Category

SSL History

50 guides on the protocol's timeline, its biggest security failures, and how certificates went from expensive to free.

The Heartbleed Bug and What Changed After

One missing bounds check in OpenSSL exposed private keys across roughly half a million servers.

The Rise of Let's Encrypt

In 2016, a free, automated certificate authority changed what "having HTTPS" cost — and who could afford it.

The POODLE, FREAK, and Logjam Vulnerabilities Explained

Three named attacks in three years, each exploiting a different flavor of intentionally weakened cryptography.

The DigiNotar Breach and the Rise of Certificate Transparency

One compromised Dutch CA, thousands of fraudulent certificates, and the industry response that followed for a decade.

From 40-bit Encryption to Modern TLS: The Crypto Wars of the 1990s

Why early SSL was legally required to be weak outside the US — and how that shaped the web for a decade.

The Symantec Distrust: When Browsers Stopped Trusting a Major CA

The full arc, from the first mis-issuance reports to the final migration deadline.

SHA-1's Slow Death: Why Browsers Deprecated a Whole Hash Algorithm

A decade-long, deliberately gradual retirement — and the research that finally proved it necessary.

The Flame Malware and the MD5 Certificate Forgery That Shook the Industry

A nation-state-grade attack that used a broken hash function to forge a Microsoft-trusted certificate.

How Extended Validation Certificates Rose and Fell

A decade of the green address bar — introduced with confidence, removed after the data came in.

The Road to TLS 1.3: A Decade of Protocol Hardening

Every named vulnerability between 2011 and 2018 fed directly into what TLS 1.3 removed.

Timeline
1995

SSL 2.0 released

Netscape's first public version of SSL. Contained significant weaknesses and was formally prohibited in modern TLS by 2011.

1996

SSL 3.0 released

A full redesign after SSL 2.0's flaws. Widely adopted for over a decade before being deprecated following the POODLE vulnerability in 2014.

1999

TLS 1.0 standardized

The IETF took over the protocol from Netscape and renamed it TLS. Based closely on SSL 3.0.

2008

TLS 1.2 released

Introduced stronger, more flexible cryptographic algorithm support. Remained the dominant version on the web for over a decade.

2014

Heartbleed disclosed

A critical flaw in OpenSSL exposed server memory, including private keys, across a huge share of the internet's HTTPS servers.

2015

Let's Encrypt launches

Free, automated, domain-validated certificates went from a niche idea to the default expectation for the entire web.

2018

TLS 1.3 finalized

A leaner, faster, more secure handshake — and the formal deprecation of legacy cryptographic algorithms still allowed under TLS 1.2.

2018

Chrome marks HTTP as "Not Secure"

Browsers began actively flagging plain HTTP pages, accelerating industry-wide HTTPS adoption.