@jerry@infosec.exchange a lot of 1.2, even some 1.1, ciphers are fine
Disabling an entire protocol is what bad security tools and uneducated people tell you
Just serve a set of ciphers not known to be weak and a few other tweaks like SCSV and DNSSEC, also if you're going to be relying on those nasty ACME issued DV certs maybe use your own CSR and at least get a v3 with must staple flag
TLS has too many knobs and levers....
#father #husband #bootstrap #founder #snowboarding #hiking #surfing #kayak #music #ancienthistorybuff #astronomybuff #coder #security #researcher #curious of everything else interesting In that order regardless of online representations