Stats

We're All Being Judged By a Secret 'Trustworthiness' Score (wsj.com) 135

schwit1 writes: Nearly everything we buy, how we buy, and where we're buying from is secretly fed into AI-powered verification services that help companies guard against credit-card and other forms of fraud, according to the Wall Street Journal.

More than 16,000 signals are analyzed by a service called Sift, which generates a "Sift score" ranging from 1 to 100. The score is used to flag devices, credit cards and accounts that a vendor may want to block based on a person or entity's overall "trustworthiness" score, according to a company spokeswoman.

From the Sift website: "Each time we get an event be it a page view or an API event we extract features related to those events and compute the Sift Score. These features are then weighed based on fraud we've seen both on your site and within our global network, and determine a user's Score. There are features that can negatively impact a Score as well as ones which have a positive impact."

The system is similar to a credit score except there's no way to find out your own Sift score.


Factors which contribute to one's Sift score (per the WSJ):
  • Is the account new?
  • Are there are a lot of digits at the end of an email address?
  • Is the transaction coming from an IP address that's unusual for your account?
  • Is the transaction coming from a region where there are a lot of hackers, such as China, Russia or Eastern Europe?
  • Is the transaction coming from an anonymization network?
  • Is the transaction happening at an odd time of day?
  • Has the credit card being used had chargebacks associated with it?
  • Is the browser different from what you typically use?
  • Is the device different from what you typically use?
  • Is the cadence of the way you typed out your password typical for you? (tracked by some advanced systems)

Stats

Why Hasn't The Gig Economy Killed Traditional Work? (npr.org) 170

An anonymous reader quotes NPR: In recent months, a slew of studies has debunked predictions that we're witnessing the dawn of a new "gig economy." The U.S. Bureau of Labor Statistics (BLS) found that there was actually a decline in the categories of jobs associated with the gig economy between 2005 and 2017. Larry Katz and the late Alan Krueger then revised their influential study that had originally found gig work was exploding. Instead, they found it had only grown modestly. Other economists ended up finding the same -- and now writers are declaring the gig economy is "a big nothingburger."

Arun Sundararajan, a professor at the NYU Stern School of Business and the author of The Sharing Economy: The End of Employment and the Rise of Crowd-Based Capitalism, remains a true believer in the gig revolution.... When asked about the onslaught of data contradicting his thesis, Sundararajan said the Bureau of Labor Statistics continues "to underestimate the size of the gig economy and in particular of the platform-based gig economy." The best BLS estimate of the number of gig workers employed through digital platforms -- whether full-time, part-time or occasionally -- is one percent of the total U.S. workforce, or about 1.6 million workers, as of mid-2017. Sundararajan argues that the survey questions the BLS used to gather this data were clunky and don't quite capture what's going on.... He believes work done through gig platforms can be more efficient than work done in a traditional company -- and that will spell the company's doom...

The dawn of a new gig economy has seemed plausible because the Internet has been dramatically reducing transaction costs. Search engines have made it incredibly cheap to find goods and services, compare prices, and get bargains. Social media and peer reviews have made it easier to determine if people are trustworthy. E-commerce has made it easier process payments. You can click a button on a mobile phone and instantaneously have GPS guide drivers right to you. But as big as these efficiency gains have been, a new economy based on crowds of people doing gigs through digital platforms -- as exciting or scary as that might sound -- still doesn't compare to one based on the efficiencies and stability of the good old-fashioned company.

Math

Is Statistical Significance Significant? (npr.org) 184

More than 850 scientists and statisticians told the authors of a Nature commentary that they are endorsing an idea to ban "statistical significance." Critics say that declaring a result to be statistically significant or not essentially forces complicated questions to be answered as true or false. "The world is much more uncertain than that," says Nicoole Lazar, a professor of statistics at the University of Georgia. An entire issue of the journal The American Statistician is devoted to this question, with 43 articles and a 17,500-word editorial that Lazar co-authored.

