{"id":2111,"date":"2018-06-02T22:10:48","date_gmt":"2018-06-03T06:10:48","guid":{"rendered":"https:\/\/www.cloudinsidr.com\/content\/?p=2111"},"modified":"2018-06-02T23:17:25","modified_gmt":"2018-06-03T07:17:25","slug":"restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer","status":"publish","type":"post","link":"https:\/\/www.cloudinsidr.com\/content\/restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer\/","title":{"rendered":"TLS tune-up: how to restrict Firefox to TLS v1.3 and v1.2 to protect from phishing attacks"},"content":{"rendered":"<p>Only two versions of the TLS (Transport\u00a0Layer Security) protocol can be considered safe under certain circumstances: TLS 1.3 and TLS 1.2. Trying to get your bank alongside everyone else to fix their websites and web applications is a Herculean task; good luck trying. Even so, you can protect TLS connections by modifying the browser configuration.<\/p>\n<p>It is good to know that there is something you can do to protect at least yourself and the other end users on the networks that you oversee from nasty attacks against their TLS connections. In Firefox, you can restrict the browser to &#8220;speak&#8221; only TLS 1.3 and TLS 1.2 to\u00a0limit the attack surface and restrict phishing. Here is how to do it.<\/p>\n<p><!--more--><\/p>\n<p>Here is a short how-to on restricting Firefox to the two most secure versions of the TLS protocol:<\/p>\n<h4>Step 1. Open the advanced settings page of Firefox.<\/h4>\n<p>In the address bar, enter<\/p>\n<pre>about:config<\/pre>\n<p>and hit Return.<\/p>\n<h4>Step 2. Agree to &#8220;void your warranty&#8221;.<\/h4>\n<p>Ignore the warning about voiding your warranty and proceed.<\/p>\n<h4>Step 3. Find the security settings for TLS<\/h4>\n<p>In the Search bar, type in &#8220;security.tls&#8221;.<\/p>\n<h4>Step 4. Adjust the lowest version of the TLS protocol\u00a0you want to allow<\/h4>\n<p>Double click the entry &#8220;security.tls.version.min&#8221;. The default value is 1. Change it from &#8220;1&#8221; to &#8220;3&#8221;. This will activate TLS 1.2 and disallow any version below. This change is important as it prevents protocol downgrade attacks irrespective of the actual server settings. Eliminating the possibility of a protocol downgrade allows you to protect TLS connections from <a href=\"https:\/\/www.cloudinsidr.com\/content\/known-attack-vectors-against-tls-implementation-vulnerabilities\/\">some attempts at eavesdropping<\/a>.<\/p>\n<h4>Step 5.\u00a0Adjust the highest version of the TLS protocol you want to allow<\/h4>\n<p>Verify that &#8220;security.tls.version.max&#8221; is set to to &#8220;4&#8221;. This ensures that Firefox may use TLS 1.3, (but not above; should TLS reach a higher version number, you will need to revisit this setting).<\/p>\n<figure id=\"attachment_2116\" aria-describedby=\"caption-attachment-2116\" style=\"width: 1024px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.cloudinsidr.com\/content\/restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer\/firefox_tls_1_3_and_tls_1_2_config\/\" rel=\"attachment wp-att-2116\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-2116\" src=\"https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2_config-1024x364.png\" alt=\"Restricting Firefox to TLS version 1.3 and TLS 1.2\" width=\"1024\" height=\"364\" srcset=\"https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2_config-1024x364.png 1024w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2_config-300x107.png 300w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2_config-768x273.png 768w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2_config-600x213.png 600w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2_config.png 1183w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption id=\"caption-attachment-2116\" class=\"wp-caption-text\">Restricting Firefox to TLS version 1.3 and TLS 1.2<\/figcaption><\/figure>\n<p>Now, your Firefox web browser speaks only TLS 1.3 and TLS 1.2; you will not be able to connect to websites that do not support these two protocols, but then again\u2014perhaps you shouldn&#8217;t. Either way, there aren&#8217;t that many of them left.<\/p>\n<h4>Step 6. Test your configuration<\/h4>\n<p>Head over to Qualys SSL Labs&#8217; browser test:<\/p>\n<p><a href=\"https:\/\/www.ssllabs.com\/ssltest\/viewMyClient.html\" target=\"_blank\" rel=\"noopener\">https:\/\/www.ssllabs.com\/ssltest\/viewMyClient.html<\/a><\/p>\n<h4>Step 7. Verify the test results<\/h4>\n<p>Allow the test to run its course. In the overview of details, look for the section &#8220;Protocol Features&#8221;. In the list of supported protocols, verify that only TLS 1.3 and TLS 1.2 are allowed.<\/p>\n<figure id=\"attachment_2114\" aria-describedby=\"caption-attachment-2114\" style=\"width: 1024px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.cloudinsidr.com\/content\/restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer\/firefox_tls_1_3_and_tls_1_2\/\" rel=\"attachment wp-att-2114\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-2114 size-large\" src=\"https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2-1024x367.png\" alt=\"Restricting Firefox to TLS version 1.3 and TLS 1.2 makes browsing safer\" width=\"1024\" height=\"367\" srcset=\"https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2-1024x367.png 1024w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2-300x108.png 300w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2-768x275.png 768w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2-600x215.png 600w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2.png 1172w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption id=\"caption-attachment-2114\" class=\"wp-caption-text\">Browser test by Qualys SSL Labs reveals that the attempt at restricting Firefox to TLS 1.3 and 1.2 was successful<\/figcaption><\/figure>\n<p>These changes do not offer absolute security as such a thing doesn&#8217;t even exist. They offer protection in so far as they limit the attack surface without compromising compatibility.