EFForg / https-everywhere

A browser extension that encrypts your communications with many websites that offer HTTPS but still allow unencrypted connections.
https://eff.org/https-everywhere
Other
3.37k stars 1.09k forks source link

Audit default_off="mismatched" rulesets. #13088

Closed bardiharborow closed 5 years ago

bardiharborow commented 6 years ago

Type: other

The following default_off="mismatched" rulesets pass a curl -I https://host/ scan for at least one host (full host list):

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

cschanaj commented 6 years ago

@bardiharborow Start.me.xml is not default_off in master, see #13151 for Start.me-problematic.xml

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.

bardiharborow commented 6 years ago

@cschanaj a bug in how I mapped hosts to rulesets means that any ruleset with the affected host will be picked up, regardless of if they are default_off or not, but that's probably good anyway because it catches issues like that.

cschanaj commented 6 years ago

@bardiharborow I agree that you don't have to fix this. Thank you for your explanations!!

https-everywhere-bot[bot] commented 6 years ago

Thanks! Your edit helped me out. I'll take it from here now.