learn linux and unix commands - unix shell scripting

Firefox's Bold Move


 
Thread Tools Search this Thread
# 1  
Old 08-26-2008
Firefox's Bold Move

The blog at Pingdom.com discusses the change Firefox made recently to how it reacts to invalid certificates. Actually, the post is more concerned about how the user will react to this change, because now when Firefox (version 3.01) comes across a page using SSL with an invalid certificate (expired, non-FQDM used, etc.) the user gets the very user-unfriendly error "Secure Connection Failed. [site address] uses an invalid security certificate." It isn't a warning in a small pop-up window or a bar at the top that is easily dismissed. No, this is an in-your-face, impossible to ignore, error. Which, I think, is great.

I have had personal experience with this recently. When, using Firefox, I try to log on to a blogging service that I recently started using, the site is redirected to https:// that appears to be using an invalid certificate, because instead of the log in page I get the "Secure Connection Failed" page. Digging deeper into the error and certificate, it's pretty plain to see that the certificate being used has some problems: it has CN=localhost.domain for both the Issued To and Issued By fields for starters.

At the bottom of the Firefox-generated error page are two buttons: "Get me out of here!" and "Add exception..." Clicking the latter allows you to see the details of the invalid certificate, and gives you the option of adding the certificate as an exception (you can later remove this exception by going to the Firefox preferences.) Again, other browsers do not inform the user in such an obvious way, meaning the user can be fooled into thinking that the current SSL session is secure.

It's a bold move on Firefox's part, but a good one, because in my opinion users have had it too easy when it comes to internet security. Hence the mind-boggling number of zombies and data theft incidents, for which everyone pays. Unless we start putting up loud notifications that the user actually has to read and consider, users will continue to dismiss these errors as annoyances, even though ignoring them they could have devastating consequences (MITM attacks, spoofing, etc.)

Lastly, the Firefox approach is also a win-win situation, because the companies whose sites are presented to the user as broken will be very motivated to get their own security house in order, fast.


Image
Image

More...
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

Bold Characters

Hi All, How to make the characters bold in k shell. like for example "File is too large to view" to "File is too large to view" is it like echo "File is too large to view" Please advice and samples (18 Replies)
Discussion started by: rajeshorpu
18 Replies

2. Shell Programming and Scripting

how to display in bold

Hi, i am using mailx option to send mail from unix In the body of the mail i want certain numbers to be displayed in bold Is there any way to do it If so, can anyone help me in this regard. (2 Replies)
Discussion started by: trichyselva
2 Replies

3. Shell Programming and Scripting

how can i bold a text

Dear i want to bold a text using shell script. please give sample.. Thanks rex (1 Reply)
Discussion started by: jrex1983
1 Replies

4. UNIX for Dummies Questions & Answers

What does a bold filename in ls mean?

I am ssh'd into my box using a terminal emulation of vt100. When I do a directory listing (ls) some of the file names are bold. I know that directories are also in bold, but these are not directories. What does a bolded filename mean? This seems like such a basic question, but I've spent 20... (3 Replies)
Discussion started by: nunemaj
3 Replies

5. Shell Programming and Scripting

color,bold

hi friend , I am generating a csv file i,e output file E104|0|06/04/1994|The values E005 and E001 are not equal. E106|0|01/09/1993|The values E001 and E002 are not equal. E106|0|01/09/1993|The values E003 and E002 are not equal. E108|0|02/30/1995|The values R001 and E001 are not equal.... (0 Replies)
Discussion started by: charandevu
0 Replies

6. UNIX for Dummies Questions & Answers

How can i make this bold

Folks; I'm writing this as a part of a script: echo "col1 hdg|col2hdg|col3hdg|" How can i make these fields shows in Bold text? (10 Replies)
Discussion started by: moe2266
10 Replies

7. Programming

Bold text

hello, how do i display the text in the printf statement in bold. or is there anyway to display the text on the console in bold thx in advance svh (3 Replies)
Discussion started by: svh
3 Replies

8. UNIX for Dummies Questions & Answers

Printing in Bold

Hi, How do I print some shell variable in BOLD/ Thanks for any suggestions, Preeti (10 Replies)
Discussion started by: preetikate
10 Replies

9. Shell Programming and Scripting

Bold the paragraph

Hi, I have a file with multiple paragraph. I want to look for some word and make that paragraph bold. How can I do that? Thanks, Karthik (3 Replies)
Discussion started by: caprikar
3 Replies

10. UNIX for Dummies Questions & Answers

Bold Text?

Hello, On the linux box I use at work, the directories are bold type to distinguish them. Is there a way to make certain words in a text file bold? Thanks! (4 Replies)
Discussion started by: Atama
4 Replies
Login or Register to Ask a Question