Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On the other hand these stupid dialog tricks are why I stopped using Chrome. I'm not an idiot and I know what I'm doing. It's pretty arrogant to assume that I shouldn't be visiting my router's configuration page just because it uses a self-signed certificate. I don't care to set up an X.509 infrastructure at my house, thank you. Please stop mollycoddling me.

Firefox continues to do a good job of just letting me visit the damn website after warning me.



I'm confused - Firefox and Chrome act completely identically to a self signed cert for me. Both let me click through after looking at the cert or expanding a section. I have never been "blocked" by some hidden modal unless the site chooses to be HSTS-enforcing, and in that case Firefox does not allow a clickthrough either.

Both examples on latest current, taken right now:

Firefox: https://i.imgur.com/4VMjDZ4.png

Chrome: https://i.imgur.com/YosvXEu.png

For HSTS, both Firefox and Chrome act identically and do not allow clickthrough: https://i.imgur.com/WPCTep1.png


Youre confused because you're not using Chrome on OSX: on osx there's no "Proceed to <website>" option.



I'm now even more confused: https://i.imgur.com/jl9agwG.png


You’re right to be confused because I’ve never seen a rhyme or reason to it either. I generated a cert using OpenSSL’s command line tools and told Django’s manage.py to use my self-generated cert and it works in Firefox but not Chrome.

It did work in Chrome. And then after an update it didn’t work anymore. I don’t know why and it seems like no one else here does either.


I was literally going to say that at one point that screen didn't look like that, and it appears it still doesn't but only sometimes.


Your router's self-signed cert can be imported into your browser and trusted from thereon — that will also stop any potential attacks from someone pretending to be your wifi ap nearby because I am pretty sure you are not double-checking the cert fingerprint every time you visit the router's admin interface. Provided you were not MITMed once you added the cert in the first place :)


At least Chrome lets you use that trick to bypass an hsts error message. Firefox won't let you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: