In line with our continuous efforts to maintain the highest security standards and ensure the safety of our customer data, on November 6, 2018 we will be deprecating TLS versions 1.0 and 1.1.
At Talkdesk we take security very seriously. We use Transport Layer Security (TLS) to enable our customers to access our services in a secure manner.
Versions 1.0 and 1.1 have been around for some time now, and their age is noticeable.
Following industry trends, security best practices declared by NIST, by the Payment Card Industry (PCI) Security Standards Council policy PCI DSS 3.2 and considering that the Internet Engineering Task Force (IETF) is formalizing the deprecation of TLS 1.0 and TLS 1.1, we are deprecating TLS 1.0 and TLS 1.1 and have our service via TLS 1.2 only.
Why is this a good idea?
TLS versions 1.0 and 1.1 are old protocol versions with an impressive record of known security vulnerabilities (e.g., FREAK, BEAST, LogJam). This means that, by using these versions of TLS, you are exposing yourself to unnecessary risk.
Chrome, Mozilla, Microsoft and Safari have recently made public announcements for their plans to deprecate TLS 1.0 and TLS 1.1. This means that, in order to have an updated browser with the latest security patches, which is something everyone should have as a good security hygiene practice, usage of TLS version 1.2 or higher will soon be mandatory for almost every user in the Internet.
Will I be affected?
We have gathered data about how our customers are reaching Talkdesk and made extensive tests that give us high confidence that the impact will be almost negligible.
Currently, over 99% of connections to Talkdesk are being done using TLS 1.2.
What should I do if I experience a problem?
The effect of a user being affected by this change is that the application will simply not be accessible and the browser will warn you of a connection failure. While we don't expect this to occur (check “Will I be affected?” for details), we have our support team standing by!
If you encounter any problems, please contact email@example.com.
When will this be done?
We will discontinue support for TLS 1.0 and TLS 1.1 on November 6, 2018.