Add a warning to about:neterror when SSLKEYLOGFILE is in use
Categories
(Core :: Networking, enhancement, P2)
Tracking
()
| Tracking | Status | |
|---|---|---|
| firefox154 | --- | fixed |
People
(Reporter: valentin, Assigned: valentin)
References
(Blocks 1 open bug, )
Details
(Whiteboard: [necko-triaged][necko-priority-queue])
Attachments
(2 files)
It seems a bunch of AV are using SSLKEYLOGFILE to decrypt TLS traffic - and sometimes break it in unusual ways.
On Windows about 10% of users have the env var set.
@mt:
if we can detect SSLKEYLOGFILE being set, we should add something to every network error page we show.Β "It looks like someone is snooping on your communications.Β If you are having trouble getting online, consider disabling features.Β <See su.mo for details, where we list software that engages in these practices and describe how to disable each.>"
| Assignee | ||
Comment 1•5 months ago
|
||
More suggestions:
- Show the warning in devtools
- Show the warning in the shield status - because if SSLKEYLOGFILE is in use, it is possible someone is decrypting your connection.
Comment 2•5 months ago
|
||
+1 to also having some alternatives, as "to every network error page we show" could be either too late, or the consumer never reached the error page in case they're stuck in some empty result / zombie connection.
| Assignee | ||
Updated•5 months ago
|
| Assignee | ||
Comment 3•4 months ago
|
||
Updated•4 months ago
|
| Assignee | ||
Comment 4•4 months ago
|
||
| Assignee | ||
Comment 5•4 months ago
|
||
Screenshots of proposed warning: https://drive.google.com/drive/u/1/folders/1KINByYi8oSRTiRyqC5_ImdzQIseTHzUR
| Assignee | ||
Comment 6•4 months ago
|
||
Background for this bug:
SSLKEYLOGFILE is an environment variable used to make Firefox dump the encryption keys used for HTTPS connections into a file.
This is useful for debugging, or inspecting connection data with Wireshark.
However in bug 2035411, and bug 1188660 we also noticed that some anti-virus software injects this variable into Firefox to be able to decrypt HTTPS connections. In doing so, they sometimes break the connections.
Bug 2035411 is going to display a warning in network/TLS error pages when SSLKEYLOGFILE is present, telling users that software on their machine might be monitoring their connection and linking to the sumo article.
The KB article should instruct users who are seeing networking issues to check their antivirus/firewall software before filing a Firefox bug. And when filing the bug they should specify which anti-virus solution they are using.
| Assignee | ||
Updated•3 months ago
|
Updated•3 months ago
|
Comment 9•3 months ago
•
|
||
Backout for causing xpcshells and mochitests failures at dom/security
| Assignee | ||
Updated•3 months ago
|
Comment 10•3 months ago
|
||
Comment 11•3 months ago
|
||
Comment 12•3 months ago
|
||
Reverted this because it was causing build bustages.
- Revert link
- Push with failures
- Failure Log
- Failure line: gmake[2]: *** No rule to make target 'backend.FasterMakeBackend', needed by 'pre-export'.
Please also check this.
Comment 13•2 months ago
|
||
There are some r+ patches which didn't land and no activity in this bug for 1 week.
:valentin, could you have a look please?
If you still have some work to do, you can add an action "Plan Changes" in Phabricator.
For more information, please visit BugBot documentation.
| Assignee | ||
Updated•2 months ago
|
Comment 14•2 months ago
|
||
Comment 15•2 months ago
|
||
| bugherder | ||
https://hg.mozilla.org/mozilla-central/rev/7a378c1ff778
https://hg.mozilla.org/mozilla-central/rev/3000d68ae25d
Updated•2 months ago
|
Description
•