Author Topic: https:// is broken on forum server  (Read 12278 times)

0 Members and 1 Guest are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: https:// is broken on forum server
« Reply #15 on: October 15, 2014, 04:14:15 PM »
Supported in V10 (2015). :)
I'm tempted  :-\
Go ahead Gordon, it won't bite. ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: https:// is broken on forum server
« Reply #16 on: October 15, 2014, 06:16:40 PM »
Did not know we were so "in the flow"with actuality of the "Poodle" hole.

Last night I spread the news on the Avast forums that we expected breaking news via Brian Krebs expecting this.

Now we know that the Google testers stumbled upon this fallback gaping hole exploit in SSLv3.

Disable SSLv3 in Chrome via this Command line flag "--ssl-version-min=tls1" (without "") if you already want to do this now.

This is what Google plans for the future considering the Poodle hole:
re; https://www.imperialviolet.org/2014/10/14/poodle.html

For firefox give in about:config and look for security.tls.version.min
Change  the value for this to 1 to disable SSLv3.

Firefox will support SCSV-mechanisme from version 36 onwards..

Tor browsers are secure by desigm.

In IE go to Extra -> Internet Options -> Tab -Advanced .-> at Security untick SSL 3.0 and then tick to use TLS 1.0, TLS 1.1 en TLS 1.2
whenever this has not been enabled yet.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: https:// is broken on forum server
« Reply #17 on: October 16, 2014, 02:41:40 PM »
Just for a laugh, set "security.ssl.require_safe_negotiation;true" and maybe also "security.ssl.treat_unsafe_negotiation_as_broken;true", then go to https://www.howsmyssl.com/.

KM gives me this:
Quote
Secure Connection Failed

An error occurred during a connection to www.howsmyssl.com. Peer attempted old style (potentially vulnerable) handshake. (Error code: ssl_error_unsafe_negotiation)

The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.

    Please contact the website owners to inform them of this problem.

I did try (not very hard, you'll see) to contact them, using Opera.

Quote
Have feedback? Leave it on the howsmyssl-upkeep mailing list. Notice a bug? Create an issue on the Github repository.

Feedback is very welcome.

The mailing list is maintained by Google Groups, and I do have an account.  They want me to join a group before posting.  So GitHub...  wants me to make a new account...  Why?  I do that for things I care about, like JIRA at ReactOS.  Not to tell someone the hard way his product has a problem.  Maybe he doesn't want to know?  Even Open Hardware Monitor doesn't do this sort of rubbish, you just go there and post.

ReactOS should be ready about the time W7 dies of old age  :)

BTW, I'm using the exact same config settings on this forum.  Amazing.

Anyway,

Gordon.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33913
  • malware fighter
Re: https:// is broken on forum server
« Reply #18 on: January 13, 2015, 12:20:11 AM »
Security header configuration on https://forum-02.avast.com (and recommendations)
http://www.uploady.com/#!/download/wu2ajyxLvBV/7FpuOEXwvGoLr6nk

polonus
« Last Edit: January 13, 2015, 12:21:48 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: https:// is broken on forum server
« Reply #19 on: January 13, 2015, 01:11:11 PM »
Polonus, ahaha.
This thread is nearly 3 months old now.. ???
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48586
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: https:// is broken on forum server
« Reply #20 on: January 13, 2015, 05:00:38 PM »
Polonus, ahaha.
This thread is nearly 3 months old now.. ???
That's what happens when there's little activity on the forum and you're bored..... :) :) :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet