Published 10 months ago
Published 10 months ago
M4rcellxD
Updated 10 months ago
0
I’m concerned that the free version of your product still enables outdated and insecure SSL/TLS protocols (TLS 1.0 and TLS 1.1) by default, with no option to disable them or adjust cipher suites. These protocols have been officially deprecated for years and are vulnerable to known attacks.
For a security-focused product, forcing users to allow insecure connections is unacceptable and undermines trust. Please consider updating the free version to disable deprecated protocols by default or allow users to configure supported TLS versions and ciphers. Security should not be a premium-only feature.
Carrie
Updated 10 months ago
0
Thanks for the suggestion. We may optimize this in future versions.
Wil
Updated 9 months ago
agree. a Security Product should have disabled TLS 1.0 and TLS 1.1 disabled by default.
Carrie
Updated 7 months ago
0
Hi <@322021277240000523> The latest version 9.2.7 has resolved this issue. SSL Protocol configuration is now available in the free Personal Edition.