Closed Bug 1170833 Opened 10 years ago Closed 10 years ago

home.nest.com breaks with Firefox 39 or higher

Categories

(Web Compatibility :: Site Reports, defect)

Firefox 39
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: catlee, Unassigned)

References

Details

I am unable to use home.nest.com with Firefox 39 or higher due to this error: An error occurred during a connection to transport01-rts10-iad01.transport.home.nest.com. SSL received a weak ephemeral Diffie-Hellman key in Server Key Exchange handshake message. (Error code: ssl_error_weak_server_ephemeral_dh_key)
See also this other user having problems: https://twitter.com/phinze/status/604718110210441216
Fallout from the Logjam fix
768-bit DHE. Wonder if it is Java. Will notify Google security.
Just added sleevi and wtc to CC list.
Please report through the proper channels, rather than CC'ing random Googlers or tweeting at them :) In this case, reporting through our normal security channels is the right way, the same as any security issue.
I did. Cid: 1-8374000007338 if interested.
I also tried contacting Nest support (ref 01247546), and was encouraged to try a different browser instead :P
Workaround: install Disable DHE extension: https://addons.mozilla.org/ja/firefox/addon/disable-dhe/
I believe that this should now be fixed on the server side.
Status: NEW → RESOLVED
Closed: 10 years ago
Resolution: --- → FIXED
TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA is still enabled though, which is probably an error.
Product: Tech Evangelism → Web Compatibility
You need to log in before you can comment on or make changes to this bug.