"In the early 20th century, the father of statistics, R.A. Fisher, developed a test of significance," reports NPR. "It involves a variable called the p-value, that he intended to be a guide for judging results. Over the years, scientists have warped that idea beyond all recognition, creating an arbitrary threshold for the p-value, typically 0.05, and they use that to declare whether a scientific result is significant or not. Slashdot reader apoc.famine writes: In a nutshell, what the statisticians are recommending is that we embrace uncertainty, quantify it, and discuss it, rather than set arbitrary measures for when studies are worth publishing. This way research which appears interesting but which doesn't hit that magical p == 0.05 can be published and discussed, and scientists won't feel pressured to p-hack.
XBox (Games)

Microsoft Announces Xbox Live For Any iOS Or Android Game (theverge.com) 22

Microsoft is bringing its Xbox Live network to iOS and Android devices. "The software giant is launching a new cross-platform mobile software development kit (SDK) for game developers to bring Xbox Live functionality to games that run on iOS and Android," reports The Verge. "Xbox Live features like achievements, Gamerscore, hero stats, friend lists, clubs, and even some family settings will all be available on iOS and Android." From the report: It's all part of a bigger push from Microsoft to make its Xbox games and services available across multiple platforms. Game developers will be able to pick and choose parts of Xbox Live to integrate into their games, and it will all be enabled through a single sign-in to a Microsoft Account. Microsoft is using its identity network to support login, privacy, online safety, and child accounts. Microsoft wants game developers to take a similar Minecraft approach and bring Xbox Live to more mobile games. Some iOS and Android games already have Xbox Live Achievements, but they're only enabled in titles from Microsoft Studios at the moment and this new SDK will open up Xbox Live functionality to many more games.

If you were hoping to see Xbox Live on Nintendo Switch then you might have to wait a little longer. "Our goal is to really unite the 2 billion gamers of the world and we're big fans of our Xbox Live community, but we don't have any specific announcements as it relates to Switch today," reveals Choudhry. Xbox Live on PlayStation 4 also looks unlikely, but Microsoft is open to the idea if Sony is willing to allow it. "If you've watched us for the past few years, we've taken a very inclusive approach," says Choudhry. "Phil [Spencer] has been very proactive on issues like crossplay, cross-progression, and uniting gamer networks, and we're willing to partner with the industry as much as we possibly can."

First Person Shooters (Games)

Study Shows Gamers At High FPS Have Better Kill-To-Death Ratios In Battle Royale Games (hothardware.com) 149

MojoKid writes: Gaming enthusiasts and pro-gamers have believed for a long time that playing on high refresh rates displays with high frame rates offers a competitive edge in fast-action games like PUBG, Fortnite and Apex Legends. The premise is, the faster the display can update the action for you, every millisecond saved will count when it comes to tracking targets and reaction times. This sounds logical but there's never been specific data tabulated to back this theory up and prove it. NVIDIA, however, just took it upon themselves with the use of their GeForce Experience tool, to compile anonymous data on gamers by hours played per week, panel refresh rate and graphics card type. Though obviously this data speaks to only NVIDIA GPU users, the numbers do speak for themselves.

The more powerful the GPU with a higher frame rate, along with higher panel refresh rate, generally speaking, the higher the kill-to-death ratio (K/D) for the gamers that were profiled. In fact, it really didn't matter hour many hours per week were played. Casual gamers and heavy-duty daily players alike could see anywhere from about a 50 to 150 percent increase in K/D ratio for significantly better overall player performance. It should be underscored that it really doesn't matter what GPU is at play; gamers with AMD graphics cards that can push high frame rates at 1080p or similar can see similar K/D gains. However, the new performance sweet spot seems to be as close to 144Hz/144FPS as your system can push, the better off you'll be and the higher the frame rate and refresh rate the better as well.

