Closed Bug 1167373 Opened 10 years ago Closed 10 years ago

Sign addon for Logjam vulnerability

Categories

(Release Engineering :: General, defect)

defect
Not set
major

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: mt, Assigned: rail)

References

()

Details

Attachments

(2 files)

Attached file disable-dhe.xpi
This addon disables DHE cipher suites. It's for the logjam attack announced this week (https://weakdh.org). We decided that this might be a good option to offer to our users since we aren't landing a fix until Firefox 39. Disabling DHE is perhaps a little risky for general consumption. Up to 5% of our connections use DHE and we're not sure if there is a good fallback if we disable it. An addon should help users who are concerned about the attack.
Assignee: nobody → rail
Attached file disable-dhe-signed.xpi
Done.
Status: NEW → RESOLVED
Closed: 10 years ago
Resolution: --- → FIXED
Many thanks. I'll get this into a.m.o as soon as I can.
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: