Forum Moderators: open

Message Too Old, No Replies

No More POODLE Attacks: Mozilla To Disable SSLv3 In Firefox 34

         

engine

3:24 pm on Oct 15, 2014 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Firefox will get an automatic disabling of SSLv3 with V34, due out in a few weeks. If you have concerns, use the SSL version control extension.

It seems IE6 is the only browser that relies on SSLv3, so if there was another reason the ditch it, this is another one to just say no.

Today, Firefox uses SSLv3 for only about 0.3% of HTTPS connections. That’s a small percentage, but due to the size of the Web, it still amounts to millions of transactions per day.No More POODLE: Mozilla To Disable SSLv3 In Firefox 34 [blog.mozilla.org]
SSLv3 will be disabled by default in Firefox 34, which will be released on Nov 25. The code to disable it is landing today in Nightly, and will be promoted to Aurora and Beta in the next few weeks. This timing is intended to allow website operators some time to upgrade any servers that still rely on SSLv3.
As an additional precaution, Firefox 35 will support a generic TLS downgrade protection mechanism known as SCSV. If this is supported by the server, it prevents attacks that rely on insecure fallback.
For users who don’t want to wait till November 25th (when SSLv3 is disabled by default in Firefox 34), we have created the SSL Version Control Firefox extension to disable SSLv3 immediately.



[addons.mozilla.org...]

Earlier story
Poodle Attack, SSL 3.0 Vulnerability, Solution, and Compatibility Problems [webmasterworld.com]

not2easy

4:53 pm on Oct 15, 2014 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



I installed the addon, it took about a minute and did not require shutdown or configuration, but does allow the user to adjust if needed.