• 设为首页
  • 点击收藏
  • 手机版
    手机扫一扫访问
    迪恩网络手机版
  • 关注官方公众号
    微信扫一扫关注
    公众号

sibiantony/ssleuth: A firefox add-on to rate the quality of HTTPS connections

原作者: [db:作者] 来自: 网络 收藏 邀请

开源软件名称:

sibiantony/ssleuth

开源软件地址:

https://github.com/sibiantony/ssleuth

开源编程语言:

JavaScript 90.6%

开源软件介绍:

Update Jan 27, 2020 : SSleuth development has stopped. Please look at the alternatives IndicateTLS, Certainly Something

Update Sep 2, 2018 : Please note : This add-on is not compatible with Firefox 57+ (Quantum). For more details : #78

SSleuth

SSleuth is a Firefox addon that ranks an established SSL/TLS connection to estimate the connection strength. It also gives a brief summary of the important SSL/TLS connection parameters.

Screenshot mozilla.org

This was developed with the intent to rate the encryption ciphers used in an SSL/TLS connection. The project maintains a list of cipher suites that are shipped with Firefox and a rank for each of them. The rankings are mainly inspired from Qualys's SSL labs server testing tool. The SSL labs testing is meant for web servers, more sophisticated and is much more than a cipher ranking service. However to know which ciphers are used when a user connects to a website, browser support and/or an addon is necessary. Firefox started exposing the full cipher suite name from version 25.0. Users can see the cipher suite by going to the URL notification lock icon -> More information or Page Info -> Security -> Technical details. The user can see the cipher suite used for connection and firefox's assessment of the strength of the cipher.

SSleuth attempts to enhance this visibility of ciphers to the user, by ranking it and appropriateley color coding it. The addon panel also gives information on perfect forward secrecy, firefox connection status and the certificate details.

Rating Rationale

The rating mechanism is in the early stages now, and might change in future. See the wiki page on Rating Mechanism for more information.

Disabling weak ciphers

Beginning with version 0.2.3 SSleuth supports enabling and disabling cipher suites. Users can create a list of cipher suites to toggle, and use the notifier right click menu to toggle them. More details on enabling/disabling cipher suites in the wiki.

Graphical User Interface

There is a URL bar notification box (next to Firefox's own notification area). A 'sleuth' cap and the rank notifies the user of the estimated strength. There is an optional toolbar button mode (choose from preferences), if the user wishes to move around a toolbar button.

Color coding

The color of the notification area changes from green (very good), to blue (good), orange (medium) and red(bad).

Keyboard shortcut

The panel can be easily brought up with the key combinations 'Ctrl' + 'Shift' + '}'. If the keyboard shortcut interferes with any existing addon and/or your keyboard doesn't support the key combination, please report it. It is however possible to change the keyboard shortcut via configuration.

  • Navigate to 'about:config'
  • Key in extensions.ssleuth to find all ssleuth configurables, and look for extensions.ssleuth.ui.keyshortcut
  • The preference type is a string and you can change the modifieres and key. Please follow mozilla guidelines for modifiers and keys to set the shortcut. SSleuth uses 'keys' rather than 'keycodes'.

License

SSleuth is released under GPLv3.0. You should find the license text in the About page of add-on preferences.

Jdenticon 1.3.2 zlib license, jdenticon.com (c) Daniel Mester Pirttijärvi




鲜花

握手

雷人

路过

鸡蛋
该文章已有0人参与评论

请发表评论

全部评论

专题导读
热门推荐
阅读排行榜

扫描微信二维码

查看手机版网站

随时了解更新最新资讯

139-2527-9053

在线客服(服务时间 9:00~18:00)

在线QQ客服
地址:深圳市南山区西丽大学城创智工业园
电邮:jeky_zhao#qq.com
移动电话:139-2527-9053

Powered by 互联科技 X3.4© 2001-2213 极客世界.|Sitemap