Notification to clients for September 2020
What are Vuture doing and Why are we doing this?
Vuture currently supports TLS 1.0-1.3 and in order to meet industry best practices for security we are disabling TLS 1.0 and 1.1 on your instance in September 2020. This means it will be disabled on your front-end sites and back-end administration site.
TLS is the protocol used by browsers and servers to secure connections to Vuture and other websites that use HTTPS. It ensures that all communication between the browser and Vuture is securely encrypted.
There are four versions of TLS: 1.0, 1.1, 1.2 and 1.3. Web security best practice recommends that secure connections should be made using 1.2 or above. Some browsers have even started showing security warning messages to visitors if the website is using old TLS versions, and all browsers will show this warning by the end of September 2020. For that reason we are disabling TLS 1.0 and 1.1 in its entirety across all clients in September 2020.
Disabling TLS 1.0 and 1.1 means that some older browsers will not be able to connect to Vuture either as a user in the back-end administration of the system or as a recipient accessing landing pages, micro-sites or forms.
The following browsers will not longer be able to connect to Vuture, so this could impact your visitors if they use these old browsers:
- Desktop Internet Explorer versions 7 and below
- Mobile Internet Explorer versions 10 and below
- Internet Explorer on Windows XP or Vista
- Android 4.3 (Jelly Bean) or lower
- Desktop Safari versions 6 and below for OS X 10.8 (Mountain Lion) and below
- Mobile Safari for iOS 4 and below
When are Vuture doing this?
We will be disabling TLS 1.0 and 1.1, as well as re-arranging our encryption ciphers to current best-practice during the last 2 weeks of August 2020. During the weekend of the 22nd August we will disable in our Hong Kong data centre, then the following weekend of 29 August we will disable in all other data centres. So by 1 September 2020 all clients in all data centres will have TLS 1.0 and 1.1 disabled.
Impact on Vuture clients?
There will be no downtime on client instances, sites or email delivery as this is a non-intrusive change. The only impact some clients may notice, as described above, is that visitors using older browsers will not be able to access pages when visiting client sites. We have already disabled TLS 1.0 and 1.1 on multiple clients who have requested this, on an individual basis, over the last 6 months, and have noticed no impact on any Vuture services.
Impact on your clients?
A very small fraction of older browsers do not support TLS 1.2 and will not be able to access any Vuture landing pages and forms after the update. We see very little traffic that does not support TLS 1.2 This is a global change across the internet and all major websites will be dropping support for TLS1.0 and 1.1 if they have not already done so.
Please contact your account manager should you have any further questions.
CRM Connections
Vuture would also like to disable TLS 1.0 and 1.1 on CRM connections before December 2020, but this relies on the client ensuring their CRM supports TLS 1.2. If clients could let us know once this is done, we will disable 1.0 and 1.1 on their CRM connection. Thanks.
See this article for more information on how to manage TLS settings on your InterAction server