That's how IE 6 was killed.
That's how IE 6 was killed.
What killed it was IE6 not supporting TLS1.0 out of the box or TLS1.1+ at all, and that started to make them fail external audits. After years of telling them IE6 was holding us back implementing best-practise security on their instances of our apps¹ and being ignored because doing anything about it their side was too much hassle, external auditors started refusing to give them relevant certificates & such because of their systems not being up to best practise (or even good practise by that point!) and suddenly they made the effort to no longer have anyone in their orgs using IE6.
--------
[0] source: I was working on software serving the banking industry (customer facing & investment sides, not trading) around that time and years either side
[1] Even having annual conversations like:
! The pen test results say you should disable anything below TLS1.0 (and later 1.1), and you haven't. Please do.
? Are you sure? We'd *really* like to, as we've repeatedly mentioned, but that will block your IE6 users.
! Yes! You must follow the recommendations!
? Excellent. Done.
[a short time passes]
! Your application is broken for some of our users!
? Yep. They are using IE6 without TLS enabled.
? Either you need to upgrade their configurations or tell us, in writing please, to break from best practise and reenable the older protocols.
[another short time later]
! Please reenable the older protocols.Unless it's all fud in which case I shall archive this under headcanon.
Some management types might have even seen YouTube potentially blocking IE6 users as an advantage for keeping with IE6 to save bandwidth on their creaking external network links!
Also FE devs using all new Chrome shinny APIs, and their Electron junk are also to blame, and they aren't going to throw their toys away.