Crime

Workplace Theft Is On the Rise (theatlantic.com) 328

rfengineer tipped us off to this story. The Atlantic reports: Your office is a den of thieves. Don't take my word for it: When a forensic-accounting firm surveyed workers in 2013, 52 percent admitted to stealing company property. And the thievery is getting worse. The Association of Certified Fraud Examiners reports that theft of "non-cash" property -- ranging from a single pencil in the supply closet to a pallet of them on the company loading dock -- jumped from 10.6 percent of corporate-theft losses in 2002 to 21 percent in 2018. Managers routinely order up to 20 percent more product than is necessary, just to account for sticky-fingered employees.

Some items -- scissors, notebooks, staplers -- are pilfered perennially; others vanish on a seasonal basis: The burn rate on tape spikes when holiday gifts need wrapping, and parents ransack the supply closet in August, to avoid the back-to-school rush at Target. After a new Apple gadget is released, some workers report that their company-issued iPhone is broken -- knowing that IT will furnish a replacement, no questions asked. What's behind this 9-to-5 crime wave? Mark R. Doyle, the president of the loss-prevention consultancy Jack L. Hayes International, points to a decrease in supervision, the ease of reselling purloined products online, and what he alleges is "a general decline in employee honesty."

The report advises companies that the best way to reduce fraud was with surprise audits and data monitoring.

Another interesting statistic? "Fraudsters" who'd been with their company for more than five years "stole twice as much."
Stats

Misleading Results From Widely-Used Machine-Learning Data Analysis Techniques (bbc.com) 23

Long-time Slashdot reader kbahey writes: The increased reliance on machine-learning techniques used by thousands of scientists to analyze data, is producing results that are misleading and often completely wrong, according to the BBC.

Dr. Genevera Allen from Rice University in Houston said that the increased use of such systems was contributing to a "crisis in science".

She warned scientists that if they didn't improve their techniques they would be wasting both time and money. Her research was presented at the American Association for the Advancement of Science in Washington.


This is the oft-discussed 'reproducibility problem' in modern science.

The BBC writes that this irreproducibility happens when experiments "aren't designed well enough to ensure that the scientists don't fool themselves and see what they want to see in the results." But machine learning now has apparently become part of the problem.

Dr. Allen asks "If we had an additional dataset would we see the same scientific discovery or principle...? Unfortunately the answer is often probably not.â
Android

Google Play Store App Rejections Up 55% From Last Year, App Suspensions Up 66% (zdnet.com) 23

In a year-in-review announcement today, Google said Play Store app rejections went up 55% last year after the OS maker tightened up its app review process. From a report: Similarly, stats for app suspensions also went up, by more than 66%, according to Google, which the company credited to its continued investment in "automated protections and human review processes that play critical roles in identifying and enforcing on bad apps." One of the most significant roles in the automated systems cited by Google in identifying malware is the Google Play Protect service, which is currently included by default with the official Play Store app. Google said this service now scans over 50 billion apps per day, and even goes as far as downloading and scanning every Android app it finds on the internet.

[...] Play Store's automated systems are now getting better and better at detecting threats, so much so that Google is now seeing clear patterns. "We find that over 80% of severe policy violations are conducted by repeat offenders and abusive developer networks," Ahn said. "When malicious developers are banned, they often create new accounts or buy developer accounts on the black market in order to come back to Google Play."

Privacy

83% Of Consumers Believe Personalized Ads Are Morally Wrong (forbes.com) 219

An anonymous reader quotes Forbes: A massive majority of consumers believe that using their data to personalize ads is unethical. And a further 76% believe that personalization to create tailored newsfeeds -- precisely what Facebook, Twitter, and other social applications do every day -- is unethical.

At least, that's what they say on surveys.

RSA surveyed 6,000 adults in Europe and America to evaluate how our attitudes are changing towards data, privacy, and personalization. The results don't look good for surveillance capitalism, or for the free services we rely on every day for social networking, news, and information-finding. "Less than half (48 percent) of consumers believe there are ethical ways companies can use their data," RSA, a fraud prevention and security company, said when releasing the survey results. Oh, and when a compan y gets hacked? Consumers blame the company, not the hacker, the report says.

