The TLS 1.0/1.1 encryption protocols are aging versions of the TLS standard. In an acknowledgment of the vulnerabilities affecting these versions, the IETF has announced their official deprecation in favor of TLS 1.2 or higher. It is possible for an attacker to launch a TLS 1.0 based attack from clients which support only 1.0, when the server supports the connection. TLS 1.0 has several flaws, for example, an attacker can cause connection failures and they can trigger the use of TLS 1.0 to exploit vulnerabilities like BEAST(Browser Exploit Against SSL/TLS) which is a client side attack that uses man-in-the-middle technique, or POODLE, also an MITM attack that would downgrade the connection to a protocol that was vulnerable to the attack. POODLE primarily targeted SSL 3.0, however, TLS 1.0 and TLS 1.1 were also vulnerable.
TLS 1.3 is another exciting protocol update that we can expect to benefit from for years to come. Not only will encrypted (HTTPS) connections become faster, but they will also be more secure. It has eliminated support for algorithms and ciphers that are both theoretically and practically vulnerable.
In accordance with InstaSafe's mission to keep customer networks safe online, support for Transport Layer Security (TLS) versions 1.0 and 1.1 was removed across the InstaSafe Secure Access (ISA) solution on Saturday, 10th July 2021 and
all connections to our services would require TLS 1.2+ compatible clients. The decision to deprecate support is aligned with industry recommendations and follows similar announcements made by all major web browsers.