Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Plusnet and TLS  (Read 1226 times)

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5272
    • Thinkbroadband Quality Monitors
Plusnet and TLS
« on: April 13, 2021, 09:11:29 PM »

[Moderator note: This topic has been created by splitting the following posts off of bob.gas' Plusnet bill? topic.]

They still haven't fixed portal.plus.net using outdated TLS 1.2 either.

Totally ironic when that needs to be more secure than the community forum that DOES support TLS 1.3.

Currently my Billing page says "There has been an issue; please consult your system administrator" LOL.  Touch wood, so far I haven't had any billing issues.
« Last Edit: April 20, 2021, 06:13:40 PM by burakkucat »
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

niemand

  • Kitizen
  • ****
  • Posts: 1836
Re: Plusnet and TLS
« Reply #1 on: April 16, 2021, 08:47:15 PM »

Totally ironic when that needs to be more secure than the community forum that DOES support TLS 1.3.

Portal website is managed by Plusnet, community forum isn't  :)
Logged

Chrysalis

  • Content Team
  • Addicted Kitizen
  • *
  • Posts: 7388
  • VM Gig1 - AAISP L2TP
Re: Plusnet and TLS
« Reply #2 on: April 20, 2021, 05:34:30 AM »

They still haven't fixed portal.plus.net using outdated TLS 1.2 either.

Totally ironic when that needs to be more secure than the community forum that DOES support TLS 1.3.

Currently my Billing page says "There has been an issue; please consult your system administrator" LOL.  Touch wood, so far I haven't had any billing issues.

TLS 1.2 is perfectly fine to use I can certainly understand them still having it enabled, a commercial business cant have large swathes of their customer base unable to connect to the portal.  However they could probably start supporting TLS 1.3 for clients that support it, maybe they wary that its not mature enough as  a tech yet to trust it to work properly.
Logged

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5272
    • Thinkbroadband Quality Monitors
Re: Plusnet and TLS
« Reply #3 on: April 20, 2021, 09:18:14 AM »

TLS 1.2 is perfectly fine to use I can certainly understand them still having it enabled, a commercial business cant have large swathes of their customer base unable to connect to the portal.  However they could probably start supporting TLS 1.3 for clients that support it, maybe they wary that its not mature enough as  a tech yet to trust it to work properly.

Enabled yes, but Firefox have deprecated it by default so the page wont load at all.

The idea is TLS 1.2 is enabled for legacy browser support, there should absolutely not be any situation where a modern browser fails to work because TLS 1.3 hasn't been enabled.  I can't think of a single other site which fails to work in Firefox.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

Chrysalis

  • Content Team
  • Addicted Kitizen
  • *
  • Posts: 7388
  • VM Gig1 - AAISP L2TP
Re: Plusnet and TLS
« Reply #4 on: April 20, 2021, 10:26:46 AM »

Enabled yes, but Firefox have deprecated it by default so the page wont load at all.

The idea is TLS 1.2 is enabled for legacy browser support, there should absolutely not be any situation where a modern browser fails to work because TLS 1.3 hasn't been enabled.  I can't think of a single other site which fails to work in Firefox.

Problem is not everyone runs an up to date client, Firefox probably have jumped the gun a bit though by disabling 1.2 by default, is a lot of sites that dont support 1.3 yet.  Its far from widespread in terms of adoption.

Hmm are you sure you didnt tinker with 1.2? This page indicates they only deprecated 1.0 and 1.1.

https://www.ghacks.net/2020/03/21/mozilla-re-enables-tls-1-0-and-1-1-because-of-coronavirus-and-google/

Seems they also had to back out on tls 1.0 as well due to some government website's not even using 1.2 yet.
« Last Edit: April 20, 2021, 10:30:02 AM by Chrysalis »
Logged

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5272
    • Thinkbroadband Quality Monitors
Re: Plusnet and TLS
« Reply #5 on: April 20, 2021, 05:35:49 PM »

I think I misunderstood and its not TLS 1.2 specifically or Firefox itself but something about the specific certificate they use and changes in my OS. https://fedoraproject.org/wiki/Changes/StrongCryptoSettings2

Looking at the certificate fields in Chrome I can't figure why it trips up in Firefox though as both certificates seem to be 2048 in size using SHA-256, so either both should work or neither should.  ???  I must be missing something or its a bug.
« Last Edit: April 21, 2021, 10:04:41 AM by Alex Atkin UK »
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

Chrysalis

  • Content Team
  • Addicted Kitizen
  • *
  • Posts: 7388
  • VM Gig1 - AAISP L2TP
Re: Plusnet and TLS
« Reply #6 on: April 21, 2021, 07:58:16 AM »

Hmm yeah they need to update that, it kind of reminds me of the email server issues they had that never got resolved for long periods of time.  A company where its priorities have all been sucked into sales.
Logged