Re: Iceweasel and web browsers vulnerabilty concerning poodle.

2014-10-17 Thread Elmar Stellnberger
The maintainers should be reachable at: pkg-mozilla-maintain...@lists.alioth.debian.org Perhaps you should also ask them to package the DNSSEC validatioin plugin for Firefox: http://www.internetsociety.org/deploy360/resources/how-to-add-dnssec-support-to-mozilla-firefox/ I believe there

Re: Iceweasel and web browsers vulnerabilty concerning poodle.

2014-10-16 Thread Brad Cable
I would like to point out what security.tls.version.min actually does: http://kb.mozillazine.org/Security.tls.version.* Setting security.tls.version.min to 1 allows TLSv1.0 to be used, which is vulnerable to a similar padding oracle attack (and timing oracle attacks) found long ago. You

Re: Iceweasel and web browsers vulnerabilty concerning poodle.

2014-10-16 Thread Pedro Worcel
​Just something related I happened to stumble across: http://www.bit-tech.net/news/bits/2014/10/15/google-mozilla-sslv3/1​

Re: Iceweasel and web browsers vulnerabilty concerning poodle.

2014-10-16 Thread Pedro Worcel
Sorry about the double email, this is the original source for Mozilla https://blog.mozilla.org/security/2014/10/14/the-poodle-attack-and-the-end-of-ssl-3-0/ 2014-10-17 9:12 GMT+13:00 Pedro Worcel pe...@worcel.com: ​Just something related I happened to stumble across:

Re: Iceweasel and web browsers vulnerabilty concerning poodle.

2014-10-16 Thread Yves-Alexis Perez
On jeu., 2014-10-16 at 10:28 -0500, Marco Galicia wrote: *shoulnd't iceweasel be recompiled to include this option in the complilation settings??* You're not asking at the correct place, it's a bit unlikely the maintainer read that list. But in any case, Mozilla themselves intend to disable