+ Reply to Thread
Results 1 to 9 of 9

Thread: HTTPS Everywhere

  1. #1

    Join Date
    06.02.09
    Location
    Puerto Banús
    P2P Client
    Bash shell
    Posts
    462
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 ssssss462
    Last edited by SomeGuy; 02.08.10 at 14:19.
    Reply With QuoteReply With Quote
    Thanks

  2. Who Said Thanks:

    Blocker (29.08.10) , Snitlev (03.08.10) , slikrapid (02.08.10) , BrianBosworth (02.08.10)

  3. #2

    Join Date
    12.11.08
    Location
    Europe
    P2P Client
    Nothing ATM
    Posts
    303
    Activity Longevity
    0/20 18/20
    Today Posts
    0/5 ssssss303
    I use it.
    It don't work on most sites.
    Looks like it only works on sites with HTTPS support like SBI.
    Reply With QuoteReply With Quote
    Thanks

  4. #3
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,439
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39439
    You can't force SSL on a site that doesn't support it :)
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  5. #4

    Join Date
    28.07.10
    Location
    Peerlist
    P2P Client
    Vuze
    Posts
    171
    Activity Longevity
    0/20 16/20
    Today Posts
    0/5 ssssss171
    This can just make things more complicated. It's good without that addon.
    Reply With QuoteReply With Quote
    Thanks

  6. #5
    There is link in shoulder's signature that starts with https

    I always get a untrusted security warning when i click on it in firefox

    This Connection is Untrusted











    You have asked Firefox to connect
    securely to SB-Innovation - Leecher Mod Source Nr. 1 - Home, but we can't confirm that your connection is secure.



    Normally, when you try to connect securely,
    sites will present trusted identification to prove that you are
    going to the right place. However, this site's identity can't be verified.







    What Should I Do?





    If you usually connect to
    this site without problems, this error could mean that someone is
    trying to impersonate the site, and you shouldn't continue.











    Technical Details



    SB-Innovation - Leecher Mod Source Nr. 1 - Home uses an invalid security certificate.

    The certificate is not trusted because it is self-signed.
    The certificate is only valid for confixx
    The certificate expired on 14/01/10 2:22 AM.

    (Error code: sec_error_expired_issuer_certificate)







    I Understand the Risks

    Must be related...
    Reply With QuoteReply With Quote
    Thanks

  7. #6
    Moderator anon's Avatar
    Join Date
    01.02.08
    Posts
    39,439
    Activity Longevity
    8/20 19/20
    Today Posts
    1/5 ssss39439
    Our certificate is self-signed because we don't use it to prove our identity, but to encrypt traffic between you and the server. Firefox gives you a warning because many scam sites use self-signed certs, also. Add an exception for us and it's all good!
    "I just remembered something that happened a long time ago."
    Reply With QuoteReply With Quote
    Thanks

  8. Who Said Thanks:

    hearthrob (06.01.11) , slikrapid (03.08.10)

  9. #7
    Advanced User Renk's Avatar
    Join Date
    17.08.08
    Location
    Elsewhere
    P2P Client
    utorrent
    Posts
    581
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 ssssss581
    Quote Originally Posted by Grambo View Post
    I use it.
    It don't work on most sites
    Looks like it only works on sites with HTTPS support like SBI.
    it works on "EFF predefinite" sites, such as google, wikipedia, etc. EFF explain how to add more sites, but the added sites have obviously to support SSL.

    It seems Noscript has similar feature (options->advanced->https). You can try ForceTLS, too.

    With httpsEverywhere, a problem happens when I type google.com: I no more have access to the cool features of Google Pirate V2. The problem could be solved in using some offshore google address, such as google.ag (for wich https feature is not yet implemented).

    An other potential problem relies on the way the translation http -> https is done by the extensions. In case some MIM attack might occur, the extention SSLGuard may prevent some kind of them.


    Quote Originally Posted by Resurrection View Post
    There is link in shoulder's signature that starts with https

    I always get a untrusted security warning when i click on it in firefox

    Must be related...
    As anon said, it's related to certificate self-signature. One way to sometimes solve this kind of problem is to use the extension Perspectives, wich uses "notaries", run by academic researchers, asking servers for their public key. With Perspectives, when yopur browser has to authenticate a key, it ask the notaries.


    Perspectives prevent in some way MIM attack too, and it's not entirely clear for me if Perpectives and SSLguard are redundant or complementary (or if there is some kind of incompatibility ?)
    Last edited by Renk; 20.08.10 at 22:35.
    Reply With QuoteReply With Quote
    Thanks

  10. #8

    Join Date
    24.08.10
    Location
    you really wanna know ?
    P2P Client
    utorrent 2.0.4
    Posts
    31
    Activity Longevity
    0/20 16/20
    Today Posts
    0/5 sssssss31
    small question :) what is https all about ?
    Reply With QuoteReply With Quote
    Thanks

  11. #9
    Moderator
    Instab's Avatar
    Join Date
    17.09.09
    Posts
    6,661
    Activity Longevity
    4/20 17/20
    Today Posts
    0/5 sssss6661
    Quote Originally Posted by soso View Post
    small qüstion :) what is https all about ?
    HTTP Secure - Wikipedia, the free encyclopedia
    Your account has been disabled.
    Reply With QuoteReply With Quote
    Thanks

  12. Who Said Thanks:

    anon (29.08.10)

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •