A Timeline of TLS Cipher Suite Deprecations
RC4, 3DES, CBC-mode ciphers, and non-forward-secret RSA — a decade of the industry saying goodbye.
Guides on the protocol's timeline, its biggest security failures, and how certificates went from expensive to free.
RC4, 3DES, CBC-mode ciphers, and non-forward-secret RSA — a decade of the industry saying goodbye.
Chrome moving to manage its own trust store independently of the underlying operating system.
A privacy regulation with no explicit HTTPS mandate that still moved the needle significantly.
Free certificates existed before 2015 — just not at the scale or automation that changed the industry.
The same trust-chain concept as a website certificate, applied to software instead of a domain.
Stricter, less forgiving clients that pushed the whole industry toward more careful chain installation.
A transport protocol where, for the first time, encryption isn't a layer bolted on top — it's mandatory by design.
DigiNotar, Comodo, Symantec — different companies, a strikingly similar failure pattern each time.
Not yet a practical threat — but standards bodies are already moving, and it's worth understanding why.
From a minority protocol to the overwhelming default of web traffic, in roughly ten years.