<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>.:SSLFail:. &#187; Mixed Content</title>
	<atom:link href="http://www.sslfail.com/tag/mixed-content/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sslfail.com</link>
	<description>1.2.840.113549.1.1</description>
	<lastBuildDate>Sat, 24 Jul 2010 14:50:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Mixed-Content Warnings == SSLFail!</title>
		<link>http://www.sslfail.com/2009/06/mixed-content-warnings-sslfail/</link>
		<comments>http://www.sslfail.com/2009/06/mixed-content-warnings-sslfail/#comments</comments>
		<pubDate>Fri, 26 Jun 2009 03:57:29 +0000</pubDate>
		<dc:creator>Tyler</dc:creator>
				<category><![CDATA[SSLFail]]></category>
		<category><![CDATA[Mixed Content]]></category>

		<guid isPermaLink="false">http://www.sslfail.com/?p=341</guid>
		<description><![CDATA[Jay posted on this previously and we had a brief discussion surrounding it in the comments, but I wanted to bring this up again because I&#8217;m really not a fan of it, and I wanted to make sure people are paying attention. Oh yeah and discuss, discuss, discuss &#8212; let&#8217;s have some chatter  
I [...]]]></description>
			<content:encoded><![CDATA[<p>Jay <a href="http://www.sslfail.com/2009/01/mixed-content-warnings/">posted on this previously</a> and we had a brief discussion surrounding it in the comments, but I wanted to bring this up again because I&#8217;m really not a fan of it, and I wanted to make sure people are paying attention. Oh yeah and discuss, discuss, discuss &#8212; let&#8217;s have some chatter <img src='http://www.sslfail.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I always had two pet peeves about a number of the websites I frequent. First, they frequently required me to whitelist them on NoScript, which I wasn&#8217;t a fan of and second, the SSL versions of the sites often gave large Mixed-Content warnings. These warnings are annoying, distracting and honestly disruptive to the user experience. I&#8217;ll be the first to admit to that. It seems that some browsers listened to these complaints. I just recently remembered when visiting my <a href="https://www.computerdefense.org/">personal blog</a> that these warnings no longer exist when using Firefox. Sure if you look in the bottom corner there&#8217;s a little red exclamation mark over the lock but it doesn&#8217;t contain the full screen warning that a Domain Mismatch or Self Signed Cert cause.</p>
<div id="attachment_342" class="wp-caption aligncenter" style="width: 609px"><a href="http://www.sslfail.com/wp-content/uploads/2009/06/cdo_https.jpg"><img class="size-large wp-image-342" title="cdo_https" src="http://www.sslfail.com/wp-content/uploads/2009/06/cdo_https-1024x727.jpg" alt="ComputerDefense.org via HTTPS" width="599" height="425" /></a><p class="wp-caption-text">ComputerDefense.org via HTTPS</p></div>
<p>See it there, next to Fiddler: Disabled&#8230; a little time red exclamation mark. That&#8217;s all the warning you get. So what do other browsers do? Well, Chrome gives you a slightly bigger, yellow-ish exclamation mark in the address bar, yet it still allows the content to load. IE on the other hand brings up a pop-up (pictured below) prompting the user if they want to load the insecure data or not. It&#8217;s not as vocal as it could be, but it&#8217;s better than nothing.</p>
<div id="attachment_343" class="wp-caption aligncenter" style="width: 341px"><a href="http://www.sslfail.com/wp-content/uploads/2009/06/ie_secure_nonsecure.jpg"><img class="size-full wp-image-343" title="ie_secure_nonsecure" src="http://www.sslfail.com/wp-content/uploads/2009/06/ie_secure_nonsecure.jpg" alt="IE Pop-up for Mixed-Content" width="331" height="152" /></a><p class="wp-caption-text">IE Pop-up for Mixed-Content</p></div>
<p>So why am I blogging about this? After all I said they were annoying and distracting and it seems that the browser vendors are removing them. That&#8217;s a good thing&#8230; isn&#8217;t it? Nope, definitely not a good thing.</p>
<p>Let&#8217;s think about some of the pages that throw large, screaming, in-your-face type errors. Let&#8217;s take two examples, Self Signed Cert and Domain Mismatch. Now remember that the aim of SSL is two-fold. One is to provide verification of the source of the data, the other is to provide encryption.</p>
<p>Does a Self-Signed Cert provide encryption? Yes.<br />
Does a Certificate with a Domain Mismatch provide encryption? Yes.<br />
Does a site with Mixed-Content provide encryption? Partially.</p>
<p>Does a Self Signed Cert provide site verification? No.<br />
Does a Certificate with a Domain Mismatch provide site verification? No.<br />
Does a site with Mixed-Content provide site verification? Partially.</p>
<p>So Yes + No = In-Your-Face Error<br />
Yet, Partially + Partially = Tiny Little Error in the Corner</p>
<p>I would say that Mixed-Content is more dangerous than both a Self-Signed Cert and a Domain Mismatch, yet they&#8217;ve been treated as more serious issues. I&#8217;m don&#8217;t understand that logic, and I&#8217;m not sure that I ever will.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sslfail.com/2009/06/mixed-content-warnings-sslfail/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Blogger mixed content</title>
		<link>http://www.sslfail.com/2009/01/blogger-mixed-content/</link>
		<comments>http://www.sslfail.com/2009/01/blogger-mixed-content/#comments</comments>
		<pubDate>Tue, 27 Jan 2009 22:46:57 +0000</pubDate>
		<dc:creator>romain</dc:creator>
				<category><![CDATA[SSLFail]]></category>
		<category><![CDATA[Mixed Content]]></category>

		<guid isPermaLink="false">http://www.sslfail.com/?p=229</guid>
		<description><![CDATA[
]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.sslfail.com/wp-content/uploads/2009/01/blogger1.jpg" alt="blogger1" title="blogger1" width="600" class="aligncenter size-full wp-image-231" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sslfail.com/2009/01/blogger-mixed-content/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mixed Content Warnings</title>
		<link>http://www.sslfail.com/2009/01/mixed-content-warnings/</link>
		<comments>http://www.sslfail.com/2009/01/mixed-content-warnings/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 03:01:08 +0000</pubDate>
		<dc:creator>jgraver</dc:creator>
				<category><![CDATA[SSLFail]]></category>
		<category><![CDATA[Mixed Content]]></category>

		<guid isPermaLink="false">http://www.sslfail.com/?p=205</guid>
		<description><![CDATA[We are off the domain mismatch SSL Errors right now so I thought I would highlight another one that I find pretty often &#8211; Mixed Content Errors.
My (current) browser of choice Chrome defines Mixed Content Errors as;
&#8220;Your connection to www.website.com is encrypted with 128-bit encryption. However this page includes other resources which are not secure. [...]]]></description>
			<content:encoded><![CDATA[<p>We are off the domain mismatch SSL Errors right now so I thought I would highlight another one that I find pretty often &#8211; Mixed Content Errors.</p>
<p>My (current) browser of choice Chrome defines Mixed Content Errors as;</p>
<blockquote><p>&#8220;Your connection to www.website.com is encrypted with 128-bit encryption. <strong>However this page includes other resources which are not secure.</strong> These resources can be viewed by others in transit, and can be modified by an attacker to change the look or behavior of the page.&#8221;</p></blockquote>
<p>Oh Noes!</p>
<p>Royalbank serving up mixed content</p>
<p><a href="http://www.sslfail.com/wp-content/uploads/2009/01/mc_rb1.jpg"><img class="alignnone size-full wp-image-206" title="mc_rb1" src="http://www.sslfail.com/wp-content/uploads/2009/01/mc_rb1.jpg" alt="mc_rb1" width="600" height="409" /></a></p>
<p>Here is HSBC doing so on its homepage</p>
<p><a href="http://www.sslfail.com/wp-content/uploads/2009/01/mc_hs1.jpg"><img class="alignnone size-full wp-image-207" title="mc_hs1" src="http://www.sslfail.com/wp-content/uploads/2009/01/mc_hs1.jpg" alt="mc_hs1" width="599" height="356" /></a></p>
<p><span id="more-205"></span></p>
<p>Here are two Foriegn Canadian Fails</p>
<p><a href="http://www.sslfail.com/wp-content/uploads/2009/01/mc_nb2.jpg"><img class="alignnone size-full wp-image-208" title="mc_nb2" src="http://www.sslfail.com/wp-content/uploads/2009/01/mc_nb2.jpg" alt="mc_nb2" width="598" height="446" /></a></p>
<p><a href="http://www.sslfail.com/wp-content/uploads/2009/01/mc_ic1.jpg"><img class="alignnone size-full wp-image-209" title="mc_ic1" src="http://www.sslfail.com/wp-content/uploads/2009/01/mc_ic1.jpg" alt="mc_ic1" width="600" height="273" /></a></p>
<p>And I think this one was my favorite because I found it on National Bank&#8217;s Confidentiality Policy page.</p>
<p><a href="http://www.sslfail.com/wp-content/uploads/2009/01/mc_nb1.jpg"><img class="alignnone size-full wp-image-210" title="mc_nb1" src="http://www.sslfail.com/wp-content/uploads/2009/01/mc_nb1.jpg" alt="mc_nb1" width="601" height="388" /></a></p>
<p>I want to start a discussion about the dangers of Mixed Content in SSL Sessions.</p>
<ul>
<li>Are these things serious?</li>
<li>Did my lock icon pop open to alert me of an attack?</li>
<li>What part of this session IS encrypted and what part ISN&#8217;T?</li>
<li>Where are my cookies going?</li>
<li>What is the most malicious thing you can think of injecting into a Mixed Content SSL Session?</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.sslfail.com/2009/01/mixed-content-warnings/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
