midori-browser / core

Midori Web Browser - a lightweight, fast and free web browser using WebKit and GTK+
https://www.midori-browser.org/
GNU Lesser General Public License v2.1
400 stars 67 forks source link

Midori for Windows does not Verify SSL Certificates #433

Open nazgulsenpai opened 3 years ago

nazgulsenpai commented 3 years ago

When accessing a personal webserver's HTTPS with a self-signed certificate, Midori doesn't show any error or warning that the Certificate is not signed by a trusted certificate authority.

The same website on the Linux build (7.0-2 from MX Linux repo) shows the expected warning.

The Windows version of Midori was installed using the Web Installer link from the official website. The properties of Midori.exe list the file version as 1.1.4.0.

I also tested by changing the hosts file to point google.com to hulu.com's IP address. Midori for Windows did not show a warning and opened Hulu.

In my opinion, this is a critical security risk.

Untitled

freedomFu commented 3 years ago

Hello, I'm sorry to disturb you ( sorry again for that English is not my mother language), but I have found that on my Mac OSX there is a scene like windows. I want to ask you where did you download the application, I hava read the issue in here , but it doesn't help, what I see is that the midori still doesn't verify my self-signed certificate on windows. And as you say, it's different from the things in Linux, so where have you put the certificate file on the system?