Category — Page 2

SSL History — Page 2

50 guides on the protocol's timeline, its biggest security failures, and how certificates went from expensive to free.

SSL 2.0: The First, Deeply Flawed Version of the Protocol

Netscape's original 1995 release — broken enough that it's been formally prohibited in TLS since 2011.

Why SSL 3.0 Was Finally Killed Off in 2014

A protocol that lasted 18 years, ended by a single padding-oracle attack.

TLS 1.0: The Protocol's First IETF Standard

1999 — the year Netscape's protocol got a new name, a new steward, and a new number.

TLS 1.1: The Forgotten, Short-Lived Version

Released in 2006, largely skipped by the industry's collective memory of TLS history.

TLS 1.2: The Decade-Long Workhorse

Released in 2008, and still the practical floor for most production TLS configurations today.

The BEAST Attack Explained

2011 — the vulnerability that made CBC-mode cipher weaknesses in TLS 1.0 impossible to ignore.

The CRIME Attack Explained

2012 — when TLS-layer compression turned out to leak information through response size alone.

The Lucky Thirteen Attack Explained

2013 — a timing-based attack on the same CBC-mode weakness family as BEAST.

The Sweet32 Attack Explained

2016 — the vulnerability that finally ended 3DES's long career in TLS.

The DROWN Attack Explained

2016 — proof that a server's old SSLv2 support could compromise its otherwise-modern TLS traffic too.