I really dislike this "browser smarter than the user" design.
I really dislike this "browser smarter than the user" design.
a) Know what TLS is
b) and, have a secure channel to their destination website that allows them to determine that it intends to serve TLS 1.0
c) and, aren't in a position to just upgrade the darn thing to at least TLS 1.2?
d) and, know that there are no undisclosed weaknesses in the outdated design of TLS 1.0 or in the outdated cryptography that it mandate
Most users fail a). Basically the only way to pass b) is to be the website operator or someone that knows that person or group in real life. But, to pass c), you can't be the operator. Then, finally, no one can really pass d), but, the closest you could get would be to be a part of a sophisticated government sponsored security agency, probably working as a cryptographer and definitely being kept up to date on pretty sensitive intelligence. And for reasons that aren't clear, you are totally fine with the website in question running on outdated crypto - so, in addition, you are probably bad at your job.
How many people fit that description? Those are the people that have a right to consider this a user hostile change. I'm willing to bet its a pretty small group. Everyone else benefits since they either know they can't make a good choice as to whether to accept TLS 1.0 from a website, or, mistakenly think they can.
Supporting old stuff costs time. If the company (or a group of companies) believes they know better, they can contribute the code to change this. And maintain it. Or pay someone else to. It's perfectly viable and it accurately reflects the cost of the business's decision to not change something.
Otherwise no, most browsers must be safe for the lowest common denominator, and they do know better than most.
Users MUST have ultimate control over software and not the other way around; even if it such control is used to do something very stupid. Software deliberately designed to go against the wishes of its users is defective, malicious, or both.
PS: point (d) is a non-point.
I think its quite a stretch to say that Mozilla choosing not to support a technology makes their product "defective" or "malicious". They get to choose what they support. They beauty of open source software, is that if someone disagrees with that decision, they are free to support it themselves. That is unlikely to happen in this case - and that just validates Mozilla's decision.
Point D) is highly relevant - if it's hard for users to present a rational reason that a feature should exist, it further justifies Mozilla not wanting to support it. The IETF, NIST, browser vendors, PCI security standards, vendors such as Cloudflare, etc have all moved away from TLS 1.0 or recommended no longer using it as described in https://tools.ietf.org/html/draft-ietf-tls-oldversions-depre.... That document also lays out various technical reasons to no longer use TLS 1.0. TLS 1.2 has been the recommended version of TLS since 2008 - 10 years ago and it will be 12 years by 2020 when Mozilla stops supporting it. That is all overwhelming evidence that anyone that thinks that they are the special exception for whom using TLS 1.0 makes sense, is almost certainly wrong. People have the right to be wrong, but, it's hardly Mozilla's ethical obligation to enable them.
You can build your own Firefox. You can even download the source and build an old version. What more control do you want?
And yes, it's a heavy handed way, but the fact there are "There are still some essential government, military and corporate websites relying on these protocols that will not be updated any time soon" shows the soft touch isn't working.
Fortunately most of those sites still use "not secure" plain HTTP (I wonder if they're going to remove that too!?), but this feels to me like yet another sad sacrifice of freedom for security, and in this case it's almost --- but not quite --- book-burning. The Internet used to be a much more diverse and interesting place, if perhaps more dangerous; but in encouraging the dominance of this "safe and secure" censorship, sites run by large corporations and centralisation of power into them and the CAs that essentially act as access gatekeepers, I feel like we've lost a lot of what made the Internet a really unique and fun (including the risk) experience.
I think an appropriate real-world analogy is https://en.wikipedia.org/wiki/Slum_clearance
Besides, we all know there will be plenty of organizations that issue convoluted instructions that are the equivalent of "reset your clock to before the cert expiration".
As someone who had to deal with fallout from Equifax, I'm all in favor of smarter, yes smarter, parties acting in the collective security benefit of us all. As you point out, some will drag their feet otherwise.
I'm sure that alternatives will exist for people who know they need to deal with TLS 1.0 for a while longer.
And even as a person who wants to have toggle for everything i don't think this is a good option in this particular case. If someone wants legacy, they can stick with an old browser instead.
With open source software you have every opportunity to customize it to your needs. The question that remains of cause is: Which is more expensive, upgrading the outdated software or maintaining your own Firefox branch.
But uh isn't it better that it breaks in peacetime* than in wartime?
Don’t jeopardize my security just so you can keep living in the Stone Age.