4 ms·
As far as I know almost all browser security warnings are overridable. The only one that comes to mind that does not have a click-through option is when a HSTS-
by kkl 10y ago
As far as I know almost all browser security warnings are overridable. The only one that comes to mind that does not have a click-through option is when a HSTS-enabled site fails a validation check.
- r1ch 10y agoThis one in particular feels very strange, since there's actually nothing bad actively happening with the connection, it's more of a policy decision.
- coldpie 10y agoMy understanding is that you can't know that nothing bad is actively happening with the connection since SHA-1 is no longer a strong hash, so it's basically (hand-wave) no different from an HTTP connection.
- bandrami 10y agoSo why don't they present any warning on HTTP connections? It's not "basically no different" from an HTTP connection, it's strictly better than an HTTP connection, but not as good as a cert made with a more modern hash. (For that matter the same argument applies to self-signed certificates: you're still keeping a third party from snooping on the phishing attempt the MITM is giving you, which is itself a Good Thing.)
- coldpie 10y agoI agree, insecure HTTPS should be treated like HTTP. But this issue has been argued to death, especially over self-signed certs, and our side lost.
- kevincox 10y agoAll major browsers are moving towards this. Starting with the tiny icons changing colors they are beginning to make HTTP as insecure. Yes, it's very slow but at least they have started moving.
- MrRadar 10y agoIf you have explicitly dis-trusted a certificate you can't click-through either.
- rocqua 10y agoI think HPKP might also suffer the same issue.
- kkl 10y agoIt depends on who you ask, but I personally don't think hard certificate validation failures are a bad thing.
- rocqua 10y agoHKPK has the potential problem that losing / compromising 2 keys leaves your site unavailable until the pin expires.
- kkl 10y agoThis is a common theme in this thread but I'll re-state it here: Web browsers cannot reliably distinguish between a configuration mistake and an attack. For this reason, I think hard HPKP fails are a good thing. For those who opt-in to HPKP, this is a risk one takes in exchange for greater control over certificate validation.
- amiraliakbari 10y agoQuite a few are only overridable in about:config, like: (if I recall correctly) * DH short exchange keys * NTLM1 passwords
- smoyer 10y agoI just went digging through the about:config options and couldn't find a way to force SHA-1 off. Why are they gradually rolling this out to beta users if they've purposely downloaded the Developer Edition?
- sbierwagen 10y agoThere's a couple fatal errors, ERR_CERT_CONTAINS_ERRORS, ERR_CERT_REVOKED, ERR_CERT_INVALID, ERR_CERT_NOT_IN_DNS: https://github.com/adobe/chromium/blob/cfe5bf0b51b1f6b9fe239c2a3c2f2364da9967d7/content/browser/ssl/ssl_policy.cc#L78 https://github.com/adobe/chromium/blob/cfe5bf0b51b1f6b9fe239... Not sure which one of these catches HSTS failures.