[Bugs] #4895 Browse UNSP: Browse does not warn of expired certs

Sugar Labs Bugs bugtracker-noreply at sugarlabs.org
Thu Oct 8 18:49:25 EDT 2015


#4895: Browse does not warn of expired certs
---------------------------------------------+--------------------------
       Reporter:  SAMdroid                   |       Owner:
           Type:  defect                     |      Status:  new
       Priority:  Unspecified by Maintainer  |   Milestone:  Unspecified
      Component:  Browse                     |     Version:  Unspecified
       Severity:  Critical                   |    Keywords:
Distribution/OS:  Fedora                     |  Bug Status:  Unconfirmed
---------------------------------------------+--------------------------
 How to reproduce:

 1.  Go to site with expired cert (eg. https://dev.laptop.org/)

 Result:

 *  Padlock in urlbar has an ! next to it

 Expected result:

 *  Users are warned of the dangers and scared out of going there
 *  Click the padlock with the ! warns the about the dangers again

 Notes:

 Epiphany has this feature.  They have awsome copy too:


 {{{
 Look out!
 This might not be the real **dev.laptop.org**.

 When you try to connect securely, websites present identification to prove
 that your connection has not been maliciously intercepted. There is
 something wrong with this website’s identification:

 This website’s identification is too old to trust. Check the date on your
 computer’s calendar.

 A third party may have hijacked your connection. You should continue only
 if you know there is a good reason why this website does not use trusted
 identification. **Legitimate banks, stores, and other public sites will
 not ask you to do this.**
 }}}

--
Ticket URL: <https://bugs.sugarlabs.org/ticket/4895>
Sugar Labs <http://sugarlabs.org/>
Sugar Labs bug tracking system


More information about the Bugs mailing list