SSL 2.0: The First, Deeply Flawed Version of the Protocol
Netscape's original 1995 release — broken enough that it's been formally prohibited in TLS since 2011.
50 guides on the protocol's timeline, its biggest security failures, and how certificates went from expensive to free.
Netscape's original 1995 release — broken enough that it's been formally prohibited in TLS since 2011.
A protocol that lasted 18 years, ended by a single padding-oracle attack.
1999 — the year Netscape's protocol got a new name, a new steward, and a new number.
Released in 2006, largely skipped by the industry's collective memory of TLS history.
Released in 2008, and still the practical floor for most production TLS configurations today.
2011 — the vulnerability that made CBC-mode cipher weaknesses in TLS 1.0 impossible to ignore.
2012 — when TLS-layer compression turned out to leak information through response size alone.
2013 — a timing-based attack on the same CBC-mode weakness family as BEAST.
2016 — the vulnerability that finally ended 3DES's long career in TLS.
2016 — proof that a server's old SSLv2 support could compromise its otherwise-modern TLS traffic too.