opensubscriber
   Find in this group all groups
 
Unknown more information…

m : mozilla-security@mozilla.org 20 December 2005 • 4:41AM -0500

Re: 401 user authentication window does not indicate protocol in 1.5
by Nelson B

REPLY TO AUTHOR
 
REPLY TO GROUP




Jack wrote:

>>> When I got the popup window due to 401 in 1.0.x, it used to indicate
>>> whether it was http versus https.  1.5 does not seem to indicate this
>>> as 1.0.x did. Is this intentional?

>> This is a problem because one can't tell whether redirection occured or
>> not and so one can't be sure that one is sending the user name and
>> password over a secure channel.
>>
>> Is there a settings to enable display of the protocol (http v. https) as
>> well?

I posted https://bugzilla.mozilla.org/show_bug.cgi?id=320851 about this.
If true, this seems like a significant security regression to me.

I gather the problem was being reported against linux, and reported it
against the linux version.  If some other version is involved, please
correct that bug report.

--
Nelson B
_______________________________________________
Mozilla-security mailing list
Mozilla-security@mozi...
http://mail.mozilla.org/listinfo/mozilla-security

Bookmark with:

Delicious   Digg   reddit   Facebook   StumbleUpon

Related Messages

opensubscriber is not affiliated with the authors of this message nor responsible for its content.