Author Topic: New Google Chrome extension warns about insecure SSL sites!  (Read 2526 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: New Google Chrome extension warns about insecure SSL sites!
« Reply #1 on: January 29, 2015, 02:00:42 PM »
An example you would not suspect that would be there for a website security scan site:
When I check Quttera dot com with Tracker SSL extension I get a 66% insecure status:
Unique IDs about your web browsing habits have been insecurely sent to third parties.

dqaaapgaaaaqzpufrq512382ant9ovai-7bjjvvji6yi - can be (ab)used as Surveillance Beacon for NSA
Quttera should fix this insecurity.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: New Google Chrome extension warns about insecure SSL sites!
« Reply #2 on: January 30, 2015, 12:21:30 AM »
This extension is mainly meant to inspire websites to change from http to https.
What about this site: https://www.hotjar.com/ 
Tracker SSL gives it the all green
At least 1 third parties know you are on this webpage.
fonts.googleapis.com
Not quite so, there are more sites that are informed with all you do at https://www.hotjar.com/
as SpyWatch lists these as:
Quote
The following sites know that you visited this page. Click on a site to find out what more it knows about you.
cloudflare.com
optimizely.com
Trackers detected on this page Details:
Facebook Tracker (As provided by Bitdefender TrafficLight)
Ghostly finds most:
5 trackers detected:
www.hotjar.com
AdRoll
Advertisements, Behavior Tracking
Facebook Connect
Widgets, Social
Google Analytics
Analytics, Analytics
New Relic
Analytics, Analytics
Optimizely

The SSL site's security header situation: https://www.uploady.com/#!/download/wcWdMfSgY8I/h6iLSJJfDcmW_lPS

Warnings: http://www.dnsinspect.com/hotjar.com/1422573367

So use the extension with also an eye for the restrictions thereof
and realizing no single extension may cover all trackers on a particular https and or http-website.


polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: New Google Chrome extension warns about insecure SSL sites!
« Reply #3 on: January 30, 2015, 01:10:42 AM »
RequestPolicy add-on would probably put a crimp in most of them, since they would be trying to access the 3rd party site.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security