[HTTPS-Everywhere] Automated live-browser testing for rulesets that cause cert warnings

Peter Eckersley pde at eff.org
Fri Aug 22 16:58:28 PDT 2014


On Fri, Aug 22, 2014 at 04:46:50PM -0700, Peter Eckersley wrote:
 
> Those tests can be found by toggling
> extensions.https_everywhere.show_ruleset_tests to true in about:config,
> after which they'll be in the HTTPS Everywhere menu.  They should be
> able to give us data on which rulesets are obviously causing cert
> warnings and MCB...

Actually, those tests aren't currenlty noticing the cert warnings
they're triggering.  We really need to do that :)

I should be able to do that 2-3 weeks, but if anyone else wants to try,
this is the XPCOM hook to use:

https://developer.mozilla.org/en-US/docs/Mozilla/Tech/XPCOM/Reference/Interface/nsIBadCertListener2

There's an implementation in src/components/ssl-observatory.js available
for reference :)

-- 
Peter Eckersley                            pde at eff.org
Technology Projects Director      Tel  +1 415 436 9333 x131
Electronic Frontier Foundation    Fax  +1 415 436 9993


More information about the HTTPS-Everywhere mailing list