← Back to release summary

GREASE for TLS

Category
Security
Type
New or changed feature
Status
Enabled by default (Chrome 55)
Intent stage
None

Summary

TLS clients offer lists of 16-bit code points (e.g. cipher suites) that servers select from. To remain extensible, servers must ignore unknown values. However, servers may have bugs and reject unknown values. These servers will interoperate with existing clients, so the mistake may spread unnoticed, breaking extensibility for the whole ecosystem. We will reserve some values to advertise at random, to prevent such mistakes before broken servers are widespread.

Standards & signals

View on chromestatus.com