Disables support for TLS 1.0 and TLS 1.1 as these are vulnerable versions
Is there a plan to disable support for TLS 1.0 and 1.0 version across the domains e.g. firebase console, fcm.googleapis.com and other services?
32
votes
-
Amogh Asgekar commented
Especially for firebase hosting, since DAST scans keep throwing medium level vulnerabilities detected on this, for SHA-1 Cipher Suites Detected and Weak Cipher Suites - ROBOT Attack : Vulnerable cipher suites are supported by the server