<\/p>\n<p>It goes without saying that if you happen to oversee the configuration of a web host, you need to take some steps to ensure that it measures up to the demands you put on your own Firefox for the sake of your visitor&#8217;s safety (see &#8220;<a href=\"https:\/\/www.cloudinsidr.com\/content\/how-to-activate-http2-with-ssltls-encryption-in-nginx-for-secure-connections\/\" target=\"_blank\" rel=\"noopener\">How to Activate HTTP\/2 with TLS 1.3 Encryption in NGINX for Secure Connections without a Performance Penalty<\/a>&#8221; and\u00a0&#8220;<a href=\"https:\/\/www.cloudinsidr.com\/content\/tls-1-3-and-tls-1-2-cipher-suites-demystified-how-to-pick-your-ciphers-wisely\/\" target=\"_blank\" rel=\"noopener\">TLS 1.3 (with AEAD) and TLS 1.2 cipher suites demystified: how to pick your ciphers wisely<\/a>&#8221;\u00a0for more).<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Only two versions of the TLS (Transport\u00a0Layer Security) protocol can be considered safe under certain circumstances: TLS 1.3 and TLS 1.2. Trying to get your bank alongside everyone else to fix their websites and web applications is a Herculean task; good luck trying. Even so, you can protect TLS connections by modifying the browser configuration. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[33,111],"tags":[37,219,218,225],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v14.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>TLS tune-up: how to restrict Firefox to TLS v1.3 and v1.2 to protect from phishing attacks - CloudInsidr<\/title>\n<meta name=\"description\" content=\"Protect yourself from nasty attacks against TLS connections by restricting the browser to TLS 1.3 and TLS 1.2, the most secure versions of the protocol that encrypts your communications. This easy step limits the attack surface. Here is how to do it.\" \/>\n<meta name=\"robots\" content=\"index, follow\" \/>\n<meta name=\"googlebot\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta name=\"bingbot\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cloudinsidr.com\/content\/restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TLS tune-up: how to restrict Firefox to TLS v1.3 and v1.2 to protect from phishing attacks - CloudInsidr\" \/>\n<meta property=\"og:description\" content=\"Protect yourself from nasty attacks against TLS connections by restricting the browser to TLS 1.3 and TLS 1.2, the most secure versions of the protocol that encrypts your communications. This easy step limits the attack surface. Here is how to do it.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cloudinsidr.com\/content\/restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer\/\" \/>\n<meta property=\"og:site_name\" content=\"CloudInsidr\" \/>\n<meta property=\"article:published_time\" content=\"2018-06-03T06:10:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2018-06-03T07:17:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2_config-1024x364.png\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#website\",\"url\":\"https:\/\/www.cloudinsidr.com\/content\/\",\"name\":\"CloudInsidr\",\"description\":\"Cyber security, infotech\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/www.cloudinsidr.com\/content\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/06\/Firefox_TLS_1_3_and_TLS_1_2_config.png\",\"width\":1183,\"height\":420,\"caption\":\"Restricting Firefox to TLS version 1.3 and TLS 1.2\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer\/#webpage\",\"url\":\"https:\/\/www.cloudinsidr.com\/content\/restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer\/\",\"name\":\"TLS tune-up: how to restrict Firefox to TLS v1.3 and v1.2 to protect from phishing attacks - CloudInsidr\",\"isPartOf\":{\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer\/#primaryimage\"},\"datePublished\":\"2018-06-03T06:10:48+00:00\",\"dateModified\":\"2018-06-03T07:17:25+00:00\",\"author\":{\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#\/schema\/person\/dd6ee9cb21cf05763fd7cff3d6f11b2b\"},\"description\":\"Protect yourself from nasty attacks against TLS connections by restricting the browser to TLS 1.3 and TLS 1.2, the most secure versions of the protocol that encrypts your communications. This easy step limits the attack surface. Here is how to do it.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cloudinsidr.com\/content\/restricting-firefox-to-tls-version-1-3-and-tls-1-2-makes-browsing-safer\/\"]}]},{\"@type\":[\"Person\"],\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#\/schema\/person\/dd6ee9cb21cf05763fd7cff3d6f11b2b\",\"name\":\"Cloud Insidr\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8b2fa1415b3d573b97d818b8f8f83b7c?s=96&d=mm&r=g\",\"caption\":\"Cloud Insidr\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts\/2111"}],"collection":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/comments?post=2111"}],"version-history":[{"count":13,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts\/2111\/revisions"}],"predecessor-version":[{"id":2127,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts\/2111\/revisions\/2127"}],"wp:attachment":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/media?parent=2111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/categories?post=2111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/tags?post=2111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}