Ticket #147 (closed defect: fixed)
Do Not Show Ressurect Pages 2.0.1 on SSL- and Security-Error-Pages
| Reported by: | freibooter | Owned by: | t-bone |
|---|---|---|---|
| Priority: | major | Component: | Resurrect |
| Version: | 2.0.1 | Severity: | Unknown |
| Keywords: | ssl, security, resurrect, | Cc: | freibooter@… |
Description (last modified by t-bone) (diff)
First off: I really like the visual makeover and massive usability improvements of Resurrect Pages 2.0.1. But while Firefox 3.0 introduces quite a few security enhancements and more security-related error messages, Resurrect Pages 2.0.1 blindly injects itself into all of those. This might not only be considered a security issue, it doesn't make any sense from a usability-related point of view either.
Examples:
- ssl_error_bad_cert_domain error (wrong domain)
- sec_error_ca_cert_invalid error (self-singed certificate)
Security concern:
- None of these pages are actually off-line, Firefox prevents access for good reasons, Resurrect Pages should not offer a possible way around this. This could possible used for man-in-the-middle attacks.
Usability concerns:
- None of these pages are actually off-line - no reason to show Resurrection-Menu.
- Resurrection is not an option anyways: No mirror-service in Resurrect Pages actually caches any SSL-encrypted pages, choosing a mirror service in the menu is a waste of time at best.
- The "Resurrection-Menu" is much more prominent than the only actually working option to gain access to the page ("Add an exception ..." or the link to the correct domain).
Resurrect Pages should be much more selective into which error pages it injects itself and generally leave SSL and security-related errors alone.
Attachments
Change History
Note: See
TracTickets for help on using
tickets.