Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book General > News

Notices

Reply
 
Thread Tools Search this Thread
Old 10-29-2014, 11:12 PM   #16
bookmarked
Addict
bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.
 
Posts: 373
Karma: 6346855
Join Date: Nov 2012
Location: US
Device: Kindle 4 NT, Paperwhite
Quote:
Originally Posted by Lynx-lynx View Post
Thanks Rollei but I've already installed the Mozilla patch.

What I'm asking is how would someone know if they had been affected. What symptoms so to speak.
What happens now when you test your updated Firefox? Does it show vulnerable or not? If it's still showing vulnerable, you can either wait a month or change one setting in the about:config page.

Earlier I mixed up the Firefox version number that disabled SSLv3 by default. There was a different important security fix in FF33. I thought it was already fixed because my FF33.0.1 is not vulnerable, but I had forgotten that I manually disabled SSLv3.

Sorry for the confusion.
bookmarked is offline   Reply With Quote
Old 10-29-2014, 11:19 PM   #17
rollei
Addict
rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.
 
Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo


Does anyone know what should the values of security.tls.version.max and security.tls.version.min be?

I presently have the following:

security.tls.version.max = 3
security.tls.version.min = 0

What should I set the max and min values to?

Last edited by rollei; 10-29-2014 at 11:24 PM.
rollei is offline   Reply With Quote
Advert
Old 10-29-2014, 11:23 PM   #18
bookmarked
Addict
bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.bookmarked ought to be getting tired of karma fortunes by now.
 
Posts: 373
Karma: 6346855
Join Date: Nov 2012
Location: US
Device: Kindle 4 NT, Paperwhite
Quote:
Originally Posted by rollei View Post


Does anyone know what should the values of security.tls.version.max and security.tls.version.min be?

I presently have the following:

security.tls.version.max = 3
security.tls.version.min = 0

What should I set the max and min values to?
You only need to change the min value to 1.
Detailed instructions related to POODLE https://scotthelme.co.uk/sslv3-goes-...-off-protocol/
Reference info http://kb.mozillazine.org/Security.tls.version.*
bookmarked is offline   Reply With Quote
Old 10-29-2014, 11:26 PM   #19
rollei
Addict
rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.
 
Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
Quote:
Originally Posted by bookmarked View Post
You only need to change the min value to 1.
Detailed instructions related to POODLE https://scotthelme.co.uk/sslv3-goes-...-off-protocol/
Reference info http://kb.mozillazine.org/Security.tls.version.*
Thank you

Set security.tls.version.min = 1

When I run the SSL Labs, it said "Your user agent is not vulnerable."
rollei is offline   Reply With Quote
Old 10-29-2014, 11:32 PM   #20
rollei
Addict
rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.
 
Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
Quote:
Originally Posted by bookmarked View Post
You only need to change the min value to 1.

Detailed instructions related to POODLE https://scotthelme.co.uk/sslv3-goes-...-off-protocol/
Reference info http://kb.mozillazine.org/Security.tls.version.*
Those links are very helpful with clear and easy to follow instructions. I've fixed my Internet Explorer too.
rollei is offline   Reply With Quote
Advert
Old 10-30-2014, 06:08 AM   #21
shalym
Wizard
shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.
 
shalym's Avatar
 
Posts: 3,058
Karma: 54671821
Join Date: Feb 2012
Location: New England
Device: PW 1, 2, 3, Voyage, Oasis 2 & 3, Fires, Aura HD, iPad
Quote:
Originally Posted by eschwartz View Post
FF 33.0.2 is vulnerable, Mozilla will disable SSLv3.0 in FF34.
That's odd--I'm running FF32.0.1 and it came up as not vulnerable. Does that mean the poodletest.com is wrong?

Shari
shalym is offline   Reply With Quote
Old 10-30-2014, 06:29 AM   #22
Lynx-lynx
Treachery of images ...
Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.
 
Lynx-lynx's Avatar
 
Posts: 4,122
Karma: 93720365
Join Date: May 2012
Location: Australia
Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour
@shalym try testing it on one of the other sites.
Lynx-lynx is offline   Reply With Quote
Old 10-30-2014, 08:04 AM   #23
shalym
Wizard
shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.
 
shalym's Avatar
 
Posts: 3,058
Karma: 54671821
Join Date: Feb 2012
Location: New England
Device: PW 1, 2, 3, Voyage, Oasis 2 & 3, Fires, Aura HD, iPad
Quote:
Originally Posted by Lynx-lynx View Post
@shalym try testing it on one of the other sites.
I did. I still got a result of "not vulnerable"

Shari
Attached Thumbnails
Click image for larger version

Name:	Screenshot 2014-10-30 08.01.06.png
Views:	210
Size:	71.3 KB
ID:	130343  

Last edited by shalym; 10-30-2014 at 08:04 AM. Reason: Attach Screenshot
shalym is offline   Reply With Quote
Old 10-30-2014, 08:14 AM   #24
Lynx-lynx
Treachery of images ...
Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.
 
Lynx-lynx's Avatar
 
Posts: 4,122
Karma: 93720365
Join Date: May 2012
Location: Australia
Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour
@shalym that's interesting. When I tested my Firefox (same vers as you) I was vulnerable so I installed the patch and then tested it across the 3 differen testing sites all with the same not vulnerable report.

Maybe you should just install the patch anyway.
Lynx-lynx is offline   Reply With Quote
Old 10-30-2014, 08:31 AM   #25
shalym
Wizard
shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.
 
shalym's Avatar
 
Posts: 3,058
Karma: 54671821
Join Date: Feb 2012
Location: New England
Device: PW 1, 2, 3, Voyage, Oasis 2 & 3, Fires, Aura HD, iPad
Quote:
Originally Posted by Lynx-lynx View Post
@shalym that's interesting. When I tested my Firefox (same vers as you) I was vulnerable so I installed the patch and then tested it across the 3 differen testing sites all with the same not vulnerable report.

Maybe you should just install the patch anyway.
Maybe...I know that my IE version came up as vulnerable on the Poodle site, but FF and Chrome did not. I then installed the Microsoft patch for IE, and re-tested, and now all three browsers are showing as not vulnerable.

Maybe I disabled SSL 3.0 in Firefox and Chrome when the vulnerability was first announced, and forgot that I did it?

Shari
shalym is offline   Reply With Quote
Old 10-30-2014, 10:23 AM   #26
ottdmk
Wizard
ottdmk ought to be getting tired of karma fortunes by now.ottdmk ought to be getting tired of karma fortunes by now.ottdmk ought to be getting tired of karma fortunes by now.ottdmk ought to be getting tired of karma fortunes by now.ottdmk ought to be getting tired of karma fortunes by now.ottdmk ought to be getting tired of karma fortunes by now.ottdmk ought to be getting tired of karma fortunes by now.ottdmk ought to be getting tired of karma fortunes by now.ottdmk ought to be getting tired of karma fortunes by now.ottdmk ought to be getting tired of karma fortunes by now.ottdmk ought to be getting tired of karma fortunes by now.
 
Posts: 1,220
Karma: 3804496
Join Date: Feb 2012
Location: Ottawa, Ontario, Canada
Device: Kobo Libra 2, Lenovo Tab M10 FHD Plus, Lenovo Tab M9
Well, I just did some research and discovered that when the fine folks on the FreeBSD-Gecko team ported over Firefox 33 they set the preferences to disable SSL v3. Cool. Explains why both test sites told me I wasn't vulnerable.
ottdmk is offline   Reply With Quote
Old 10-30-2014, 01:08 PM   #27
rollei
Addict
rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.rollei ought to be getting tired of karma fortunes by now.
 
Posts: 219
Karma: 1000210
Join Date: Mar 2014
Device: Kobo
Quote:
Originally Posted by shalym View Post
Maybe...I know that my IE version came up as vulnerable on the Poodle site, but FF and Chrome did not. I then installed the Microsoft patch for IE, and re-tested, and now all three browsers are showing as not vulnerable.

Maybe I disabled SSL 3.0 in Firefox and Chrome when the vulnerability was first announced, and forgot that I did it?

Shari
@bookmarked has an excellent link here:
https://scotthelme.co.uk/sslv3-goes-...-off-protocol/

The link has a how-to guide on fixing the SSL3.0 issue. Follow through the guide for Firefox and verify that your settings are the same as the guide (security.tls.version.min = 1).
rollei is offline   Reply With Quote
Old 10-30-2014, 02:57 PM   #28
shalym
Wizard
shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.shalym ought to be getting tired of karma fortunes by now.
 
shalym's Avatar
 
Posts: 3,058
Karma: 54671821
Join Date: Feb 2012
Location: New England
Device: PW 1, 2, 3, Voyage, Oasis 2 & 3, Fires, Aura HD, iPad
Quote:
Originally Posted by rollei View Post
@bookmarked has an excellent link here:
https://scotthelme.co.uk/sslv3-goes-...-off-protocol/

The link has a how-to guide on fixing the SSL3.0 issue. Follow through the guide for Firefox and verify that your settings are the same as the guide (security.tls.version.min = 1).
Yup--mine is set to "security.tls.version.min = 1" which is why I'm getting an ok from both test sites. Thanks for finding that, rollei. I guess I fixed it already and just forgot that I had.

Shari
shalym is offline   Reply With Quote
Old 11-01-2014, 06:41 AM   #29
ShimSham
Enthusiast
ShimSham ought to be getting tired of karma fortunes by now.ShimSham ought to be getting tired of karma fortunes by now.ShimSham ought to be getting tired of karma fortunes by now.ShimSham ought to be getting tired of karma fortunes by now.ShimSham ought to be getting tired of karma fortunes by now.ShimSham ought to be getting tired of karma fortunes by now.ShimSham ought to be getting tired of karma fortunes by now.ShimSham ought to be getting tired of karma fortunes by now.ShimSham ought to be getting tired of karma fortunes by now.ShimSham ought to be getting tired of karma fortunes by now.ShimSham ought to be getting tired of karma fortunes by now.
 
Posts: 34
Karma: 402694
Join Date: May 2013
Location: London, UK
Device: Kobo Aura HD, Kobo Touch
This is the first, I've ever heard of any of this. My firefox 33.0.2 was vulnerable, I made a change in the settings and now I am not vulnerable. Thanks for the information.
ShimSham is offline   Reply With Quote
Old 11-09-2014, 05:32 PM   #30
Lynx-lynx
Treachery of images ...
Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.Lynx-lynx ought to be getting tired of karma fortunes by now.
 
Lynx-lynx's Avatar
 
Posts: 4,122
Karma: 93720365
Join Date: May 2012
Location: Australia
Device: Sony 650, Kobo Glo, H2O, Aura One, Forma, Libra 2, Libra Colour
I don't know about anyone else but I downloaded the latest Firefox upgrade recently, 33.0.3, and checked against the poodle tests just for the sake of it.

I'm still poodle clear.
Lynx-lynx is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 crutledge Kindle Books 0 09-23-2012 11:30 AM
Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 crutledge ePub Books 0 09-23-2012 11:29 AM
Short Fiction Anstey, F: The black poodle, and other tales. V1. 23 Sep 2012 crutledge BBeB/LRF Books 0 09-23-2012 11:28 AM
Free (Kindle UK) Alexandra's Legacy: Legacy, Book 1 by N. J. Walters arcadata Deals and Resources (No Self-Promotion or Affiliate Links) 3 09-01-2011 12:33 PM
my story has been frozen ever since i downgraded it haianh0402 iRiver Story 11 08-09-2010 03:25 AM


All times are GMT -4. The time now is 03:43 AM.


MobileRead.com is a privately owned, operated and funded community.