Hacker News new | ask | show | jobs
by toast0 1668 days ago
Following security advice blindly is never a great idea. I don't think modern browsers will fall back below TLS 1.2 anymore (or at least not automatically), so offering support for TLS 1.0 doesn't impact them.

Then the question is what do you want to do with older browsers? Do you want to give them a browser error that users probably can't understand or do you want to let them in and shop?

1 comments

Definitely let them shop. The per-account security issues created by old ciphers will be a rounding error in Amazon's risk management budget.