Transportation

Even More Americans Have Stopped Biking To Work (usatoday.com) 275

The percentage of Americans biking to work has dropped for the third year straight, reports the U.S. Census Bureau. An anonymous reader quotes USA Today: Nationally, the percentage of people who say they use a bike to get to work fell by 3.2 percent from 2016 to 2017, to an average of 836,569 commuters, according to the bureau's latest American Community Survey, which regularly asks a group of Americans about their habits. That's down from a high of 904,463 in 2014, when it peaked after four straight years of increases....

Experts offered several explanations for the nationwide decrease that has unfolded even as cities spent millions trying to become more bike-friendly. Most obviously, lower gasoline prices and a stronger economy contributed to strong auto sales and less interest in cheaper alternatives, such as mass transit and bikes. The rise of ride-hailing services such as Uber and Lyft and electric scooters cut into bike commuting, said Dave Snyder, executive director of the California Bicycle Coalition.

In at least two American cities -- Cleveland and Tampa -- the number of bike commuters has dropped by 50%.
Cellphones

Screen Time Changes Structure of Kids' Brains, NIH Study Shows (bloombergquint.com) 94

schwit1 shared this article from Bloomberg: Brain scans of adolescents who are heavy users of smartphones, tablets and video games look different from those of less active screen users, preliminary results from an ongoing study funded by the National Institutes of Health show, according to a report on Sunday by "60 Minutes." That's the finding of the first batch of scans of 4,500 nine- to 10-year-olds. Scientists will follow those children and thousands more for a decade to see how childhood experiences, including the use of digital devices, affect their brains, emotional development and mental health.

In the first round of testing, the scans of children who reported daily screen usage of more than seven hours showed premature thinning of the brain cortex, the outermost layer that processes information from the physical world.... Early results from the $300 million study, called Adolescent Brain Cognitive Development (ABCD), have determined that children who spend more than two hours of daily screen time score lower on thinking and language tests. A major data release is scheduled for early 2019.

The study's director cautions that "It won't be until we follow them over time that we will see if there are outcomes that are associated with the differences that we're seeing in this single snapshot."

The study will ultimately follow over 11,000 nine- to 10-year-olds for a decade.
Youtube

YouTube's Top-Earner For 2018 Is a 7-Year-Old (usatoday.com) 78

In 2018 the most-downloaded iPhone app was YouTube, reports USA Today, while Amazon's best-selling item was their Fire TV Stick for streaming video. "Sense a trend? We love to stream video." If you're thinking of quitting your day job this year and looking to strike it big in the world of online video, maybe this will inspire you. The No. 1 earner on YouTube this year is.....7-year-old Ryan from Ryan Toys Review. For all those unboxing videos and playing with toys -- and his own new line of toys at Walmart -- he and his family will pull in a cool $22 million, according to Forbes.
Ryan launched the channel in 2015 -- when he was four -- and now has 17.3 million followers.

One viral video of the 7-year-old even racked up 1.6 billion views, though apparently Ryan actually has fewer subscribers than several of the game streamers among YouTube's top-ten earners.
Programming

Is Visual Basic .NET More Popular Than JavaScript? (zdnet.com) 100

Microsoft's Visual Basic .NET now ranks above JavaScript, PHP, SQL on TIOBE's index of programming language popularity, which ZDNet notes is "the highest it's ever been since [TIIOBE] started tracking the Microsoft language in 2001." Tiobe analysts said it was "very surprising" that Visual Basic .Net is now the fifth most popular language, only behind C++, Python, C, and Java. It's even ahead of JavaScript, which currently lies in seventh place, down from sixth a year ago. C# meanwhile fell from fifth spot a year ago to sixth this month. The language index still reckons Visual Basic .Net will "sooner or later go into decline", but concedes it's popular for dedicated office applications in small and medium enterprises, and is probably still used by many developers because it's easy to learn.
TIOBE's methodology "basically...comes down to counting hits for the search query +"<language> programming," TIOBE explains on its web page -- though its results don't always agree with other analysts.

InfoWorld points out that on this month's PyPL Popularity of Programming Language index, which analyzes how often language tutorials are searched for on Google, VB.NET "doesn't even register Visual Basic.Net or Visual Basic among its Top 10 languages" -- and JavaScript comes in third, behind only Python and Java.
Programming

Microsoft's TypeScript Dominates In 'State of JavaScript 2018' Report (stateofjs.com) 68

This week a Paris-born designer/developer (now living in Osaka) announced the results of the third annual "State of JavaScript" survey of over 20,000 JavaScript developers in 153 countries "to figure out what they're using, what they're happy with, and what they want to learn."

An anonymous reader writes: Among its findings? The number of people who have used Microsoft's TypeScript and said they would use it again has increased from 20.08% in 2016 to 46.7% in 2018, "and in some countries that ratio even went over 50%." More than 7,000 respondents indicated they liked its "robust, less error-prone code" and another 5,500 cited "elegant programming style and patterns." A blog post announcing the results declares TypeScript "the clear leader" among other syntaxes and languages that can compile to JavaScript.

Meanwhile, when it comes to frameworks, "only React has both a high satisfaction ratio and a large user base, although Vue is definitely getting there." Elsewhere the report notes Vue has already overtaken React for certain metrics such as total GitHub stars. "Angular on the other hand does boast a large user base, but its users don't seem too happy," the announcement adds, although later the report argues that Angular's poor satisfaction ratio "is probably in part due to the confusion between Angular and the older, deprecated AngularJS (previous surveys avoided this issue by featuring both as separate items)."

94% of the survey's respondents were male, and "Years of experience" for the respondents seemed to cluster in three cohorts in the demographics breakdown: 27.8% of respondents reported they had 2-5 years of experience, while 28% reported 5-10 years, and 24% reported 10-20 years.

There's a beautiful interactive graphic visualizing "connections between technologies," where a circle's outer red band is segmented based on the popularity of JavaScript libraries, while hovering over each band reveals the popularity of other libraries with its users. But while this year's results were presented on a "dark mode" web page, the survey's announcement concedes that this year's trends didn't include many surprises.

"TL;DR: things didn't change that much this year."
Programming

GitHub's Four Most Popular Programming Languages Remain: JavaScript, Java, Python, and PHP (thenewstack.io) 144

A recent TechCrunch article claimed to have identified the best indicator of programming language popularity: GitHub's annual "State of the Octoverse" reports. So Austin-based technology reporter Mike Melanson explored the new verdict in GitHub's 2018 report: It felt to me like the overarching theme of the numbers was one of quiet stasis for the year past, at least when it comes to those languages deemed the cream of the crop. One of the first graphics offered in the post shows the top languages according to the number of repositories created and we see that everything seems to be flowing along, just as it has for the last decade. While GitHub points to a "steady uptick" for JavaScript after 2011, it looks like this list of languages hasn't changed much over time. [The graphic shows the four most popular languages -- every year since early 2014 -- have been JavaScript, Java, Python, and PHP.]

When we look at the top languages according to the number of contributors, we see a similar story, with the top four languages mirrored. In this chart, of course, we see that Ruby is on a steady decline, while Typescript is on a steady rise. The only surprise to be seen here is that C, after a brief uptick in popularity, has taken a bit of a nosedive over the past year. Either way, seven of 10 languages have the same exact ranking....

Finally, beyond the language rankings themselves, GitHub offers a wonderful analysis of just what it is that makes a particular language popular in 2018, boiling it down to three key characteristics: thread safety, interoperability, and being open source.

