Apple Will Disable Insecure TLS In Future iOS, MacOS Releases

Apple Will Disable Insecure TLS In Future iOS, MacOS Releases

Apple has deprecated the insecure Transport Layer Security (TLS) 1.0 and 1.1 protocols in recently launched iOS and macOS versions and plans to remove support in future releases altogether.

TLS is a secure communication protocol designed to protect users from eavesdropping, tampering, and message forgery while accessing and exchanging information over an Internet connection using client/server applications.

The original TLS 1.0 specification and its TLS 1.1 successor have been used for almost 20 years (with TLS 1.0 first defined in 1999 and TLS 1.1 in 2006).

The Internet Engineering Task Force (IETF) approved TLS 1.3, the next major version of the TLS protocol, in March 2018, after four years of discussions and 28 protocol drafts.

Also Read: How Long Do Employers Keep Employee Records After Termination? 1 Hard Question

TLS 1.0/1.1 deprecation update

“As part of ongoing efforts to modernize platforms, and to improve security and reliability, TLS 1.0 and 1.1 have been deprecated by the Internet Engineering Task Force (IETF) as of March 25, 2021,” Apple said.

“These versions have been deprecated on Apple platforms as of iOS 15, iPadOS 15, macOS 12, watchOS 8, and tvOS 15, and support will be removed in future releases.”

The company advised developers whose apps still use the legacy TLS protocols to begin planning for a transition to TLS 1.2 or higher in the near future.

For apps using the App Transport Security (ATS) networking security feature on all connections (enabled by default for apps linked against iOS 9.0 or macOS 10.11 SDKs or later), which requires that all connections are secured with reliable TLS certificates and ciphers, no action is required.

Apple recommends switching directly to TLS 1.3 as it is a faster and more secure protocol than TLS 1.2 by adding support to the latest TLS version and removing these deprecated Security.framework symbols from apps:

Ongoing effort to move away from outdated traffic encryption protocols

Apple’s update follows a joint announcement from Microsoft, Google, Apple, and Mozilla from October 2018, saying that the four organizations will start retiring insecure TLS protocols starting with the first half of 2020.

In August 2020, Microsoft enabled TLS 1.3 by default in the latest Windows 10 Insider builds.

“TLS 1.3 eliminates obsolete cryptographic algorithms, enhances security over older versions, and aims to encrypt as much of the handshake as possible,” Microsoft said.

Also Read: Thinking of Shredding or Burning Paper? Here’s What You Should Know

In January, the NSA shared guidance on detecting and replacing outdated Transport Layer Security (TLS) protocol versions with up-to-date and secure variants.

“Obsolete configurations provide adversaries access to sensitive operational traffic using a variety of techniques, such as passive decryption and modification of traffic through man-in-the-middle attacks,” the NSA said.

“Attackers can exploit outdated transport layer security (TLS) protocol configurations to gain access to sensitive data with very few skills required.”

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

1 week ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

2 weeks ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

2 weeks ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

3 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

3 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

4 weeks ago