few months ago. MS, RSA and Cisco have the only TLS 1.0 implementations without active exploits because of it where nearly all other implementations do. Microsoft is not like garbage developers - I mean open source developers that race to implement something for the personal gratification rather than for the quality of the product. TLS 1.3 is not a 'badly needed feature' and the speed benefits are not 'immense,' unless you are TLS servers on old consumer level hardware that lack AES accelerators.
