Disable TLS 1.0 and 1.1 in Firefox Now!

  • Security
  • Published Mar 23, 2020 Updated Apr 12, 2020

Mozilla had planned to disable the insecure versions 1.0 and 1.1 of the TLS protocol in Firefox 74. Unfortunately, they reverted that planned change. This post explains how to disable insecure TLS versions yourself.

How to Disable TLS 1.0 and 1.1

The tl;dr version of this article:

  1. Open a new tab and navigate to about:config
  2. In the search box type security.tls.version.min
  3. Set the value to 3 and click the save icon

Why Did Mozilla Revert the Change?

The release notes for Firefox 74.0 state the following:

We reverted the change for an undetermined amount of time to better enable access to critical government sites sharing COVID19 information.

Government websites from the digital stone age. Yuck!

Explanation of the security.tls.version.min Setting

The only documentation of the security.tls.version.min setting seems to be on mozillaZine, apparently a non-HTTPS site:

0
The minimum required SSL/TLS version is SSL 3.0
1
The minimum required SSL/TLS version is TLS 1.0
2
The minimum required SSL/TLS version is TLS 1.1
3
The minimum required SSL/TLS version is TLS 1.2
4
The minimum required SSL/TLS version is TLS 1.3

How to Check Your Browser’s TLS Configuration

Head over to Qualys Labs. The topmost box of the report should look like this:

Comments

Related Posts

Browser Ad Blockers and Privacy

Browser Ad Blockers and Privacy
You have probably been in this situation: on some shopping site you put an article in your cart, but decide not to buy it after all. Later on, you notice that you are getting targeted ads for the exact same product on totally unrelated sites - or so you think. There is, however, a common denominator: the ad network. It tracks you quite effectively as you move from site to site. Many people are not exactly happy about that and turn to ad blockers to guard their privacy. This article looks at one way to measure the ad blockers’ effectiveness in terms of keeping their users’ privacy.
Security

Latest Posts

Scripted WordPress to Hugo Migration

Scripted WordPress to Hugo Migration
After having published in WordPress for almost 20 years, it was time for a change. This site is now rendered by Hugo, a static website generator built for Markdown content hosted in a Git repository. The migration from WordPress (HTML) to Hugo (Markdown) was far from trivial. Since I couldn’t find any tool for the job, I developed my own set of migration scripts that fully automate the migration process. You can find them on GitHub along with extensive documentation.
Website