ssleuth
ssleuth copied to clipboard
A firefox add-on to rate the quality of HTTPS connections
The current plan is that Firefox 57 will only support [web extensions](https://wiki.mozilla.org/WebExtensions). Your add-on is not a web extension yet as far as I can see, so you should consider...
Maybe you can consider using [Liberapay](https://liberapay.com/) to collect donations? It is clearly a better alternative for free software than PayPal or so, and it is not just a one-time donation.
When this extension may finally be moved to WebExtensions, it'd also be nice to show certificate transparency information, if possible.
Not a bug, just a feature request/suggestion: The area where the numeric score is displayed (to the left of protocol) would be more legible to more people if you dispensed...
It would be nice if the used elliptic curves could be displayed. More information: - https://security.stackexchange.com/questions/31772/what-elliptic-curves-are-supported-by-browsers - https://en.wikipedia.org/wiki/Comparison_of_TLS_implementations#Supported_elliptic_curves
If the option "Show GMT/UTC time in validity" is activated, the time is directly concatenated to the date making it hard to read: data:image/s3,"s3://crabby-images/e659a/e659afdcae0212d644ac36642f34a0faaedffd6b" alt="original" I've patched the output to add...
It would be good to also check whether the server is using [HTTP Strict Transport Security](https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security) and [HTTP Public Key Pinning](HTTP Public Key Pinning).
Today I noticed that there are some Bugs when TLS 1.3 is used, specially the Ciphersuit and hence the score is wrong. (Possible because with the latest(?) Draft of TLS...
AES GCM is authenticated encryption and should therefore be considered more secure than AES CBC. See: - [Why is CBC with predictable IV considered insecure against CPA](https://crypto.stackexchange.com/questions/3883/why-is-cbc-with-predictable-iv-considered-insecure-against-cpa)
Excellent add-on, found one problem, this one cipher suite is scored 9.0 on some sites (example weakdh.org) and 10.0 on others (example usaa.com.) Is there a difference I'm not seeing?...