On Monday, April 1, 2019, 1:02:28 PM EDT, The Poloniex Team [email protected] wrote:
Dear Poloniex Customer:
As part of our effort to provide you with the most secure experience, Poloniex is going to require the use of TLS 1.2 or greater. On April 15, 2019 we will disable support for TLS 1.0 and 1.1 as well as all versions of SSL for all our services, including our website and API.
You are receiving this email either because you have created API keys or because we have detected you are using a browser that may be affected. If you are using TLS 1.0 or 1.1 after April 15th, your client will not be able to connect to the Poloniex site or API endpoints. If you use an API client to connect, you may see a message such as: “SSL/TLS Handshake Failed.” Depending on the libraries that you are using, error messages will vary. If you use a browser, you will be unable to access the site. To prevent this, we recommend updating your browser or API client to one that supports the newer protocols.
We are doing this because early versions of TLS are considered vulnerable beyond repair. This is in keeping with the PCI Security Standards Council, the organization that sets security standards for companies that accept credit cards, that has required TLS 1.1 since June 2018 while strongly encouraging the use of TLS 1.2 or greater. They state:
There are many serious vulnerabilities in SSL and early TLS that left unaddressed put organizations at risk of being breached. The widespread POODLE and BEAST exploits are just a couple examples of how attackers have taken advantage of weaknesses in SSL and early TLS to compromise organizations.
According to NIST, there are no fixes or patches that can adequately repair SSL or early TLS. Therefore, it is critically important that organizations upgrade to a secure alternative as soon as possible, and disable any fallback to both SSL and early TLS.
As always, if you have any questions or concerns, please reach out to our support team at https://poloniex.freshdesk.com/.
The Poloniex Team
Circle – The new shape of money
© 2019 Poloniex, LLC
Poloniex, LLC, PO Box 51806, Boston, MA 02205