Why hasn't TLS 1.3 been implemented yet?

Such security upgrades are complex in nature. In a multi-vendor internet environment, you need to update both client and servers to support a new security standard. So far, no major browsers have TLS 1.3 enabled by default. It cannot be assumed that by a specific date, every server and end user device will support all new security standards. Furthermore, TLS 1.3 is not an extension but a major change with complete revamping. The way TLS or SSL version negotiation works is that an end user device sends the latest version of a supported protocol to a server, which responds with the latest version and chooses something which is supported by both of them.

Get Practical Network Scanning now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.