Configuring Firefox 2.x or 3.x for Increased Security
- Blogs:
Web browsers have become the de facto client interface to Internet based applications. As we travel around the Internet, whether for pleasure or business, we find ourselves creating personal profiles for various Web sites. These profiles usually include access credentials (usernames and passwords). Good password management practice calls for many distinct passwords. But this proliferation of passwords results in the need for strong password storage. In addition to password management we need to give some thought to encrypted communications. We typically just install a browser and start surfing without any thought for the decisions other people have made for us about who we should trust or how we should communicate. The default settings for SSL/TLS are a good example of this.
Password Management Settings
Firefox provides a convenient method of storing passwords using the built in password manager. However, recent articles [ref1, ref2] have highlighted the fact that some configuration is required to raise the level of security before using this feature. The following are some configuration settings that can improve the security of information stored in the password manager.
- Use a master password. Enable the master password feature by navigating to the Security tab of the applications preferences. Check "Use a master password" and enter a strong password, a pass phrase is even better.
- Enable FIPS. Enable the FIPS-104-1 internal cryptographic device to ensure proper handling of stored information. Navigate to the Advanced tab of the application preferences. Click "Security Devices" then click "Enable FIPS".
- Remember passwords. If you haven't already, configure Firefox to remember passwords for Web sites by navigating back to the Security tab of the application preferences. Check "Remember passwords for sites."
NOTE: If you ever need to see a stored password for a particular site you can do this by navigating to the Security tab of the application preferences, click "Show passwords", click "Show passwords", enter your master password, and they will be presented along with the corresponding site and username.
ALTERNATIVE: If you really want to be paranoid, that's allowed here, you could choose not to allow Firefox to store any information and use a separate password manager like Password Safe [ref3] or pwsafe [ref4]. I do both since I use multiple machines.
SSL Settings
First a couple of recommendations, then a warning.
We've all seen the SSL warning messages stating that there is a problem with a certificate from a Web site. Most people simply accept the certificate temporarily and click through to the Web site without really understanding what they are doing. This is because most users have no idea what the messages mean. The most common warnings are 1) expired certificate or 2) unrecognized signer. My recommendation for an expired certificate is to contact the Web site owner and ask them if they are aware that their certificate is expired and when they plan to renew their certificate. Then make your decision about whether to proceed or wait. My recommendation for unrecognized signers is to view the signing certificate authority (CA) information and evaluate whether you want to trust the CA that signed the certificate. If you decide to trust the CA then you will want to locate the CA's public key(s) and install them, this is usually as simple as clicking on a link to the CA's public key. This will bring up a dialog box asking you to make some selections about what kinds of certificates you want to recognize the CA for (identify Web sites, e-mail users, and/or software makers). NOTE: It is not recommended to accept self-signed certificates unless you know the consequences.
WARNING: The following section is not for the faint of heart. If you don't want to do some research or are not willing to deal with the potential hassle that may result you should skip to the section on certificate revocation lists.
If you're still with me I'm serious, don't do this unless you know what you're getting yourself into. I'll try to explain it as best I can but don't blame me if you find yourself tracking down CA certificates so you can reinstall them later on.
Certificate Authorities
When we install Firefox, or other client software that supports SSL, it comes with a set of trusted certificate authorities. Most people never give this a second thought. However, decisions have been made by the other people about what CA's we will an won't trust. The process of getting a CA certificate into the distribution of a software package like Firefox can be a political and drawn out process, just ask CACert.org [ref5]. I would encourage you to review the list of CAs that are installed in your browser, do some research and make any changes you feel are necessary. I would also encourage you to consider installing CA certificates for CAs that you trust but are not already installed, such as CACert.org or company's CA.
To view the installed CAs navigate to the Advanced tab of the application preferences, select the Encryption tab, and click "View Certificates", then select the Authorities tab.
Certificate Revocation Lists
A certificate revocation list (CRL) is a list of all the certificates that a CA would like to revoke. I say it this way because unless you have configured your software to use the CRLs from the CAs that you trust then you will have no idea that certain certificates have been revoked. This is a very important and often overlooked aspect of SSL/TLS. Installing a CRL [ref6] is as simple as installing a CA's public key, simply click on the URL for the CRL and you will be presented with some choices about configuring automated updates of the CRL. It is recommended that you enable automatic updates.
Now that you've read this, you might want to configure Firefox for increased privacy.
References:
- geekwisdom's blog
- Login or register to post comments


Comments
Antivirüs ve güvenlik programları
sex adult erotik porno erotik film seyret sex filmi izle porno film izle adult film izle türk pornosu izle erotik film izleporno film izlesex filmi izleadult film izleyeşilçam türk pornosu izle rus lolitalarlolita pornosu izle lolita erotik videoları lolita sert sikiş seyret blog
sohbet odaları sohbet yap kızlarla sohbet ve Chat sende sohbete katılabilirsin Film izle | Erotik sikiş filmi |erotik sex Video | Sohbet | kameralı sohbet | bedava sohbet < sohbet odaları | erotik sex Film izle | Erotik | Video | erotik Video | porno Videosu | sex Video | sikiş pornosu | porno film | bedava chat | bedava sohbet | sohbet odaları | sohbet | iddaa oyna | lig tv izle bedava chat erotik film erotik porno film porno film erotik film sex film porno sex erotik erotik film izle porno film izle sex film izle sikiş filmi izle pornotv porno video izleerotik video izlesex videosu izle sikiş videosu izleadult adult video adult film erotik izle porno izle sex izle sikiş izle
Fashion weekyou can come to
Fashion week
you can come to see it,it's so fashion.I think you will like it.
thanks
Thank you very much projeksiyon
You can watch porn on this
You can watch porn on this site. Thanks to everyone who had contributed to the site. porno site and sex is such Material. Thank you for your interest.
jagra jagra jagra jagra penis buyutuculer sex shop penis buyutuculer v-pills tatil azdirici kahve sirhunter sirhunter sirhunter saat kamera kalem kamera magna rx vpills penis buyutucu azdirici azdirici azdirici azdirici yatakarkadas.com cinselsex.net vpillsmarket.com penis buyutucu burclar ruyatabirleri yemektarifleri hava durumlari azdirici ic giyimler mirc azdirici dolusextr.com porno izle sexvidyolari.com cinselsex.net adulteviniz.com
buZ
chat siteleri |sohbet|yonja|forum siteleri|mirc indir|sohbet|yonja|sohbet|sohbet|
kizlarla sohbet|dini sohbet|islami sohbet|sohbet/sohbet odalarisohbet|netlog|yonja|sohbet chat
cinsel sohbet
porno izle
toplist ekle
camfrog indir
lida fx15 biber hapı ikibindokuz seo yarışması -
lida fx15 biber hapı ikibindokuz seo yarışması -
kurumsalseo.com R10 lida fx15 pohudey zayıflama
lida
The Internet is a haven of
The Internet is a haven of discounts and bargains. All the things that you can buy on retail and traditional stores, you can find online too, like the adobe voucher code. Often we can see a big difference in price because online shops basically keep costs down. They have much less expense than a real shop. Almost all internet stores are automated and you are sure to receive your goods in good time via land or air delivery sometimes for free using a discount code. But that's not all, you can save much, much more by using norton 360 coupon areas and promotional codes while you are on your online shopping spree.
Create supplemental content
Create supplemental content like FAQ pages, how-to pages, industry glossary and related articles about the product.
Search Engine Optimization
RE:
fine stuff.
Buy Essay
Online Essay
Essay Writing Service
Essay Service
Essay Topics
RE:
This will bring up a dialog box asking you to make some selections
tommy hilfiger distributor
Fred Perry Polos supplier
ralph lauren wholesale
Apparel wholesale supplier
abercrombie & fitch wholesaler
diesel jeans wholesaler
calvin klein
What is the difference
What is the difference between source code and binary version distribution in open source?
Thanks,
SEO
Re:
I'll try to explain it as best I can but don't blame me if you find yourself tracking down CA certificates so you can reinstall them later on.Accounting degree | Law schools
Re:
This will bring up a dialog box asking you to make some selections about what kinds of certificates you want to recognize the CA for (identify Web sites, e-mail users, and/or software makers).
Criminal Justice degree | computer diploma | online MBA degree
TirYaKi
sohbet
yonja
chat
dini sohbet
chat siteleri
islami sohbet
almanya sohbet
sohbet siteleri
bedava chat
bedava sohbet
sohbet odalari
sohbet
yonja
bedava chat
canlı sohbet
chat emanuel chat kaynanı
chat emanuel chat kaynanı varyaa lollarım cinsel sohbet sohbet alexx
dogum günü sözleri amelemisin? bedava chat mirc indir
chat siteleri kabul et lan kameralı sohbet chat sitesi çet
chat siteleri sohbet siteleri hoşt köpek kizlarla sohbet
chat sitesi izlemeye bıkmayacaksınız. sohbet
sohbet odaları and sohbet odaları bedava chat
sohbet kızlarla sohbet sohbet odaları bedava sohbet
Bill Smit
Tricor Side Effects
buy tricor
Check with your doctor if any of these most common side effects persist or become bothersome:
* back pain; constipation; diarrhea; dizziness; flu syndrome; gas; headache; nausea; stomach pain; weakness.
Seek medical attention right away if any of these severe side effects occur:
* severe allergic reactions (rash; hives; difficulty breathing; tightness in the chest; swelling of the mouth, face, lips, or tongue); fever; inflammation of the pancreas (stomach tenderness; nausea; vomiting; fever; increased pulse rate); runny nose; muscle pain, tenderness, or weakness.
buy Cialis Soft Tabs
porno izle, sikiş, amcık,
porno izle, sikiş, amcık, seks videoları seyret, erotik video, amatör, sakso, götten, sikiş videolar, sex video
porno izle -
sex -
porno -
sikiş
casino online
Come giocare gratis a
casino online bonus il Bingo Online bonus i The Casino online bonus visita anche: Titan casino bonus europa casino bonus tropez casino bonus bellini casino bonus vegas red bonus cameo casino bonus del rio casino bonus craps.com casino bonus titan poker bonus bingo day bonus slot machines bonus blackjack bonus roulette bonus videopoker bonus dadi bonus keno bonus baccarat bonus glossario bonus metodi incasso/deposito bonus codici bonus reali migliori casino online trucchi migliori poker online bonus Directory bonus Forum bonus ciao a tutti
Thank you for the SSL
Thank you for the SSL settings. I was trying to install a ssl certificate and I was having some trouble. By the way, Firefox 3.x seems more secure but it jams more than 2.x.
hello
online casino
best online casino
casino online
us online casino