<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Opera 12.17 Build 1863 TLS 1.1 1.2]]></title><description><![CDATA[<p dir="auto">hello</p>
<p dir="auto">is it safe to enable TLS 1.1 and 1.2 and disable the insecure cipher suites ?</p>
<p dir="auto">Your client supports cipher suites that are known to<br />
be insecure:<br />
TLS_RSA_WITH_RC4_128_MD5: This cipher use RC4 which has insecure biases in its output.<br />
TLS_RSA_WITH_RC4_128_SHA: This cipher use RC4 which has insecure biases in its output.</p>
<p dir="auto">thx for help</p>
]]></description><link>https://forums.opera.com/topic/10903/opera-12-17-build-1863-tls-1-1-1-2</link><generator>RSS for Node</generator><lastBuildDate>Sun, 14 Jun 2026 04:53:30 GMT</lastBuildDate><atom:link href="https://forums.opera.com/topic/10903.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 19 Jul 2015 14:10:12 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Mon, 20 Jul 2015 00:16:27 GMT]]></title><description><![CDATA[<p dir="auto">Thanks for the security tips Lando.</p>
<p dir="auto">I think the OP and I are in the same boat, wondering how best to hang on to 12.17 for email as long as possible and when to let it go.  We need a guru.</p>
]]></description><link>https://forums.opera.com/post/80174</link><guid isPermaLink="true">https://forums.opera.com/post/80174</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Mon, 20 Jul 2015 00:16:27 GMT</pubDate></item><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Sun, 19 Jul 2015 21:12:50 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">Did you not make an https connection using TLS in order to make that post?</p>
</blockquote>
<p dir="auto">Its not that I don't go to places that use TLS and HTTPS, its that I don't use <strong>just</strong> TLS and HTTPS to do things that I have security concerns with. If someone compromises the Opera forums and my account the worst case is they get my throwaway email address I used to register with and can make bogus posts in my name. Since I use very strong passwords* and don't reuse passwords between accounts that gets them nothing. Thats not a security concern because I am not risking anything. You wont see me putting out my SSN or CC/bank account info without some extra level of security though.</p>
<p dir="auto">Its like using a cheap padlock vs a 800 lbs safe embedded in the concrete of my basement. The padlock is fine for keeping people out of my backyard shed. I'd definitely want my hundreds of millions of dollars in something more secure though.</p>
<blockquote>
<p dir="auto">What do you use instead?</p>
</blockquote>
<p dir="auto">Things other than the internet, generally. Its harder for a hacker to perform a man-in-the-middle attack when I've mailed my credit card bill payment via USPS <img src="https://forums.opera.com/assets/plugins/nodebb-plugin-emoji/emoji/emoji-one/1f609.png?v=qqje97jok90" class="not-responsive emoji emoji-emoji-one emoji--winking_face" title=";)" alt="😉" /> Its even harder if I setup an automatic bill payment. In either case its out of my hands and someone else's problem. But, as I said above, if you're really concerned with security making sure your browser is up to date goes a long way to improving your security.</p>
<p dir="auto">*My Opera account password is 350 bits. Just want to give a shout out to the team that maintains this site for allowing very long passwords. Good job.</p>
]]></description><link>https://forums.opera.com/post/80162</link><guid isPermaLink="true">https://forums.opera.com/post/80162</guid><dc:creator><![CDATA[lando242]]></dc:creator><pubDate>Sun, 19 Jul 2015 21:12:50 GMT</pubDate></item><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Sun, 19 Jul 2015 20:06:40 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">I still try to avoid using TLS because of its known issues.</p>
</blockquote>
<p dir="auto">Did you not make an https connection using TLS in order to make that post?  And how do you avoid TLS while using Opera?  I see a flag to set the minimum TLS but nothing about maximum or about disabling TLS.</p>
<p dir="auto">Unless there is an alternative it sounds like a strategy to use no security in order to avoid flawed security.  That or give up a large part of my online activity as more and more sites use https.  Maybe I am missing something here.</p>
]]></description><link>https://forums.opera.com/post/80160</link><guid isPermaLink="true">https://forums.opera.com/post/80160</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Sun, 19 Jul 2015 20:06:40 GMT</pubDate></item><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Sun, 19 Jul 2015 19:26:51 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">I still try to avoid using TLS because of its known issues.</p>
</blockquote>
<p dir="auto">What do you use instead?</p>
]]></description><link>https://forums.opera.com/post/80156</link><guid isPermaLink="true">https://forums.opera.com/post/80156</guid><dc:creator><![CDATA[utfo]]></dc:creator><pubDate>Sun, 19 Jul 2015 19:26:51 GMT</pubDate></item><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Sun, 19 Jul 2015 19:10:37 GMT]]></title><description><![CDATA[<p dir="auto">Right, because Opera 30 has been updated to 'manage' the problems with TLS so its 'secure enough' for general use. Opera 12 has not been updated because it is no longer being maintained. I still try to avoid using TLS because of its known issues. Just like I try to avoid using Flash and Java for anything that requires security.</p>
]]></description><link>https://forums.opera.com/post/80150</link><guid isPermaLink="true">https://forums.opera.com/post/80150</guid><dc:creator><![CDATA[lando242]]></dc:creator><pubDate>Sun, 19 Jul 2015 19:10:37 GMT</pubDate></item><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Sun, 19 Jul 2015 18:58:21 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">You shouldn't use TLS at all, its not secure.</p>
</blockquote>
<p dir="auto">Opera 30 uses TLS.</p>
]]></description><link>https://forums.opera.com/post/80148</link><guid isPermaLink="true">https://forums.opera.com/post/80148</guid><dc:creator><![CDATA[utfo]]></dc:creator><pubDate>Sun, 19 Jul 2015 18:58:21 GMT</pubDate></item><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Sun, 19 Jul 2015 18:54:58 GMT]]></title><description><![CDATA[<p dir="auto">You shouldn't use TLS at all, its not secure. Theres a draft for 1.3 out but its not finalized and it wont be added to Opera 12 (which is no longer maintained) even if it is. If you are concerned with security you should use better crypto protocols and update your browser.</p>
]]></description><link>https://forums.opera.com/post/80146</link><guid isPermaLink="true">https://forums.opera.com/post/80146</guid><dc:creator><![CDATA[lando242]]></dc:creator><pubDate>Sun, 19 Jul 2015 18:54:58 GMT</pubDate></item><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Sun, 19 Jul 2015 18:44:23 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">Nope, its not safe. TLS 1.1 and 1.2 are flawed and you shouldn't use them.</p>
</blockquote>
<p dir="auto">What should we use? TLS 1.1 and 1.2 are the latest.</p>
]]></description><link>https://forums.opera.com/post/80145</link><guid isPermaLink="true">https://forums.opera.com/post/80145</guid><dc:creator><![CDATA[utfo]]></dc:creator><pubDate>Sun, 19 Jul 2015 18:44:23 GMT</pubDate></item><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Sun, 19 Jul 2015 18:41:16 GMT]]></title><description><![CDATA[<p dir="auto">Galabutbul, certain characters are reserved in the local markup renderer, so use backticks to show stuff.</p>
<blockquote>
<p dir="auto">Your client supports cipher suites that are known to<br />
be insecure:<br />
<code>TLS_RSA_WITH_RC4_128_MD5</code>: This cipher use RC4 which has insecure biases in its output.<br />
<code>TLS_RSA_WITH_RC4_128_SHA</code>: This cipher use RC4 which has insecure biases in its output.</p>
</blockquote>
]]></description><link>https://forums.opera.com/post/80144</link><guid isPermaLink="true">https://forums.opera.com/post/80144</guid><dc:creator><![CDATA[[[global:former_user]]]]></dc:creator><pubDate>Sun, 19 Jul 2015 18:41:16 GMT</pubDate></item><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Sun, 19 Jul 2015 18:20:25 GMT]]></title><description><![CDATA[<p dir="auto">Nope, its not safe. TLS 1.1 and 1.2 are flawed and you shouldn't use them. That said, you shouldn't be using a web browser that hasn't been updated in 2 years either. So I guess you will have to evaluate the level of risk you are comfortable with and base your decision on that.</p>
]]></description><link>https://forums.opera.com/post/80139</link><guid isPermaLink="true">https://forums.opera.com/post/80139</guid><dc:creator><![CDATA[lando242]]></dc:creator><pubDate>Sun, 19 Jul 2015 18:20:25 GMT</pubDate></item><item><title><![CDATA[Reply to Opera 12.17 Build 1863 TLS 1.1 1.2 on Sun, 19 Jul 2015 18:09:20 GMT]]></title><description><![CDATA[<p dir="auto">It looks like those are results from <a href="http://howsmyssl.com" target="_blank" rel="noopener noreferrer nofollow ugc">howsmyssl.com</a>?</p>
<ul>
<li>Go to Settings - Preferences - Advanced tab - Security.</li>
<li>Click the "Security protocols" button.</li>
<li>Click the "Details" button.</li>
<li>Look under the "Cipher" column, and uncheck :</li>
</ul>
<p dir="auto">128 bit ARC4 (RSA/MD5)  and  128 bit ARC4 (RSA/SHA)</p>
<p dir="auto">This will improve your results on <a href="http://howsmyssl.com" target="_blank" rel="noopener noreferrer nofollow ugc">howsmyssl.com</a>.</p>
]]></description><link>https://forums.opera.com/post/80134</link><guid isPermaLink="true">https://forums.opera.com/post/80134</guid><dc:creator><![CDATA[utfo]]></dc:creator><pubDate>Sun, 19 Jul 2015 18:09:20 GMT</pubDate></item></channel></rss>