What else do these websites support?

A comparison of TLS hygiene

Provider-balanced security comparison
HybridConventional

TLS versions and ciphers

Support for older protocol versions and encryption configurations.

Legacy TLS versions

Lower indicates less of this legacy feature or issue
Hybrid18.0%
Conventional14.7%

Support for TLS 1.0 or TLS 1.1.

Deprecated cipher suites

Lower indicates less of this legacy feature or issue
Hybrid73.6%
Conventional49.9%

Support for at least one deprecated encryption configuration.

Certificates

Certificate-status sharing and whether certificate identities match the requested endpoints.

Certificate status sharing

Higher indicates more use of this certificate feature
Hybrid18.2%
Conventional3.9%

OCSP stapling lets a website provide recent certificate-status information during connection setup.

Certificate name mismatches

Lower indicates less of this legacy feature or issue
Hybrid0.7%
Conventional10.4%

The certificate identity does not match the requested website name.

Known vulnerability indicators

Configuration signals associated with known weaknesses.

BEAST

Lower indicates fewer reported configuration indicators
Hybrid17.2%
Conventional14.3%

TLS 1.0 with CBC-mode ciphers enabled, even when newer TLS versions are also supported.

BREACH

Lower indicates fewer reported configuration indicators
Hybrid50.6%
Conventional31.7%

HTTP compression detected in a response. Compression alone does not establish that an endpoint is exploitable.

Lucky13

Lower indicates fewer reported configuration indicators
Hybrid64.5%
Conventional51.3%

Support for CBC-mode ciphers. The study flags this feature without testing for vulnerable timing behavior.

SWEET32

Lower indicates fewer reported configuration indicators
Hybrid8.1%
Conventional4.1%

Support for ciphers that encrypt data in 64-bit blocks.

RC4

Lower indicates fewer reported configuration indicators
Hybrid0.00%
Conventional0.00%

Support for the deprecated RC4 cipher.

Provider-managed HTTPS endpoints, grouped by hybrid or conventional key exchange. Paper, §6.5 and the security-labeling appendix

A post-quantum upgrade is not a complete TLS upgrade.

Hybrid deployments show stronger certificate practices, but older protocols, deprecated cipher suites, and known weakness indicators remain. The PQC transition therefore offers an opportunity to review the wider TLS configuration alongside enabling post-quantum key exchange.

TAILORING THE TRANSITION

Different management models need different migration guidance.

Provider-managed hybrid endpoints more often retain deprecated cipher suites than their conventional counterparts, while owner-managed endpoints show the opposite pattern. Transition guidance should address these differences, encouraging providers to review shared configurations and helping individual operators update their own systems.

MEASURING TRANSITION PROGRESS

Track security improvements alongside adoption.

A rising post-quantum adoption rate tells only part of the story. Tracking certificate practices, legacy configurations, and known weakness indicators alongside adoption can show where migration brings broader improvements and where further work remains.

CONTINUE EXPLORING

Return to the bigger picture.

Explore the main findings or read the full paper.