The Inquirer-Home

Firefox plugin checks SSL certificates

Queries multiple notary servers
Wed Sep 03 2008, 10:43

INSECURITY RESEARCHERS at at Carnegie Mellon University have developed a new SSL (Secure Sockets Layer) verification plugin for Mozilla Firefox 3.

Perspectives is designed to query at least four notary servers to obtain the status of a questionable certificate via current and archived domain keys.

The plugin will automatically override the Firefox 3 security error page if the certificate is deemed legitimate. However, if the veracity of the site cannot be confirmed, Perspectives will add a red bar to the Firefox warning page that reads: " Suspected attack: Perspectives was unable to verify the security of your connection to this website”.

It should be noted that Firefox 3 is set to block surfers from accessing sites with self-signed certificates and may also prevent visits to pages with expired third-party validations. However, users are permitted to click through four dialog boxes and add the unrecognized SSL certificate as an "exception”.

According to Firefox developer Jonathan Nightingale, self-signed certificates are not inherently evil, but are “implicitly untrusted -- [as] no one has vouched for them”. µ

Share this:

Comments
school!

I have to punch around Firefox for University of Texas site. They appear to have a self-signed certificate.

posted by : Markus, 03 September 2008 Complain about this comment
Already reported!

Once again, the INQ publishes an already boring story twice!

http://www.theinquirer.net/gb/inquirer/news/2008/08/28/firefox-gets-better-site-id

posted by : Louis, 03 September 2008 Complain about this comment
Better than nothing!

Surely self-signed certificates are better than no encryption at all..
Problem with all this malarkey is it makes self-certs seem WORSE, which is clearly wrong.

posted by : Jim, 03 September 2008 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Authorities in several countries raided Megaupload recently, shut down all of its services, seized hundreds of servers and arrested several of its executives on criminal charges.

Do you think the move was justified?