<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Mixed Content Warnings</title>
	<atom:link href="http://www.sslfail.com/2009/01/mixed-content-warnings/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sslfail.com/2009/01/mixed-content-warnings/</link>
	<description>1.2.840.113549.1.1</description>
	<lastBuildDate>Thu, 01 Jul 2010 03:13:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: .:SSLFail:. &#187; Blog Archive &#187; Mixed-Content Warnings == SSLFail!</title>
		<link>http://www.sslfail.com/2009/01/mixed-content-warnings/comment-page-1/#comment-2642</link>
		<dc:creator>.:SSLFail:. &#187; Blog Archive &#187; Mixed-Content Warnings == SSLFail!</dc:creator>
		<pubDate>Fri, 26 Jun 2009 03:57:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=205#comment-2642</guid>
		<description>[...] Warnings == SSLFail!   Posted by Tyler on June 25, 2009  SSLFail  Jay posted on this previously and we had a brief discussion surrounding it in the comments, but I wanted to bring this up again [...]</description>
		<content:encoded><![CDATA[<p>[...] Warnings == SSLFail!   Posted by Tyler on June 25, 2009  SSLFail  Jay posted on this previously and we had a brief discussion surrounding it in the comments, but I wanted to bring this up again [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Coates</title>
		<link>http://www.sslfail.com/2009/01/mixed-content-warnings/comment-page-1/#comment-24</link>
		<dc:creator>Michael Coates</dc:creator>
		<pubDate>Sat, 24 Jan 2009 15:43:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=205#comment-24</guid>
		<description>Another item to add is that there is a good chance one of those unencrypted requests could be going to the same domain and thus carrying the sessionID across in the clear.  If so, game over, your session is compromised.

re: firefox, you can turn on the mixed content warning. But it&#039;s just a warning with an ok box. There&#039;s no way to say you want to stop going forward.

-Michael</description>
		<content:encoded><![CDATA[<p>Another item to add is that there is a good chance one of those unencrypted requests could be going to the same domain and thus carrying the sessionID across in the clear.  If so, game over, your session is compromised.</p>
<p>re: firefox, you can turn on the mixed content warning. But it&#8217;s just a warning with an ok box. There&#8217;s no way to say you want to stop going forward.</p>
<p>-Michael</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Dickey</title>
		<link>http://www.sslfail.com/2009/01/mixed-content-warnings/comment-page-1/#comment-19</link>
		<dc:creator>Michael Dickey</dc:creator>
		<pubDate>Mon, 19 Jan 2009 21:25:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=205#comment-19</guid>
		<description>1. Are these things serious? Certainly they could be, for two reasons. First, if the site actually is secure and the only non-secure things are stupid things that don&#039;t matter, then we&#039;re hurting the user trust/experience. Second, it could mean the important stuff isn&#039;t even secure! O_o

2. What part of this session IS encrypted and what part ISN’T? Sadly, no one really can answer this in any practical way. We could examine the code and/or traffic and see what is being pulled down in SSL or not, but that chances of most people doing that are nil.


3. What is the most malicious thing you can think of injecting into a Mixed Content SSL Session?

I suppose I could inject goatse images! I could maybe even inject a twiddled form that submits to my server (over https because we gotta be secure!) rather than the real server. Not sure what alerts that may cause, but is interesting to think about. I could probably also inject javascript somewhere in there and do whatever I want, really.


@Tyler: Verification of identity...and god only knows how well the CAs are doing at even that part! 

I love your observation there, and it&#039;s a great point! A site is encrypted but with a non-EV SSL cert (or self-signed cert), and we get stopped cold. But partial encryption?

I wonder when the day will come where we don&#039;t have unencrypted and encrypted traffic, but rather it is encrypted from the start? I suppose it can&#039;t happen on the web, but maybe the thing that replaces the web in 20 years? Then again, maybe that is asking too much from the onset of some new technology/protocol...</description>
		<content:encoded><![CDATA[<p>1. Are these things serious? Certainly they could be, for two reasons. First, if the site actually is secure and the only non-secure things are stupid things that don&#8217;t matter, then we&#8217;re hurting the user trust/experience. Second, it could mean the important stuff isn&#8217;t even secure! O_o</p>
<p>2. What part of this session IS encrypted and what part ISN’T? Sadly, no one really can answer this in any practical way. We could examine the code and/or traffic and see what is being pulled down in SSL or not, but that chances of most people doing that are nil.</p>
<p>3. What is the most malicious thing you can think of injecting into a Mixed Content SSL Session?</p>
<p>I suppose I could inject goatse images! I could maybe even inject a twiddled form that submits to my server (over https because we gotta be secure!) rather than the real server. Not sure what alerts that may cause, but is interesting to think about. I could probably also inject javascript somewhere in there and do whatever I want, really.</p>
<p>@Tyler: Verification of identity&#8230;and god only knows how well the CAs are doing at even that part! </p>
<p>I love your observation there, and it&#8217;s a great point! A site is encrypted but with a non-EV SSL cert (or self-signed cert), and we get stopped cold. But partial encryption?</p>
<p>I wonder when the day will come where we don&#8217;t have unencrypted and encrypted traffic, but rather it is encrypted from the start? I suppose it can&#8217;t happen on the web, but maybe the thing that replaces the web in 20 years? Then again, maybe that is asking too much from the onset of some new technology/protocol&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jgraver</title>
		<link>http://www.sslfail.com/2009/01/mixed-content-warnings/comment-page-1/#comment-18</link>
		<dc:creator>jgraver</dc:creator>
		<pubDate>Mon, 19 Jan 2009 15:09:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=205#comment-18</guid>
		<description>Firefox 3 does a horrible job of informing the user about Mixed Content. Firefox 2 had a far superior SSL user experience in every way.</description>
		<content:encoded><![CDATA[<p>Firefox 3 does a horrible job of informing the user about Mixed Content. Firefox 2 had a far superior SSL user experience in every way.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tyler</title>
		<link>http://www.sslfail.com/2009/01/mixed-content-warnings/comment-page-1/#comment-17</link>
		<dc:creator>Tyler</dc:creator>
		<pubDate>Mon, 19 Jan 2009 07:37:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=205#comment-17</guid>
		<description>I&#039;ll start off the discussion here... 

Firefox gives almost no warning for mixed-content pages. My lock has a little &#039;!&#039; on it in the bottom corner of my screen. It provides more of a warning when a cert is self-signed than it does for a page that has mixed content. 

That to me is a problem... but also a statement of the direction we&#039;re going. This issue speaks to me in a couple of ways. 

1) SSL is all about verification of identity, not encryption. Given that a fully encrypted site with a self signed cert gets a full warning, and a partially encrypted site with mixed content gets no warning, I think that&#039;s a fair assumption to make. 

2) Trust is fully and wholly placed in the owner of the site. If we trust the owner, then we can trust anyone associated with the site. 

Both of these worry me a great deal. This is a gross injustice to the user, or maybe it&#039;s what the user wants. This has actually given me an idea... more to come in the future. 

Anyways, I like the discussion idea, so let&#039;s have more discussion!</description>
		<content:encoded><![CDATA[<p>I&#8217;ll start off the discussion here&#8230; </p>
<p>Firefox gives almost no warning for mixed-content pages. My lock has a little &#8216;!&#8217; on it in the bottom corner of my screen. It provides more of a warning when a cert is self-signed than it does for a page that has mixed content. </p>
<p>That to me is a problem&#8230; but also a statement of the direction we&#8217;re going. This issue speaks to me in a couple of ways. </p>
<p>1) SSL is all about verification of identity, not encryption. Given that a fully encrypted site with a self signed cert gets a full warning, and a partially encrypted site with mixed content gets no warning, I think that&#8217;s a fair assumption to make. </p>
<p>2) Trust is fully and wholly placed in the owner of the site. If we trust the owner, then we can trust anyone associated with the site. </p>
<p>Both of these worry me a great deal. This is a gross injustice to the user, or maybe it&#8217;s what the user wants. This has actually given me an idea&#8230; more to come in the future. </p>
<p>Anyways, I like the discussion idea, so let&#8217;s have more discussion!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
