WHIR | BLOGS | WEB HOST NEWS | FIND WEB HOSTS | RESELLER HOSTING | MAGAZINE | WHIR TV | NEWSLETTER | rss feeds
web hosting news - daily web host interviews, insight Jobs | Events | Sitemap | Search
Green Data Center Info


WEB HOSTING NEWS | BLOGS | INTERVIEWS | EUROPE | EVENTS | WEB HOSTING JOBS

<< Momentum Buys BroadSpire Division     IBM to Build 13 DR Centers >>


Firefox 3 Rejects Self-Signed SSLs

By David Hamilton, theWHIR.com

August 20, 2008 -- (WEB HOST INDUSTRY REVIEW) -- While expired and self-signed SSL certificates may have warranted yellow flags in Firefox 2 and Internet Explorer, the latest Firefox will scare away users from SSL-carrying sites unless they are certified by a third party, causing controversy as users are blocked from popular sites like Google and LinkedIn.
 

   
DataPipe’s high-value managed global IT services help thousands of businesses decrease CAPEX, OPEX, & risk while increasing overall service levels. Partner with DataPipe – Improve your ROI - Extend your IT resources

Reported by BetaNews (betanews.com) and other sources, Modzilla began cracking down on SSCs, which are valid, albeit unauthenticated, SSL certificates used for online encryption and website authentication to guard against phishing attacks, giving users frightening warnings, saying the certificate is "invalid" and "not trusted."
 
Mozilla began implementing a stricter policy because self-signed certificates can potentially be malicious because there is no third party to verify the site's identity, according analysis from Royal Pingdom, the official blog of uptime monitoring provider Pingdom(pingdom.com). However, they note that most users will be turned off from websites that do not carry an expensive third-party certificate from such Certification Authorities as VeriSign (verisign.com).

"From a security standpoint, the change in Firefox 3 kind of makes sense, but from a usability standpoint, the implementation is too confusing," according to Royal Pingdom.

While site administrators can pay a one-time fee of $29.99 from a company like Go Daddy (godaddy.com) for a basic SSL package, for some it is a matter of principle.

According to Scott M. Fulton's report on BetaNews, some developers self-sign because they do not want to register for security reasons with a third party when working on a covert project. Other developers find it simply more convenient and economical to self-sign certificates, especially when they have many certificates to issue.
 
Univeristy of Massachusetts's Nat Tuck opposes Mozilla's de facto censorship because he said it infringes on net neutrality, the concept that the internet should be free of restrictions on content, sites or platforms.
 
"This behavior means that a public web site basically can't be encrypted unless they are willing to pay an approved vendor a yearly fee for a certificate," Tuck wrote in a recent blog posting. "This has two effects: First, some sites are forced to pay for certificates that they otherwise wouldn't have bought. Second, some sites are forced to go without encryption that they otherwise would have had.
 
"This is really an issue of the basic principles of internet openness. Everyone has equal access to the features of HTTP or SSH, there's no reason why there should be artificial constraints on access to HTTPS. But that's exactly what the Firefox SSL behavior does."
 
Fulton noted an alternative to SSLs for budget-conscious developers is StartCom Certification Authority's free Class 1 digital certificates (startssl.com).

Print this Page       Email this Page        Add to: | del.icio.us | digg


COMMENTS

Be the first one to comment on this article. Click the link below to post your comment.

[POST COMMENT]



Q&A: Jim Lewandowski, Rackspace

Q&A: Clint Poole, Brinkster

New Features in Parallels Plesk 9

Q&A: James Bond, Apptix

Noise Filter: McColo Taken Down

Wowza Offers Friction Free Flash

Sun Battles for Greenest Data Center

More feature interviews and reports
 

What's the Deal with Cyber Monday?

Go Daddy Ads in the Grey Cup

Video Interview with Vinay Nagpal, Tata Communications

Copywriting for Direct Mail - Part 2: Big Guns

What Exactly is Semi-Dedicated Hosting?

Own your own jet

More posts from our Bloggers


Horizon Leases DRT's Dallas Facility

RackForce Adds VM Manager

Verio Names Service Delivery SVP

The Planet Offers Unmetered Bandwidth

LINX Connects 300th Member

Dell Unveils Green Reno Services

HP Trims IT Infrastructure, Saves $1B

Logicworks Among Best NY Workplaces

Websense to Host Partner Conference

NameCheap Launches Twitter Promo

CBS Web Site Faces Malware Hack

VineyardHosting Limits Eternal Hosting


 

Marketing/Sales Trainer

Sales Operator

Management Trainer

Senior Account Manager, Dedicated Hosting

Sales Executive

Senior Accounting Analyst

Technical Solutions Engineer

Product Manager

Account Manager

Ajax Experienced Developer

 

SPONSORED LINKS
> Apollo Hosting: Award Winning Website Hosting from $6.96 – Click Here!

> iWeb: Quality servers. 3000GB of traffic for only $69

> TopLayer: SC Mag Recommended. Protect against DDoS Attacks & more.

> Parallels: Automation and Virtualization. Buy ONLINE or Learn MORE!

> Rackspace: What Do You Get With Your Hosting Provider?

> Verio: Get Email Anywhere w/ Hosted Exchange $11.95/mo, 2 Mo Free

> IronScale: Why Rack? Automate with IronScale Managed Hosting

> Learn more about the greening of the data center here.

> Is your company hiring? Post your job listing here!

> Get your company listed in our annual Buyer's Guide magazine issue - Deadline: Dec 31

WHIR NEWSLETTER SIGN-UP | MANAGE SUBSCRIPTIONS | WHIR RSS FEEDS
Name:
Email:
Password:
theWHIR Blog Email Update
Magazine
Daily News
Find Web Hosts
Occupation:
Company Type:

Find Web Hosts | Reseller Hosting | Personal Web Hosting | Small Business Web Hosting | Dedicated Servers | Managed Hosting | Adult Web Hosting


About WHIR | Online Advertising | Print Advertising | Print Subscription | Email Newsletters | RSS Feeds
 
Submit News | Privacy Policy | Buy Reprints

Web Host Industry Review, Inc. is not responsible for the content of comments submitted by our users.

  © Copyright Web Host Industry Review, Inc.