Skip to content
This repository has been archived by the owner on May 10, 2024. It is now read-only.

Brave accepts TLS 1.0 and TLS 1.1 without any warning #2867

Open
jumde opened this issue Sep 9, 2020 · 2 comments
Open

Brave accepts TLS 1.0 and TLS 1.1 without any warning #2867

jumde opened this issue Sep 9, 2020 · 2 comments
Labels
priority/P4 Planned work. We expect to get to it "soon". security

Comments

@jumde
Copy link
Contributor

jumde commented Sep 9, 2020

Description

Brave shows that TLS 1.0/1.1 is secure. You have to click on the lock icon to get a warning. But the lock should indicate that BEFORE clicking on it

Steps to Reproduce

  1. go to chair for E-Business of Univerity of Magdeburg or tls-v1-0.badssl.com 1 or tls-v1-1.badssl.com 2
  2. the site is using TLS 1.0 or TLS 1.1 and the lock next to the address bar is closed
  3. klick on the lock and then there will be a warning text

Actual result:

The lock symbol shows a secure connection

Expected result:

The lock symbol should show an "not secure connection"

Reproduces how often:

Every site that uses TLS 1.0 or TLS 1.1

More details here: brave/brave-browser#10607

@jumde jumde added the security label Sep 9, 2020
@iccub
Copy link
Contributor

iccub commented Sep 9, 2020

how do we compare vs other browsers?

@jumde
Copy link
Contributor Author

jumde commented Sep 9, 2020

Other browsers have the same issue.

@diracdeltas diracdeltas added the priority/P4 Planned work. We expect to get to it "soon". label Oct 20, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
priority/P4 Planned work. We expect to get to it "soon". security
Projects
None yet
Development

No branches or pull requests

3 participants