GitHub's report also identifies its fastest growing languages over the last year -- including Kotin, TypeScript, Rust, Python, and Go. "This year, TypeScript shot up to #7 among top languages used on the platform overall, after making its way in the top 10 for the first time last year," the report notes.

"TypeScript is now in the top 10 most used languages across all regions GitHub contributors come from -- and across private, public, and open source repositories."
Transportation

Cyclists Are Faster Than Cars And Motorbikes in Cities and Towns, Study Says (forbes.com) 414

Smartphone data from riders and drivers schlepping meals for restaurant-to-home courier service Deliveroo shows that bicycles are faster than cars and motorized two-wheelers. From a news writeup, which sources its data from Deliveroo, a UK-headquartered food delivery company with more than 30,000 riders and drivers in 13 countries: That bicyclists are faster in cities will come as no surprise to bicycle advocates who have staged so-called "commuter races" for many years. However, these races -- organized to highlight the swiftness of urban cycling -- are usually staged in locations and at hours skewed towards bicycle riders. The Deliveroo stats are significant because they have been extracted from millions of actual journeys. And it's all thanks to Frank.

Frank is the name Deliveroo gives its routing algorithm (the name was chosen for the Danny DeVito character in the TV series "It's Always Sunny in Philadelphia.") Delivering millions of simultaneous orders from thousands of restaurants to hungry consumers within 30 minutes using roving self-employed couriers equipped with smartphones is a complex vehicle routing problem: consumers want piping hot food; restaurants want meals picked up when cooked; riders -- paid per drop -- want multiple deliveries per hour, and Deliveroo needs to make money. The algorithm team employs data scientists with PhDs in computer vision, computer science, operations research, cognitive neuroscience, econometrics, machine learning, and physics.

Stats

1 In 4 Statisticians Say They Were Asked To Commit Scientific Fraud (acsh.org) 95

As the saying goes, "There are three kinds of lies: lies, damned lies, and statistics." We know that's true because statisticians themselves just said so. From a report: A stunning report published in the Annals of Internal Medicine concludes that researchers often ask statisticians to make "inappropriate requests." And by "inappropriate," the authors aren't referring to accidental requests for incorrect statistical analyses; instead, they're referring to requests for unscrupulous data manipulation or even fraud. The authors surveyed 522 consulting biostatisticians and received sufficient responses from 390. Then, they constructed a table that ranks requests by level of inappropriateness. For instance, at the very top is "falsify the statistical significance to support a desired result," which is outright fraud. At the bottom is "do not show plot because it did not show as strong an effect as you had hoped," which is only slightly naughty.
Power

New Material Could Up Efficiency of Concentrated Solar Power (arstechnica.com) 80

An anonymous reader shares new work that could allow us to generate electricity using supercritical carbon dioxide. Ars Technica reports: The researchers involved in the new work, a large U.S.-based collaboration, focus on a composite material: tungsten and zirconium carbide. These have extremely high melting points: 3,700K for both materials. Both of them conduct heat extremely well, and neither of them expands or softens much under these conditions, meaning they would hold up better to the mechanical stresses. While the stats are impressive, the amazing part of this is how the material is fabricated. The researchers started with tungsten carbide, a ceramic that can be formed into a porous material simply by pouring it as a powder into a mold and heating it. At this point, the ceramic can be further machined to produce a final shape. Once in its final form, the ceramic was placed in a bath of a molten mixture of copper and zirconium. The molten mixture filled the pores, and the zirconium reacted with the tungsten carbide, replacing the tungsten. The copper in the molten material formed a thin film on the surface of the solid.

The tungsten then filled the pores in the resulting material, allowing it to retain the same shape and size despite the chemical changes. The zircon carbide ends up providing the material with a stiffness even at high temperatures, while the tungsten is flexible enough to keep the whole thing from being brittle. And the whole thing conducted heat better than the metals currently in use. The remaining issue is that, at the conditions involved in solar thermal plants, the copper on the material would react with the carbon dioxide, forming a copper oxide and releasing carbon monoxide. But the researchers determined that adding a small amount of carbon monoxide to the supercritical CO2 would suppress this reaction, something that they confirmed experimentally. Because the material holds up to these conditions so much better than the metals currently in use, it's possible to use much less of it to build a heat exchanger. This is great economically (since you need fewer raw materials), and the small size increases the power density and efficiency of the heat exchanger.

Security

'Do Not Track,' the Privacy Tool Used By Millions of People, Doesn't Do Anything (gizmodo.com) 228

An anonymous reader quotes a report from Gizmodo: When you go into the privacy settings on your browser, there's a little option there to turn on the "Do Not Track" function, which will send an invisible request on your behalf to all the websites you visit telling them not to track you. A reasonable person might think that enabling it will stop a porn site from keeping track of what she watches, or keep Facebook from collecting the addresses of all the places she visits on the internet, or prevent third-party trackers she's never heard of from following her from site to site. According to a recent survey by Forrester Research, a quarter of American adults use "Do Not Track" to protect their privacy. (Our own stats at Gizmodo Media Group show that 9% of visitors have it turned on.) We've got bad news for those millions of privacy-minded people, though: "Do Not Track" is like spray-on sunscreen, a product that makes you feel safe while doing little to actually protect you.

Yahoo and Twitter initially said they would respect it, only to later abandon it. The most popular sites on the internet, from Google and Facebook to Pornhub and xHamster, never honored it in the first place. Facebook says that while it doesn't respect DNT, it does "provide multiple ways for people to control how we use their data for advertising." (That is of course only true so far as it goes, as there's some data about themselves users can't access.) From the department of irony, Google's Chrome browser offers users the ability to turn off tracking, but Google itself doesn't honor the request, a fact Google added to its support page some time in the last year. [...] "It is, in many respects, a failed experiment," said Jonathan Mayer, an assistant computer science professor at Princeton University. "There's a question of whether it's time to declare failure, move on, and withdraw the feature from web browsers." That's a big deal coming from Mayer: He spent four years of his life helping to bring Do Not Track into existence in the first place.
Only a handful of sites actually respect the request -- the most prominent of which are Pinterest and Medium (Pinterest won't use offsite data to target ads to a visitor who's elected not to be tracked, while Medium won't send their data to third parties.)
Microsoft

Microsoft To Disable TLS 1.0 and TLS 1.1 Support in Edge and Internet Explorer (zdnet.com) 64

Microsoft today said it plans to disable support for Transport Layer Security (TLS) 1.0 and 1.1 in Edge and Internet Explorer browsers by the first half of 2020. From a report: "January 19th of next year marks the 20th anniversary of TLS 1.0, the inaugural version of the protocol that encrypts and authenticates secure connections across the web," said Kyle Pflug, Senior Program Manager for Microsoft Edge. "Two decades is a long time for a security technology to stand unmodified," he said. "While we aren't aware of significant vulnerabilities with our up-to-date implementations of TLS 1.0 and TLS 1.1 [...] moving to newer versions helps ensure a more secure Web for everyone."

The move comes as the Internet Engineering Task Force (IETF) -- the organization that develops and promotes Internet standards -- is hosting discussions to formally deprecated both TLS 1.0 and 1.1. Microsoft is currently working on adding support for the official version of the recently-approved TLS 1.3 standard. Edge already supports draft versions of TLS 1.3, but not yet the final TLS 1.3 version approved in March, this year. Microsoft engineers don't seem to be losing any sleep over their decision to remove both standards from Edge and IE. The company cites public stats from SSL Labs showing that 94 percent of the Internet's sites have already moved to using TLS 1.2, leaving very few sites on the older standard versions. "Less than one percent of daily connections in Microsoft Edge are using TLS 1.0 or 1.1," Pflug said, also citing internal stats.
You can check public stats on the usage of TLS 1.0 and 1.1 here.

Slashdot Top Deals