<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Network-Security on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/network-security/</link><description>Recent content in Network-Security on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 04:25:25 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/network-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Firewall vs WAF: Network Gatekeeper or Application-Layer Guard</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-firewall-vs-waf-network-gatekeeper-or-application-layer-guar/</link><pubDate>Mon, 03 Aug 2026 04:25:25 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-firewall-vs-waf-network-gatekeeper-or-application-layer-guar/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;A firewall and a web application firewall (WAF) both filter traffic, but they operate at different layers of the stack. A firewall makes allow/deny decisions based on &lt;strong class="kw"&gt;IP and port&lt;/strong&gt;, while a WAF inspects the actual &lt;strong class="kw"&gt;HTTP payload&lt;/strong&gt; of requests to catch application-layer attacks like SQL injection and XSS. Most production environments deploy both, since neither can see what the other is built to catch.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="160" y="30" text-anchor="middle" font-size="18" style="fill:var(--primary)"&gt;Firewall&lt;/text&gt;&lt;text x="480" y="30" text-anchor="middle" font-size="18" style="fill:var(--primary)"&gt;WAF&lt;/text&gt;&lt;line x1="320" y1="45" x2="320" y2="335" style="stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4,4"/&gt;&lt;text x="160" y="58" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Raw network traffic&lt;/text&gt;&lt;rect x="95" y="65" width="130" height="25" rx="3" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="82" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;TCP SYN, dst port 22&lt;/text&gt;&lt;line x1="160" y1="90" x2="160" y2="115" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;polygon points="155,112 165,112 160,120" style="fill:var(--compare-a)"/&gt;&lt;rect x="85" y="120" width="150" height="55" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="2"/&gt;&lt;text x="160" y="142" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Firewall&lt;/text&gt;&lt;text x="160" y="158" text-anchor="middle" font-size="9.5" style="fill:var(--secondary)"&gt;L3/L4: IP, port, protocol&lt;/text&gt;&lt;line x1="160" y1="175" x2="122" y2="200" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;line x1="160" y1="175" x2="197" y2="200" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;rect x="90" y="200" width="65" height="28" rx="3" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="122" y="218" text-anchor="middle" font-size="9.5" style="fill:var(--content)"&gt;Allow 443&lt;/text&gt;&lt;rect x="165" y="200" width="65" height="28" rx="3" style="fill:none;stroke:var(--compare-a)" stroke-width="1.5" stroke-dasharray="3,3"/&gt;&lt;text x="197" y="218" text-anchor="middle" font-size="9.5" style="fill:var(--content)"&gt;Block 22&lt;/text&gt;&lt;text x="160" y="252" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;Cannot see inside the&lt;/text&gt;&lt;text x="160" y="266" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;HTTP request body&lt;/text&gt;&lt;text x="480" y="55" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;HTTP request&lt;/text&gt;&lt;rect x="395" y="65" width="170" height="25" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="82" text-anchor="middle" font-size="9" style="fill:var(--content)"&gt;GET /login?id=1' OR '1'='1&lt;/text&gt;&lt;line x1="480" y1="90" x2="480" y2="115" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;polygon points="475,112 485,112 480,120" style="fill:var(--compare-b)"/&gt;&lt;rect x="405" y="120" width="150" height="55" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="2"/&gt;&lt;text x="480" y="142" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;WAF&lt;/text&gt;&lt;text x="480" y="158" text-anchor="middle" font-size="9.5" style="fill:var(--secondary)"&gt;L7: URL, headers, body&lt;/text&gt;&lt;line x1="480" y1="175" x2="442" y2="200" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="480" y1="175" x2="517" y2="200" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;rect x="410" y="200" width="65" height="28" rx="3" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="442" y="218" text-anchor="middle" font-size="9.5" style="fill:var(--content)"&gt;Allow normal&lt;/text&gt;&lt;rect x="485" y="200" width="65" height="28" rx="3" style="fill:none;stroke:var(--compare-b)" stroke-width="1.5" stroke-dasharray="3,3"/&gt;&lt;text x="517" y="218" text-anchor="middle" font-size="9.5" style="fill:var(--content)"&gt;Block SQLi&lt;/text&gt;&lt;text x="480" y="252" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;Decrypts TLS to inspect&lt;/text&gt;&lt;text x="480" y="266" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;the request payload&lt;/text&gt;&lt;text x="320" y="310" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Layered defense: firewall blocks unauthorized access, WAF blocks malicious payloads&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Firewall&lt;/th&gt;
&lt;th&gt;WAF&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;OSI layer inspected&lt;/td&gt;
&lt;td&gt;Network/transport (L3/L4)&lt;/td&gt;
&lt;td&gt;Application (L7)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Traffic filtered&lt;/td&gt;
&lt;td&gt;All IP traffic, any protocol or port&lt;/td&gt;
&lt;td&gt;HTTP/HTTPS requests only&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Inspection criteria&lt;/td&gt;
&lt;td&gt;Source/destination IP, port, protocol, connection state&lt;/td&gt;
&lt;td&gt;URL, headers, cookies, and request body content&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Rule basis&lt;/td&gt;
&lt;td&gt;Static allow/deny rules and ACLs&lt;/td&gt;
&lt;td&gt;Signature and behavioral rules for known attack patterns&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical deployment point&lt;/td&gt;
&lt;td&gt;Network perimeter or between internal subnets&lt;/td&gt;
&lt;td&gt;In front of or alongside web servers/load balancers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Attacks stopped&lt;/td&gt;
&lt;td&gt;Port scans, unauthorized network access, network-layer floods&lt;/td&gt;
&lt;td&gt;SQL injection, XSS, CSRF, other OWASP Top 10 exploits&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Encrypted traffic handling&lt;/td&gt;
&lt;td&gt;Sees only packet headers, not TLS-encrypted payload&lt;/td&gt;
&lt;td&gt;Typically terminates TLS to inspect decrypted HTTP content&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Maintenance cadence&lt;/td&gt;
&lt;td&gt;Relatively static rule sets, infrequent changes&lt;/td&gt;
&lt;td&gt;Frequent signature updates as new exploits are discovered&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A firewall filters at the &lt;strong class="kw"&gt;network layer&lt;/strong&gt; using IP and port, while a WAF filters at the &lt;strong class="kw"&gt;application layer&lt;/strong&gt; using HTTP content.&lt;/li&gt;
&lt;li&gt;Firewalls control which connections are permitted; WAFs inspect the &lt;strong class="kw"&gt;payload&lt;/strong&gt; within connections already allowed through.&lt;/li&gt;
&lt;li&gt;A WAF typically must &lt;strong class="kw"&gt;decrypt TLS&lt;/strong&gt; to read requests, whereas a firewall generally cannot see inside encrypted traffic.&lt;/li&gt;
&lt;li&gt;The two are &lt;strong class="kw"&gt;complementary&lt;/strong&gt; controls, not substitutes — each blocks a different class of attack the other misses.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Firewall&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Zero Trust vs Perimeter Security: Verify Every Request or Trust the Network?</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-zero-trust-vs-perimeter-security-verify-every-request-or-tru/</link><pubDate>Mon, 03 Aug 2026 04:21:13 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-zero-trust-vs-perimeter-security-verify-every-request-or-tru/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Perimeter Security protects a network by treating everything inside a defined &lt;strong class="kw"&gt;boundary&lt;/strong&gt; as trusted, while Zero Trust assumes no user or device is trusted and requires &lt;strong class="kw"&gt;continuous verification&lt;/strong&gt; for every request. The distinction matters because cloud adoption, remote work, and lateral-movement attacks have made a hardened network edge insufficient as the sole line of defense.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;line x1="320" y1="60" x2="320" y2="320" style="stroke:var(--border)" stroke-width="1"/&gt;&lt;text x="195" y="32" text-anchor="middle" style="fill:var(--primary)" font-size="18" font-weight="bold"&gt;Perimeter Security&lt;/text&gt;&lt;text x="195" y="50" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;Trust based on network location&lt;/text&gt;&lt;circle cx="70" cy="110" r="16" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="70" y="145" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;User&lt;/text&gt;&lt;rect x="100" y="70" width="190" height="210" rx="8" style="fill:none;stroke:var(--compare-a)" stroke-width="3"/&gt;&lt;text x="195" y="293" text-anchor="middle" style="fill:var(--secondary)" font-size="10"&gt;Trusted zone (flat network)&lt;/text&gt;&lt;line x1="86" y1="110" x2="150" y2="112" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="118" y="100" text-anchor="middle" style="fill:var(--content)" font-size="9"&gt;Firewall&lt;/text&gt;&lt;rect x="150" y="95" width="110" height="34" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="205" y="116" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;App Server&lt;/text&gt;&lt;rect x="150" y="150" width="110" height="34" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="205" y="171" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;Database&lt;/text&gt;&lt;rect x="150" y="205" width="110" height="34" rx="4" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="205" y="226" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;File Share&lt;/text&gt;&lt;line x1="140" y1="112" x2="140" y2="222" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="3,3"/&gt;&lt;line x1="140" y1="112" x2="150" y2="112" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="3,3"/&gt;&lt;line x1="140" y1="167" x2="150" y2="167" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="3,3"/&gt;&lt;line x1="140" y1="222" x2="150" y2="222" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="3,3"/&gt;&lt;text x="480" y="32" text-anchor="middle" style="fill:var(--primary)" font-size="18" font-weight="bold"&gt;Zero Trust&lt;/text&gt;&lt;text x="480" y="50" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;Verify every request, every time&lt;/text&gt;&lt;circle cx="370" cy="110" r="16" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="370" y="145" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;User&lt;/text&gt;&lt;rect x="400" y="95" width="65" height="30" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="432" y="114" text-anchor="middle" style="fill:var(--content)" font-size="9"&gt;Verify Identity&lt;/text&gt;&lt;line x1="386" y1="110" x2="400" y2="110" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="465" y1="105" x2="480" y2="112" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="465" y1="112" x2="480" y2="167" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;line x1="465" y1="118" x2="480" y2="222" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;circle cx="472" cy="140" r="5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1"/&gt;&lt;circle cx="472" cy="190" r="5" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1"/&gt;&lt;rect x="480" y="95" width="110" height="34" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="535" y="116" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;App Server&lt;/text&gt;&lt;rect x="480" y="150" width="110" height="34" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="535" y="171" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;Database&lt;/text&gt;&lt;rect x="480" y="205" width="110" height="34" rx="4" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="535" y="226" text-anchor="middle" style="fill:var(--content)" font-size="11"&gt;File Share&lt;/text&gt;&lt;text x="535" y="293" text-anchor="middle" style="fill:var(--secondary)" font-size="10"&gt;Micro-segmented (no lateral trust)&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Perimeter Security&lt;/th&gt;
&lt;th&gt;Zero Trust&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Core trust model&lt;/td&gt;
&lt;td&gt;Trust is granted based on network location; inside the boundary is assumed safe&lt;/td&gt;
&lt;td&gt;No implicit trust; identity and context are verified for every request&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Entry authentication&lt;/td&gt;
&lt;td&gt;Checked once at the network edge via firewall or VPN gateway&lt;/td&gt;
&lt;td&gt;Checked continuously, regardless of where the request originates&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Internal network structure&lt;/td&gt;
&lt;td&gt;Largely flat trusted zone once past the boundary&lt;/td&gt;
&lt;td&gt;Micro-segmented, with access scoped to individual resources&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lateral movement after compromise&lt;/td&gt;
&lt;td&gt;High risk — a foothold on one host can reach many internal systems&lt;/td&gt;
&lt;td&gt;Low risk — each hop requires separate re-authorization&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remote and cloud access&lt;/td&gt;
&lt;td&gt;Extends the perimeter to remote users via VPN tunnels&lt;/td&gt;
&lt;td&gt;Grants access by identity, independent of network location&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Breach containment&lt;/td&gt;
&lt;td&gt;A single perimeter breach can expose the entire internal network&lt;/td&gt;
&lt;td&gt;Blast radius limited to the specific resource and session compromised&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Policy enforcement point&lt;/td&gt;
&lt;td&gt;Centralized at the network edge (firewall, VPN gateway)&lt;/td&gt;
&lt;td&gt;Distributed per resource via a policy engine on each request&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Operational complexity&lt;/td&gt;
&lt;td&gt;Lower upfront complexity with coarse-grained rules&lt;/td&gt;
&lt;td&gt;Higher upfront complexity requiring fine-grained, continuously managed policies&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Perimeter Security grants broad access once a device is inside the &lt;strong class="kw"&gt;network boundary&lt;/strong&gt;; Zero Trust re-authenticates every request.&lt;/li&gt;
&lt;li&gt;Zero Trust relies on &lt;strong class="kw"&gt;micro-segmentation&lt;/strong&gt; to isolate resources, whereas Perimeter Security typically has one flat trusted zone.&lt;/li&gt;
&lt;li&gt;Remote workers under Perimeter Security must tunnel in via &lt;strong class="kw"&gt;VPN&lt;/strong&gt;; Zero Trust grants access based on identity regardless of location.&lt;/li&gt;
&lt;li&gt;A breach inside a perimeter can move laterally with little friction; Zero Trust limits blast radius through continuous &lt;strong class="kw"&gt;policy enforcement&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Perimeter Security is simpler to deploy initially; Zero Trust requires ongoing &lt;strong class="kw"&gt;identity and context&lt;/strong&gt; evaluation infrastructure.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Perimeter Security&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>IDS vs IPS: Detecting Threats vs Blocking Them</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-ids-vs-ips-detecting-threats-vs-blocking-them/</link><pubDate>Mon, 03 Aug 2026 04:19:00 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-ids-vs-ips-detecting-threats-vs-blocking-them/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;An IDS and an IPS both inspect network traffic for malicious patterns, but they sit in different places and react differently once a threat is found. An IDS works &lt;strong class="kw"&gt;out-of-band&lt;/strong&gt;, watching a copy of traffic and raising alerts, while an IPS works &lt;strong class="kw"&gt;inline&lt;/strong&gt;, sitting directly in the traffic path so it can block the packets itself. The distinction matters because it determines whether a false positive causes a noisy log entry or an actual outage.&lt;/p&gt;</description></item><item><title>TLS vs SSL: Encryption Protocol Evolution</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-tls-vs-ssl-encryption-protocol-evolution/</link><pubDate>Mon, 03 Aug 2026 04:17:43 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-tls-vs-ssl-encryption-protocol-evolution/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;SSL and TLS are cryptographic protocols that secure data in transit between clients and servers, but SSL is the deprecated &lt;strong class="kw"&gt;predecessor&lt;/strong&gt; while TLS is its actively maintained &lt;strong class="kw"&gt;successor&lt;/strong&gt;. Every SSL version is now broken or prohibited, yet the term &amp;ldquo;SSL&amp;rdquo; persists in everyday usage even though modern connections actually negotiate TLS.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="140" y="36" font-size="22" font-weight="bold" text-anchor="middle" style="fill:var(--primary)"&gt;SSL&lt;/text&gt;&lt;text x="480" y="36" font-size="22" font-weight="bold" text-anchor="middle" style="fill:var(--primary)"&gt;TLS&lt;/text&gt;&lt;line x1="20" y1="60" x2="620" y2="60" stroke-width="1.5" style="stroke:var(--border)"/&gt;&lt;rect x="40" y="80" width="180" height="44" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="130" y="98" font-size="14" text-anchor="middle" style="fill:var(--content)"&gt;SSL 2.0 (1995)&lt;/text&gt;&lt;text x="130" y="115" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;broken by DROWN&lt;/text&gt;&lt;rect x="40" y="140" width="180" height="44" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="130" y="158" font-size="14" text-anchor="middle" style="fill:var(--content)"&gt;SSL 3.0 (1996)&lt;/text&gt;&lt;text x="130" y="175" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;broken by POODLE&lt;/text&gt;&lt;rect x="40" y="200" width="180" height="36" rx="6" stroke-dasharray="4 3" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="130" y="223" font-size="13" text-anchor="middle" style="fill:var(--secondary)"&gt;all versions prohibited&lt;/text&gt;&lt;path d="M230 118 L390 98" style="stroke:var(--border)" stroke-width="1.5" fill="none" marker-end="url(#arrow)"/&gt;&lt;defs&gt;&lt;marker id="arrow" markerWidth="8" markerHeight="8" refX="6" refY="3" orient="auto"&gt;&lt;path d="M0,0 L6,3 L0,6 Z" style="fill:var(--border)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;rect x="400" y="70" width="200" height="38" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="500" y="94" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;TLS 1.0 (1999)&lt;/text&gt;&lt;rect x="400" y="118" width="200" height="38" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="500" y="142" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;TLS 1.1 (2006)&lt;/text&gt;&lt;rect x="400" y="166" width="200" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="500" y="190" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;TLS 1.2 (2008)&lt;/text&gt;&lt;text x="500" y="203" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;widely deployed&lt;/text&gt;&lt;rect x="400" y="216" width="200" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="500" y="240" font-size="13" text-anchor="middle" style="fill:var(--content)"&gt;TLS 1.3 (2018)&lt;/text&gt;&lt;text x="500" y="253" font-size="11" text-anchor="middle" style="fill:var(--secondary)"&gt;current standard&lt;/text&gt;&lt;line x1="40" y1="300" x2="600" y2="300" stroke-width="1.5" style="stroke:var(--border)" marker-end="url(#arrow)"/&gt;&lt;text x="320" y="320" font-size="12" text-anchor="middle" style="fill:var(--secondary)"&gt;time →&lt;/text&gt;&lt;text x="130" y="340" font-size="12" text-anchor="middle" style="fill:var(--compare-a)"&gt;deprecated / prohibited&lt;/text&gt;&lt;text x="500" y="340" font-size="12" text-anchor="middle" style="fill:var(--compare-b)"&gt;actively maintained&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;SSL&lt;/th&gt;
&lt;th&gt;TLS&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Origin&lt;/td&gt;
&lt;td&gt;Developed by Netscape starting in 1995&lt;/td&gt;
&lt;td&gt;Standardized by the IETF in 1999 as SSL&amp;rsquo;s successor&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Versions released&lt;/td&gt;
&lt;td&gt;SSL 2.0, SSL 3.0 (SSL 1.0 never shipped)&lt;/td&gt;
&lt;td&gt;TLS 1.0, 1.1, 1.2, 1.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Handshake process&lt;/td&gt;
&lt;td&gt;Full handshake only, with weaker key exchange options&lt;/td&gt;
&lt;td&gt;Streamlined handshake; TLS 1.3 cuts a round trip and defaults to forward secrecy&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cipher suite support&lt;/td&gt;
&lt;td&gt;Permits weak ciphers like RC4, DES, and export-grade crypto&lt;/td&gt;
&lt;td&gt;Mandates modern AEAD ciphers (AES-GCM, ChaCha20-Poly1305); weak ciphers dropped entirely in 1.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Known vulnerabilities&lt;/td&gt;
&lt;td&gt;POODLE broke SSL 3.0; DROWN broke SSL 2.0&lt;/td&gt;
&lt;td&gt;BEAST and CRIME hit early TLS 1.0 but were patched in later versions&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Current status&lt;/td&gt;
&lt;td&gt;All versions formally deprecated and prohibited (RFC 7568)&lt;/td&gt;
&lt;td&gt;TLS 1.2 and 1.3 are the current standards; 1.0/1.1 also deprecated&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Everyday terminology&lt;/td&gt;
&lt;td&gt;&amp;ldquo;SSL certificate&amp;rdquo; and &amp;ldquo;SSL/TLS&amp;rdquo; persist as colloquial shorthand&lt;/td&gt;
&lt;td&gt;The protocol actually negotiated by nearly every modern HTTPS connection&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SSL is the obsolete &lt;strong class="kw"&gt;predecessor&lt;/strong&gt;; TLS is the actively maintained &lt;strong class="kw"&gt;successor&lt;/strong&gt; protocol&lt;/li&gt;
&lt;li&gt;TLS 1.3&amp;rsquo;s handshake trims a &lt;strong class="kw"&gt;round trip&lt;/strong&gt; compared to SSL&amp;rsquo;s full handshake&lt;/li&gt;
&lt;li&gt;SSL still permits weak ciphers like &lt;strong class="kw"&gt;RC4&lt;/strong&gt;; TLS mandates modern AEAD ciphers&lt;/li&gt;
&lt;li&gt;The label &amp;ldquo;&lt;strong class="kw"&gt;SSL certificate&lt;/strong&gt;&amp;rdquo; survives in marketing even though browsers negotiate TLS&lt;/li&gt;
&lt;li&gt;SSL 3.0 was broken by &lt;strong class="kw"&gt;POODLE&lt;/strong&gt;, forcing its complete deprecation&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;SSL&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>