Reported by Anonymous, created 8 months ago, last edited 8 months ago.
Hi there, I think that if you change the way the certs are handled this addon will be a huge sucess. I believe that the expected way to handle SSL certs are:
If it's a new cert, on a never previously visited page; Accept it blindly even though it's invalid. - If it's a new cert on a previously visited page then scare the hell out of the user, HIGH change of MitM.
There's this topic on Slashdot that have this discussion on how changing the way certs are handled would improve the web security.
Reported by Anonymous, created 8 months ago, last edited 8 months ago.
Hi there, I think that if you change the way the certs are handled this addon will be a huge sucess. I believe that the expected way to handle SSL certs are:
There's this topic on Slashdot that have this discussion on how changing the way certs are handled would improve the web security.
http://tech.slashdot.org/story/10/06/28/2340237/22-Million-SSL-Certificates-In-Use-Are-Invalid
Hope you put this in consideration.
Best regards, Michel