Hello,
the wikipedia page about TLS has a web browser support table:
https://en.wikipedia.org/wiki/Transport_Layer_Security#Web_browsers
it states that the Android 4.4-4.4.4 browser (not Chrome) has TLS 1.1 and 1.2 disabled by default, SSL Labs reports that TLS 1.1 and 1.2 are supported https://www.ssllabs.com/ssltest/viewClient.html?name=Android&version=4.4.2, on a real world Samsung Galaxy S4 mini running Android 4.4.2 I noticed that TLS 1.1 works and that TLS 1.2 is disabled (and did not find a way to enable it), I will add screenshots later on (not my phone). This is somewhat disturbing, I don't know if other KitKat phones behave this way, but perhaps SSL Labs should add a foot note concerning Android 4.4.2, since what is currently reported is misleading for at least some Android devices.
On the other hand when IE 8-10 / Win 7 are reported to handle only TLS 1.0 this is effectively the default behaviour but enabling TLS 1.1+ is not that difficult. Regarding Android 4.4.x I'm a bit lost now, could you use the SSL browser test to gater real world results and give a better picture of how TLS is configured on KitKat devices? PCI DSS 3.1 has set the end of June 2016 deadline for TLS 1.0 and it looks like Android 4.4 will still be in use by then.
Cheers
Hello,
the wikipedia page about TLS has a web browser support table:
https://en.wikipedia.org/wiki/Transport_Layer_Security#Web_browsers
it states that the Android 4.4-4.4.4 browser (not Chrome) has TLS 1.1 and 1.2 disabled by default, SSL Labs reports that TLS 1.1 and 1.2 are supported https://www.ssllabs.com/ssltest/viewClient.html?name=Android&version=4.4.2, on a real world Samsung Galaxy S4 mini running Android 4.4.2 I noticed that TLS 1.1 works and that TLS 1.2 is disabled (and did not find a way to enable it), I will add screenshots later on (not my phone). This is somewhat disturbing, I don't know if other KitKat phones behave this way, but perhaps SSL Labs should add a foot note concerning Android 4.4.2, since what is currently reported is misleading for at least some Android devices.
On the other hand when IE 8-10 / Win 7 are reported to handle only TLS 1.0 this is effectively the default behaviour but enabling TLS 1.1+ is not that difficult. Regarding Android 4.4.x I'm a bit lost now, could you use the SSL browser test to gater real world results and give a better picture of how TLS is configured on KitKat devices? PCI DSS 3.1 has set the end of June 2016 deadline for TLS 1.0 and it looks like Android 4.4 will still be in use by then.
Cheers