9 messages in org.mozilla.lists.dev-tech-cryptoRe: Comment on tls-srp enhancement?
FromSent OnAttachments
Steffen SchulzDec 7, 2007 7:43 am 
Nelson BolyardDec 7, 2007 4:20 pm 
Steffen SchulzDec 7, 2007 7:50 pm 
Nelson BolyardDec 8, 2007 6:51 pm 
Steffen SchulzDec 12, 2007 10:34 am 
Michael StröderDec 13, 2007 7:26 am 
Steffen SchulzDec 13, 2007 9:27 am 
Nelson BolyardDec 15, 2007 4:48 pm 
Steffen SchulzDec 16, 2007 1:55 pm 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:Re: Comment on tls-srp enhancement?Actions...
From:Nelson Bolyard (NOne@NObolyardSPAM.com)
Date:Dec 8, 2007 6:51:15 pm
List:org.mozilla.lists.dev-tech-crypto

Steffen Schulz wrote, On 2007-12-07 19:50:

On 071208 at 01:25, Nelson Bolyard wrote:

[snip]

Do you have a companion bug/RFE for adding the necessary UI support to PSM (Personal Security Manager), the Mozilla software component that does UI for crypto-related issues? Having SRP in NSS won't do much good unless the necessary UI is also present.

No patch as of now. Larry from FF3 displays the identity of the server as the main aspect, but with SRP there may be mutual authentication but no certificate information at all. I also personally dislike Larry.

Now if I write a PSM patch, I'd have to integrate it into the existing security interface. A lot of fuss about sth that is IMHO inherently broken.

If FF doesn't have any built-in UI for SRP, I think I have a harder time justifying the inclusion of SRP in NSS. I think it's a feature that would be included exclusively for use in the browser, so if the browser can't use it "out of the box", there may be push back on it.

So the plan was to create a FF extension instead. One that 'fixes' how the security status is displayed(and perceived, hopefully), and also includes some other ideas with regards to phishing attacks. Then the patch against PSM should be very small if needed at all. I hope this way it will be easier to settle on the way the security interface should work and it may also help to evaluate how some other ideas perform.

Easier? Because it's easier to obtain forgiveness than permission? :-)

[snip]

Regards, /steffen

Regards, /Nelson