<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Firefox 3, SSL and self-signed certs</title>
	<atom:link href="http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/</link>
	<description>I love you.</description>
	<lastBuildDate>Wed, 25 Jan 2012 17:08:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.4</generator>
	<item>
		<title>By: Robert</title>
		<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/comment-page-1/#comment-296787</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Tue, 21 Jun 2011 15:34:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.0xdeadbeef.com/weblog/?p=521#comment-296787</guid>
		<description>I&#039;d settle for a warning and the option to carry on gracefully.  The current set-up is nearly unworkable and turning all the warnings off is silly.  The last time I checked there were more options than #000000 and #FFFFFF</description>
		<content:encoded><![CDATA[<p>I&#8217;d settle for a warning and the option to carry on gracefully.  The current set-up is nearly unworkable and turning all the warnings off is silly.  The last time I checked there were more options than #000000 and #FFFFFF</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: scooter</title>
		<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/comment-page-1/#comment-296768</link>
		<dc:creator>scooter</dc:creator>
		<pubDate>Tue, 21 Jun 2011 03:18:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.0xdeadbeef.com/weblog/?p=521#comment-296768</guid>
		<description>@Christoper. Looks like the bypass [MitM Me (SSL Error Bypass) firefox plugin] for this improvement has been disabled by the adminstrator.</description>
		<content:encoded><![CDATA[<p>@Christoper. Looks like the bypass [MitM Me (SSL Error Bypass) firefox plugin] for this improvement has been disabled by the adminstrator.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dmytry</title>
		<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/comment-page-1/#comment-251148</link>
		<dc:creator>Dmytry</dc:creator>
		<pubDate>Thu, 04 Mar 2010 18:58:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.0xdeadbeef.com/weblog/?p=521#comment-251148</guid>
		<description>&quot;SSL does not provide any security without identity&quot;
You, being a developer, should know full well that SSL without identity does provide security against sniffing, which is the reason why routers commonly use SSL, and why every login form should use SSL (people use same password on multiple sites). Sniffing is a lot easier than man in the middle, and is extremely common. 
You&#039;re using your knowledge to knowingly mislead and misinform less technically inclined users with half truths or worse, less than half truths; that is in my opinion extremely shameful.
Furthermore, phishing is not affected by this warning due to fact that phishers are for most part NOT using self signed or expired certificates.</description>
		<content:encoded><![CDATA[<p>&#8220;SSL does not provide any security without identity&#8221;<br />
You, being a developer, should know full well that SSL without identity does provide security against sniffing, which is the reason why routers commonly use SSL, and why every login form should use SSL (people use same password on multiple sites). Sniffing is a lot easier than man in the middle, and is extremely common.<br />
You&#8217;re using your knowledge to knowingly mislead and misinform less technically inclined users with half truths or worse, less than half truths; that is in my opinion extremely shameful.<br />
Furthermore, phishing is not affected by this warning due to fact that phishers are for most part NOT using self signed or expired certificates.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Can we disable Firefox&#8217;s stupid self-signed encryption dialog? &#171; Richard WM Jones</title>
		<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/comment-page-1/#comment-238633</link>
		<dc:creator>Can we disable Firefox&#8217;s stupid self-signed encryption dialog? &#171; Richard WM Jones</dc:creator>
		<pubDate>Sat, 21 Nov 2009 10:19:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.0xdeadbeef.com/weblog/?p=521#comment-238633</guid>
		<description>[...] lot has been written about how Firefox&#8217;s stupid dialog is a big step backwards for the [...]</description>
		<content:encoded><![CDATA[<p>[...] lot has been written about how Firefox&#8217;s stupid dialog is a big step backwards for the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Firefox 3 handling of SSL Certs is broken &#171; Fiji Ecuador Seattle Greece Montana</title>
		<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/comment-page-1/#comment-227590</link>
		<dc:creator>Firefox 3 handling of SSL Certs is broken &#171; Fiji Ecuador Seattle Greece Montana</dc:creator>
		<pubDate>Tue, 13 Oct 2009 17:38:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.0xdeadbeef.com/weblog/?p=521#comment-227590</guid>
		<description>[...] http://www.0xdeadbeef.com/weblog/?p=521 [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.0xdeadbeef.com/weblog/?p=521" rel="nofollow">http://www.0xdeadbeef.com/weblog/?p=521</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Wulf</title>
		<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/comment-page-1/#comment-226359</link>
		<dc:creator>John Wulf</dc:creator>
		<pubDate>Wed, 07 Oct 2009 06:18:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.0xdeadbeef.com/weblog/?p=521#comment-226359</guid>
		<description>OH MY FIN GAWD.... I am an IT tech. I have 25 routers around the country. MOST are the same model of nergear, FVS318. I am FINALLY getting around to storing these in my favorites directory. I stored one, then 5 days later I connected to another one, planning on storing it, but OH MY GAWD, I can&#039;t even connect to it, because IT is using the SAME self signed certificate that the previous Netgear device is using, and I added an exemption, and NOW I get a failure that I can&#039;t even click around. I had to go find the previous certificate that I had added and exception for, delete it, then add this exception, which I will have to delete once I connect to the next one....
Just take this pistol and shoot me why don&#039;t you.</description>
		<content:encoded><![CDATA[<p>OH MY FIN GAWD&#8230;. I am an IT tech. I have 25 routers around the country. MOST are the same model of nergear, FVS318. I am FINALLY getting around to storing these in my favorites directory. I stored one, then 5 days later I connected to another one, planning on storing it, but OH MY GAWD, I can&#8217;t even connect to it, because IT is using the SAME self signed certificate that the previous Netgear device is using, and I added an exemption, and NOW I get a failure that I can&#8217;t even click around. I had to go find the previous certificate that I had added and exception for, delete it, then add this exception, which I will have to delete once I connect to the next one&#8230;.<br />
Just take this pistol and shoot me why don&#8217;t you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christopher Blizzard</title>
		<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/comment-page-1/#comment-195166</link>
		<dc:creator>Christopher Blizzard</dc:creator>
		<pubDate>Tue, 07 Jul 2009 08:13:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.0xdeadbeef.com/weblog/?p=521#comment-195166</guid>
		<description>You can install this add-on if you want:

https://addons.mozilla.org/en-US/firefox/addon/6843

Bypasses all those &quot;improvements.&quot;</description>
		<content:encoded><![CDATA[<p>You can install this add-on if you want:</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/6843" rel="nofollow">https://addons.mozilla.org/en-US/firefox/addon/6843</a></p>
<p>Bypasses all those &#8220;improvements.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/comment-page-1/#comment-195138</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Tue, 07 Jul 2009 00:02:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.0xdeadbeef.com/weblog/?p=521#comment-195138</guid>
		<description>For people who spend a significant part of their day working with hardware devices Firefox is no longer even an option.  You have &quot;improved&quot; yourself out of the hunt...I suppose I could run IE7 under Wine...it actually sucks (as opposed to being poorly implemented) but I can connect to my hardware with it.

Better yet, where is the source code?  I could get my guys to remove that &quot;improvement&quot; and recompile.</description>
		<content:encoded><![CDATA[<p>For people who spend a significant part of their day working with hardware devices Firefox is no longer even an option.  You have &#8220;improved&#8221; yourself out of the hunt&#8230;I suppose I could run IE7 under Wine&#8230;it actually sucks (as opposed to being poorly implemented) but I can connect to my hardware with it.</p>
<p>Better yet, where is the source code?  I could get my guys to remove that &#8220;improvement&#8221; and recompile.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/comment-page-1/#comment-190660</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Thu, 28 May 2009 05:44:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.0xdeadbeef.com/weblog/?p=521#comment-190660</guid>
		<description>Why can we not disable this? At least for a specific subset of hosts...

I understand the goal, but some people want a browser that &quot;just works&quot; and for all of our internal machines and network devices with self-signed certificates Firefox no longer &quot;just works&quot;.

Please fix this. soon.</description>
		<content:encoded><![CDATA[<p>Why can we not disable this? At least for a specific subset of hosts&#8230;</p>
<p>I understand the goal, but some people want a browser that &#8220;just works&#8221; and for all of our internal machines and network devices with self-signed certificates Firefox no longer &#8220;just works&#8221;.</p>
<p>Please fix this. soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nmn</title>
		<link>http://www.0xdeadbeef.com/weblog/2008/08/firefox-3-ssl-and-self-signed-certs/comment-page-1/#comment-189525</link>
		<dc:creator>nmn</dc:creator>
		<pubDate>Tue, 19 May 2009 06:56:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.0xdeadbeef.com/weblog/?p=521#comment-189525</guid>
		<description>This whole mess has made me start pushing users to move to Google Chrome or SRWare Iron over Firefox. Please fix it. It&#039;s ridiculous, I have to go through an ordeal just to help someone through a self-signed page that has no intentions whatsoever of preventing man-in-the-middle. And no, there&#039;s not a single damn soul who would care whether or not it takes 4 steps or 1 to go to the page; they&#039;re either going to go or not, it doesn&#039;t matter how many jumping jacks you ask them to do. Take it from Google, they&#039;ve mastered ease of use and security in one swipe and they&#039;re doing it in one step.

I don&#039;t want to offend, but this is absolutely ridiculous to deal with. There at least should be a way to disable via about:config. Didn&#039;t anyone think about the possibility that what they were doing was just about as effective as UAC? (annoys users, still makes it completely plausible to get exploited - although to the power user, UAC actually has value. Not only that, UAC can be disabled.)

Something must be done about this. This is a big deal.</description>
		<content:encoded><![CDATA[<p>This whole mess has made me start pushing users to move to Google Chrome or SRWare Iron over Firefox. Please fix it. It&#8217;s ridiculous, I have to go through an ordeal just to help someone through a self-signed page that has no intentions whatsoever of preventing man-in-the-middle. And no, there&#8217;s not a single damn soul who would care whether or not it takes 4 steps or 1 to go to the page; they&#8217;re either going to go or not, it doesn&#8217;t matter how many jumping jacks you ask them to do. Take it from Google, they&#8217;ve mastered ease of use and security in one swipe and they&#8217;re doing it in one step.</p>
<p>I don&#8217;t want to offend, but this is absolutely ridiculous to deal with. There at least should be a way to disable via about:config. Didn&#8217;t anyone think about the possibility that what they were doing was just about as effective as UAC? (annoys users, still makes it completely plausible to get exploited &#8211; although to the power user, UAC actually has value. Not only that, UAC can be disabled.)</p>
<p>Something must be done about this. This is a big deal.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

