Live data from Hacker News

Why HTTPS Everywhere isn't on addons.mozilla.org

lists.eff.org

51–60 of 61 posts

Re: Why HTTPS Everywhere isn't on addons.mozilla.org

#51
post #7

Earlier quoted context omitted.

Perhaps I misunderstand you but since it's HTTPS, in theory there are no MITM attacks.

Its possible to MITM an HTTPS connection, trick you into thinking it is secure by providing a green lock favicon, and intercepting or sniffing everything you do over that connection. And it will work on nearly every website in existance. More people should be aware of SSL Strip and how to protect yourself against it. http://www.thoughtcrime.org/software/sslstrip/

> Its possible to MITM an HTTPS connection

Not in the case of Firefox connecting to AMO, because it uses a pinned certificate for that.

Re: Why HTTPS Everywhere isn't on addons.mozilla.org

#52
post #10
post #7

Earlier quoted context omitted.

Perhaps I misunderstand you but since it's HTTPS, in theory there are no MITM attacks.

Unless, as the article points out, the attacker has your private SSL key (perhaps leaked via Heartbleed). Without cert pinning here's also the problem of the attacker convincing some browser-trusted CA to issue an SSL cert for addons.mozilla.org, then MITMing you with that. (And with 600+ trusted roots, many of which are owned by various governments, against state level attackers an ssl connection's claim of authenti…

> Without cert pinning

In the case of Firefox connecting to addons.mozilla.org, there is cert pinning.

Re: Why HTTPS Everywhere isn't on addons.mozilla.org

#53

and yet: https://addons.mozilla.org/en-US/firefox/addon/privacy-badge... Given the inconsistency of EFF and Mozilla's "policy" on this issue, plausible context to what's written might include something like an inability to upstream HTTPSEverywhere into Firefox by default due to political pushback from large advertising sponsors of Mozilla. EFF certainly resolved these issues for PrivacyBadger, which nevertheless has…

...working with Mozilla to make AMO more secure for everyone by default seems like a pretty straightforward and desirable option for EFF. it's unclear why that hasn't happened here. The bug report [1] was closed as WONTFIX. Essentially, AMO is more worried about malicious updates by extension authors than hijacking of legitimate extensions: The "hijacking" we worry about is from the addon authors themselves: we revie…

to me, WONTFIX is just a signal that personal conversations with Mozilla devs as humans--or at least a more subtle understanding of why Mozilla's not budging--are that much more important as next steps.

and i don't necessarily disagree with the technical merits of EFF's position, either. but what does it say about EFF if they don't feel the same way about PrivacyBadger being available through AMO? seems inconsistent, if we're to take the given rationale at face value.

and more broadly, it seems clear that if EFF's goal is to maximize the number of people using HTTPSEverywhere, the status quo for providing access to their code is not optimal.

i hope Mozilla/EFF will be able to work out a solution that increases the availability of HTTPSEverywhere's functionality.

Re: Why HTTPS Everywhere isn't on addons.mozilla.org

#54
post #18

"main reason I haven't put it in AMO yet is because AMO offers less security to users than EFF self-hosting it" Another pointless crusade. Aren't there many ways you could make it safer still? Wouldn't some of those be really dumb because they would prevent many people from accessing the add on? How many people are you making more secure? Close to no one because 98% of Firefox https everywhere users have some other a…

Those 99% of addons are not about adding strong security and good practices to your browser hence do not bear the same expectations.

I would be disappointed if a security add on could easily be circumvented because of a poor choice of distribution.

Keep in mind that such security addons may be used by activists and journalists in hostile environments, you do have a different opinion when overlooking this kind of details could mean imprisonment and torture.

Re: Why HTTPS Everywhere isn't on addons.mozilla.org

#55
post #10

Earlier quoted context omitted.

Unless, as the article points out, the attacker has your private SSL key (perhaps leaked via Heartbleed). Without cert pinning here's also the problem of the attacker convincing some browser-trusted CA to issue an SSL cert for addons.mozilla.org, then MITMing you with that. (And with 600+ trusted roots, many of which are owned by various governments, against state level attackers an ssl connection's claim of authenti…

> Without cert pinning In the case of Firefox connecting to addons.mozilla.org, there is cert pinning.

I didn't know that, thanks.

(In retrospect, it's such an obvious thing for them to do - I don't know why I didn't assume it was likely enough to be implemented and check before I posted that...)

Re: Why HTTPS Everywhere isn't on addons.mozilla.org

#56
post #21

Im all for signing stuff but: - amo wasnt affected by heartbleed - signatures arent foolproof either - HTTPS everywhere.. is supposed to advocate for TLS being safe ? So the criticism seems quite misguided in this case.

- amo wasnt affected by heartbleed If you only address issues that have already happened, you will never provide adequate protection . The point is to ensure sane behavior when AMO is affected by some exploit. - signatures arent foolproof either Yeah, and actually, why bother with HTTPS at all: it's not foolproof, is it? - HTTPS everywhere.. is supposed to advocate for TLS being safe ? No, it advocates for TLS being…

you contradicted yourself here - or voluntarily misunderstood the point.

Re: Why HTTPS Everywhere isn't on addons.mozilla.org

#57
post #55

Earlier quoted context omitted.

> Without cert pinning In the case of Firefox connecting to addons.mozilla.org, there is cert pinning.

I didn't know that, thanks. (In retrospect, it's such an obvious thing for them to do - I don't know why I didn't assume it was likely enough to be implemented and check before I posted that...)

To be fair, I _think_ the pinning was only added in Firefox 32, back in September. So it's a pretty recent development.

Re: Why HTTPS Everywhere isn't on addons.mozilla.org

#58

Earlier quoted context omitted.

Its possible to MITM an HTTPS connection, trick you into thinking it is secure by providing a green lock favicon, and intercepting or sniffing everything you do over that connection. And it will work on nearly every website in existance. More people should be aware of SSL Strip and how to protect yourself against it. http://www.thoughtcrime.org/software/sslstrip/

> Its possible to MITM an HTTPS connection Not in the case of Firefox connecting to AMO, because it uses a pinned certificate for that.

Are you sure?

I perform HTTPS interception on all out-bound traffic on my network and I don't recall making an exception for AMO, and I have a number of add-ons installed. Though, it wouldn't be the first time I've forgotten about something like that.

Re: Why HTTPS Everywhere isn't on addons.mozilla.org

#59
post #5

Earlier quoted context omitted.

I think the idea is that you don't need the extra security of signing, because if the file was served over HTTPS then you can be secure in the knowledge that it has not been modified. The reason you sign packages is to ensure that the file you want and the file you get are actually the same. If you have a secure connection to the trusted host of said file, you don't need to worry about that.

> The reason you sign packages is to ensure that the file you want and the file you get are actually the same. If you have a secure connection to the trusted host of said file, you don't need to worry about that. HTTPS provides a secure connection, in theory, but what if AMO is itself compromised? They are just a 3rd party host for the EFF's extension, after all. HTTPS or not, the only way to check that the code you…

If AMO is compromised, then a bogus hash or whatever could be published as well.

Re: Why HTTPS Everywhere isn't on addons.mozilla.org

#60
HTTPS Everywhere is security theater. Encrypting everything creates pressure to cache encrypted content, using "caching services" such as Cloudflare. If it goes through Cloudflare, it's decrypted at Cloudflare. Cloudflare is a man-in-the-middle.

HTTPS Everywhere means MITM Everywhere. It makes interception easier.

Post reply on HN