HTTPS Everywhere Now Warns About Encryption Weaknesses - gHacks Tech News

HTTPS Everywhere Now Warns About Encryption Weaknesses

Two weeks ago a team of mathematicians and cryptographers have released a paper in which they describe a weakness in the encryption used by routers, firewalls, web services or virtual private network. The flaw, affecting only a small number of cases where the random prime number generation fails to work correctly.

A new HTTPS Everywhere version released today for the Firefox web browser can detect and notify users of that encryption weakness.

The Firefox add-on ships with the optional SSL Observatory component that is disabled by default. Firefox users need to open the extension's preferences and switch to the SSL Observatory tab there to configure the feature.

ssl observatory

Firefox users who want to use the feature need to first check the Use the Observatory box. Once activated, copies of the HTTPS certificate will be send to the EFF Observatory where they are analyzed for man in the middle attacks. The service checks for insecure connections or attacks and notifies the user.

The "Decentralized SSL Observatory" is an optional feature that detects encryption weaknesses and notifies users when they are visiting a website with a security vulnerability – flagging potential risk for sites that are vulnerable to eavesdropping or "man in the middle" attacks.

Firefox users with the Torbutton extension installed can route the traffic through TOR to anonymize the requests.

A click on advanced options displays two additional features. These allow you to submit and check certificates that are signed by non-standard root CAs or non-public DNS names.

The Electronic Frontier Foundation recommends to enable the feature for an extra level of protection in the browser. The Firefox extension is now available in 12 different languages.

The developers have also released a beta version of HTTPS Everywhere for the Chrome browser which can also be downloaded from the official download page on the EFF website. The Chrome version does not include weak key vulnerability notifications yet.

We need your help

Advertising revenue is falling fast across the Internet, and independently-run sites like Ghacks are hit hardest by it. The advertising model in its current form is coming to an end, and we have to find other ways to continue operating this site.

We are committed to keeping our content free and independent, which means no paywalls, no sponsored posts, no annoying ad formats or subscription fees.

If you like our content, and would like to help, please consider making a contribution:

Comments

  1. bastik said on February 28, 2012 at 8:22 pm
    Reply

    A nice new feature.

    BTW: It’s spelled Tor. Although it’s an acronym for The Onion Router (TOR), the Torproject prefers Tor.

  2. paul(us) said on February 29, 2012 at 2:41 am
    Reply

    Great update.
    Do I understand it correctly that its smart to activate under ssl observatory and than the show advanced function both options?

    1. Martin Brinkmann said on February 29, 2012 at 10:21 am
      Reply

      Well you need to understand that you are submitting data to the EFF when you enable the option. For most users, it should be enough to enable the feature.

Leave a Reply

Check the box to consent to your data being stored in line with the guidelines set out in our privacy policy

Please note that your comment may not appear immediately after you post it.