|
![]() |
|
Thread Tools | Search this Thread |
![]() |
#16 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 373
Karma: 6346855
Join Date: Nov 2012
Location: US
Device: Kindle 4 NT, Paperwhite
|
Quote:
Earlier I mixed up the Firefox version number that disabled SSLv3 by default. There was a different important security fix in FF33. I thought it was already fixed because my FF33.0.1 is not vulnerable, but I had forgotten that I manually disabled SSLv3. Sorry for the confusion. |
|
![]() |
![]() |
![]() |
#17 |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
|
![]() Does anyone know what should the values of security.tls.version.max and security.tls.version.min be? I presently have the following: security.tls.version.max = 3 security.tls.version.min = 0 What should I set the max and min values to? Last edited by rollei; 10-29-2014 at 11:24 PM. |
![]() |
![]() |
Advert | |
|
![]() |
#18 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 373
Karma: 6346855
Join Date: Nov 2012
Location: US
Device: Kindle 4 NT, Paperwhite
|
Quote:
Detailed instructions related to POODLE https://scotthelme.co.uk/sslv3-goes-...-off-protocol/ Reference info http://kb.mozillazine.org/Security.tls.version.* |
|
![]() |
![]() |
![]() |
#19 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
|
Quote:
![]() Set security.tls.version.min = 1 When I run the SSL Labs, it said "Your user agent is not vulnerable." |
|
![]() |
![]() |
![]() |
#20 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
|
Quote:
![]() |
|
![]() |
![]() |
Advert | |
|
![]() |
#21 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,058
Karma: 54671821
Join Date: Feb 2012
Location: New England
Device: PW 1, 2, 3, Voyage, Oasis 2 & 3, Fires, Aura HD, iPad
|
|
![]() |
![]() |
![]() |
#22 |
Treachery of images ...
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 4,122
Karma: 93720365
Join Date: May 2012
Location: Australia
Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour
|
@shalym try testing it on one of the other sites.
|
![]() |
![]() |
![]() |
#23 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,058
Karma: 54671821
Join Date: Feb 2012
Location: New England
Device: PW 1, 2, 3, Voyage, Oasis 2 & 3, Fires, Aura HD, iPad
|
I did. I still got a result of "not vulnerable"
Shari Last edited by shalym; 10-30-2014 at 08:04 AM. Reason: Attach Screenshot |
![]() |
![]() |
![]() |
#24 |
Treachery of images ...
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 4,122
Karma: 93720365
Join Date: May 2012
Location: Australia
Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour
|
@shalym that's interesting. When I tested my Firefox (same vers as you) I was vulnerable so I installed the patch and then tested it across the 3 differen testing sites all with the same not vulnerable report.
Maybe you should just install the patch anyway. |
![]() |
![]() |
![]() |
#25 | |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,058
Karma: 54671821
Join Date: Feb 2012
Location: New England
Device: PW 1, 2, 3, Voyage, Oasis 2 & 3, Fires, Aura HD, iPad
|
Quote:
Maybe I disabled SSL 3.0 in Firefox and Chrome when the vulnerability was first announced, and forgot that I did it? Shari |
|
![]() |
![]() |
![]() |
#26 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,220
Karma: 3804496
Join Date: Feb 2012
Location: Ottawa, Ontario, Canada
Device: Kobo Libra 2, Lenovo Tab M10 FHD Plus, Lenovo Tab M9
|
Well, I just did some research and discovered that when the fine folks on the FreeBSD-Gecko team ported over Firefox 33 they set the preferences to disable SSL v3. Cool. Explains why both test sites told me I wasn't vulnerable.
|
![]() |
![]() |
![]() |
#27 | |
Addict
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
|
Quote:
https://scotthelme.co.uk/sslv3-goes-...-off-protocol/ The link has a how-to guide on fixing the SSL3.0 issue. Follow through the guide for Firefox and verify that your settings are the same as the guide (security.tls.version.min = 1). |
|
![]() |
![]() |
![]() |
#28 | |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,058
Karma: 54671821
Join Date: Feb 2012
Location: New England
Device: PW 1, 2, 3, Voyage, Oasis 2 & 3, Fires, Aura HD, iPad
|
Quote:
Shari |
|
![]() |
![]() |
![]() |
#29 |
Enthusiast
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 34
Karma: 402694
Join Date: May 2013
Location: London, UK
Device: Kobo Aura HD, Kobo Touch
|
This is the first, I've ever heard of any of this. My firefox 33.0.2 was vulnerable, I made a change in the settings and now I am not vulnerable. Thanks for the information.
|
![]() |
![]() |
![]() |
#30 |
Treachery of images ...
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 4,122
Karma: 93720365
Join Date: May 2012
Location: Australia
Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour
|
I don't know about anyone else but I downloaded the latest Firefox upgrade recently, 33.0.3, and checked against the poodle tests just for the sake of it.
I'm still poodle clear. |
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 | crutledge | Kindle Books | 0 | 09-23-2012 11:30 AM |
Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 | crutledge | ePub Books | 0 | 09-23-2012 11:29 AM |
Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 | crutledge | BBeB/LRF Books | 0 | 09-23-2012 11:28 AM |
Free (Kindle UK) Alexandra's Legacy: Legacy, Book 1 by N. J. Walters | arcadata | Deals and Resources (No Self-Promotion or Affiliate Links) | 3 | 09-01-2011 12:33 PM |
my story has been frozen ever since i downgraded it | haianh0402 | iRiver Story | 11 | 08-09-2010 03:25 AM |