Many of the world's top websites still support older, deprecated security protocols

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

The top 100 websites routinely fail to follow Transport Layer Security (TLS) best practices and still support older, deprecated protocols, suggests a new report.

Compiled by cybersecurity firm F5 Labs, the 2021 TLS Telemetry Report analyzes how successful the busiest websites on the internet are at implementing best practices around HTTPS and TLS using data from scans of the web’s most popular websites.

“As old protocols prove to be insecure and new standards emerge, it has never been more important to keep HTTPS configurations up to date...As this report shows, the issue is not so much the lack of adopting new ciphers and security features but the rate at which old and vulnerable protocols are removed,” reads the report.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

Commenting on the importance of this information, F5 says that websites that routinely fail to follow TLS best practices are also usually the ones that run old and like vulnerable web servers.

Two steps forward...

David Warburton, Principal Threat Research Evangelist (EMEA) at F5 Networks writes that the report shows that while web encryption has improved in several respects, as compared to last year, stagnation or even regression in many other areas is negating some of the progress.

The report notices several positives, such as the wide adoption of TLS 1.3, which has finally become the encryption protocol of choice on the majority of web servers in the top one million websites. 

Furthermore, the maximum lifespan of newly issued SSL certificates also registered a significant drop in September 2020, coming down from three years to just 398 days.

...and one step back

On the flip side though, the report revealed that the top 100 sites were more likely to still support the older SSL 3, TLS 1.0, and TLS 1.1 protocols than servers with much less traffic.

More worryingly, it found that 22% of the web servers were running Apache 2.0, which was released in 2002 and last patched in 2013. 

The report also observed that the number of phishing sites that used HTTPS with valid certificates to appear more legitimate grew from 70% in 2019 to nearly 83%.

“It’s clear that we’re facing two important realities heading into 2022. One is that the desire to intercept, circumvent, and weaken encryption has never been greater...The other is that the greatest weaknesses come not from the latest features we struggle to adopt but the old ones we are reluctant to disable,” concludes Warburton.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Security
Experts warn millions of email servers could be vulnerable to attack
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
API
Businesses are being plagued by API security risks - with nearly 99% affected
A VPN runs on a mobile phone placed on a laptop keyboard
Major new online tunneling vulnerability could put millions of devices at risk
Flag of the People&#039;s Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Hacker Typing
Racing against time on a menacing caldera: survey finds majority of organizations take days to tackle critical vulnerabilities, each of them a potential open goal for cybercriminals
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost