Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243643 > unrolled thread

Firefox: Warning: Potential Security Risk Ahead for the USPS.com

Started bylocal10 <local10@tutanota.com>
First post2022-01-03 23:10 +0100
Last post2022-01-04 16:30 +0100
Articles 20 on this page of 42 — 13 participants

Back to article view | Back to linux.debian.user


Contents

  Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:10 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Roberto C. Sánchez <roberto@debian.org> - 2022-01-03 23:20 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:20 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Mark Allums <maa@allums.com> - 2022-01-03 23:40 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-04 00:30 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 01:00 +0100
          [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com local10 <local10@tutanota.com> - 2022-01-04 01:10 +0100
            Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Michael Stone <mstone@debian.org> - 2022-01-04 19:20 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2022-01-04 19:40 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 19:40 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Michael Stone <mstone@debian.org> - 2022-01-04 21:30 +0100
              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 19:40 +0100
                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com David Wright <deblis@lionunicorn.co.uk> - 2022-01-04 20:40 +0100
                  Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 21:00 +0100
                    Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-04 22:10 +0100
                      Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 06:20 +0100
                        Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 14:50 +0100
                          Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 18:30 +0100
                            Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 18:50 +0100
                              Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 19:50 +0100
                                Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 22:00 +0100
                  Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2022-01-04 21:00 +0100
                  Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-04 22:30 +0100
                    Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-05 06:20 +0100
                      Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-05 13:50 +0100
              Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 19:50 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-03 23:50 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com Charles Curley <charlescurley@charlescurley.com> - 2022-01-03 23:40 +0100
      Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-03 23:50 +0100
        Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 00:30 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-04 00:40 +0100
            Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-04 00:50 +0100
            Re: Firefox: Warning: Potential Security Risk Ahead for the  USPS.com local10 <local10@tutanota.com> - 2022-01-04 00:50 +0100
          Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com RP <reyadmin@gmail.com> - 2022-01-04 00:50 +0100
    Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-04 07:00 +0100
      [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com local10 <local10@tutanota.com> - 2022-01-04 13:00 +0100
        Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for  the USPS.com <tomas@tuxteam.de> - 2022-01-04 13:20 +0100
      GUIs (was: Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com) rhkramer@gmail.com - 2022-01-04 15:00 +0100
        Re: GUIs (was: Re: Firefox: Warning: Potential Security Risk Ahead  for the USPS.com) <tomas@tuxteam.de> - 2022-01-04 16:30 +0100

Page 1 of 3  [1] 2 3  Next page →


#243643 — Firefox: Warning: Potential Security Risk Ahead for the USPS.com

Fromlocal10 <local10@tutanota.com>
Date2022-01-03 23:10 +0100
SubjectFirefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBDGF-5pQ-5@gated-at.bofh.it>
Hi,

Am I the only one who's getting this error? When I go to the USPS.com[1] to track a package I get this "Warning: Potential Security Risk Ahead" error ( Error code: SSL_ERROR_BAD_CERT_DOMAIN ). It's been like this for a couple of weeks for me so it looks really strange that the USPS has fixed it after all this time.
I tried the same URL[1] in Konqueror and it also complains about the bad certificate.

Any ideas? Thanks


1 .https://tools.usps.com/go/TrackConfirmAction_input?origTrackNum=1234567890

[toc] | [next] | [standalone]


#243644

FromRoberto C. Sánchez <roberto@debian.org>
Date2022-01-03 23:20 +0100
Message-ID<DBDQl-5t1-1@gated-at.bofh.it>
In reply to#243643
On Mon, Jan 03, 2022 at 11:01:34PM +0100, local10 wrote:
> Hi,
> 
> Am I the only one who's getting this error? When I go to the USPS.com[1] to track a package I get this "Warning: Potential Security Risk Ahead" error ( Error code: SSL_ERROR_BAD_CERT_DOMAIN ). It's been like this for a couple of weeks for me so it looks really strange that the USPS has fixed it after all this time.
> I tried the same URL[1] in Konqueror and it also complains about the bad certificate.
> 
> Any ideas? Thanks
> 

The site works fine for me.

In FF, click on 'SSL_ERROR_BAD_CERT_DOMAIN', which should take you to
the full error output.  Then click 'Copy text to clipboard' and paste
the full text into an email.  Someone on the list ought to be able to
help diagnose further from there.

Regards,

-Roberto

-- 
Roberto C. Sánchez

[toc] | [prev] | [next] | [standalone]


#243645 — Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

Fromlocal10 <local10@tutanota.com>
Date2022-01-03 23:20 +0100
SubjectRe: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBDQl-5t1-5@gated-at.bofh.it>
In reply to#243644
Jan 3, 2022, 22:11 by roberto@debian.org:

> The site works fine for me.
>
> In FF, click on 'SSL_ERROR_BAD_CERT_DOMAIN', which should take you to
> the full error output.  Then click 'Copy text to clipboard' and paste
> the full text into an email.  Someone on the list ought to be able to
> help diagnose further from there.
>


Weird. This is what I get:


Websites prove their identity via certificates. Firefox does not trust this site because it uses a certificate that is not valid for tools.usps.com. The certificate is only valid for the following names: www.costco.ca <http://www.costco.ca>, costco.ca

Error code: SSL_ERROR_BAD_CERT_DOMAIN


https://tools.usps.com/go/TrackConfirmAction_input?origTrackNum=123456789
0

Unable to communicate securely with peer: requested domain name does not match the server’s certificate.

HTTP Strict Transport Security: false
HTTP Public Key Pinning: false

Certificate chain:

-----BEGIN CERTIFICATE-----
MIIHTjCCBjagAwIBAgIQBOyIfmSb5tyeC53E3AQoqzANBgkqhkiG9w0BAQsFADB1
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMTQwMgYDVQQDEytEaWdpQ2VydCBTSEEyIEV4dGVuZGVk
IFZhbGlkYXRpb24gU2VydmVyIENBMB4XDTIwMDQxMzAwMDAwMFoXDTIyMDcxMjEy
MDAwMFowgdsxHTAbBgNVBA8MFFByaXZhdGUgT3JnYW5pemF0aW9uMRMwEQYLKwYB
BAGCNzwCAQMTAlVTMRswGQYLKwYBBAGCNzwCAQITCldhc2hpbmd0b24xFDASBgNV
BAUTCzYwMSAwMjQgNjc0MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3Rv
bjERMA8GA1UEBxMISXNzYXF1YWgxJTAjBgNVBAoTHENvc3RjbyBXaG9sZXNhbGUg
Q29ycG9yYXRpb24xFjAUBgNVBAMTDXd3dy5jb3N0Y28uY2EwggEiMA0GCSqGSIb3
DQEBAQUAA4IBDwAwggEKAoIBAQDaZN4KpbA4DhbWw+TT9c8mNUPeVKsYaysqMKJK
jVUKCx4DfAa1xWdR3l/DcMfuA3oTfFhf1X9tpL7hcCQN+jr/WKKTR9usHzjFzP1O
Q8QXPza0HjOaQbLwlO6MMrLfO/R5p1D2dhTAnGneL0ZR03DoqLIPqJT/aBEvQC2C
D5wxtm1TbooHuQ3OeUW8kOp/UY/+mT3uuf1LBz5EdjJ8A0Kc5FX6Lo54vK5Jty4X
VWASsj8W5DkLVL5k6zMUpRqKx9LEb1mYnKxYcTUQetCRBVo3zv7QUb+xNjhwEIiB
qe8g7pFgTW5FORITPoeWLCS68YwxZ/DJ7jYnouQludCKEsaPAgMBAAGjggNxMIID
bTAfBgNVHSMEGDAWgBQ901Cl1qCt7vNKYApl0yHU+PjWDzAdBgNVHQ4EFgQU34QV
E4cZWcbn/7IWLK0nuAzCU9YwIwYDVR0RBBwwGoINd3d3LmNvc3Rjby5jYYIJY29z
dGNvLmNhMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYB
BQUHAwIwdQYDVR0fBG4wbDA0oDKgMIYuaHR0cDovL2NybDMuZGlnaWNlcnQuY29t
L3NoYTItZXYtc2VydmVyLWcyLmNybDA0oDKgMIYuaHR0cDovL2NybDQuZGlnaWNl
cnQuY29tL3NoYTItZXYtc2VydmVyLWcyLmNybDBLBgNVHSAERDBCMDcGCWCGSAGG
/WwCATAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BT
MAcGBWeBDAEBMIGIBggrBgEFBQcBAQR8MHowJAYIKwYBBQUHMAGGGGh0dHA6Ly9v
Y3NwLmRpZ2ljZXJ0LmNvbTBSBggrBgEFBQcwAoZGaHR0cDovL2NhY2VydHMuZGln
aWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkV4dGVuZGVkVmFsaWRhdGlvblNlcnZlckNB
LmNydDAJBgNVHRMEAjAAMIIBewYKKwYBBAHWeQIEAgSCAWsEggFnAWUAdQCkuQmQ
tBhYFIe7E6LMZ3AKPDWYBPkb37jjd80OyA3cEAAAAXF1Ht6gAAAEAwBGMEQCIDR/
YSEr0iSj2uKBMQuc3YmvbFjlwH2+uEmd6NNbi9wGAiBTrfdlBpZJN6GyKMqded5g
yCxxgCV4jUtLQiw7vBUN2gB1AFYUBpov18Ls0/XhvUSyPsdGdrm8mRFcwO+UmFXW
idDdAAABcXUe3vcAAAQDAEYwRAIgJKh7x+t4g47X35aah89yser+f77yFRGzp9sj
6WryR2sCIHOa8cSDFzjBwPp3vTHAse1lJO4QGPtg/NXXfk4Veb75AHUAu9nfvB+K
cbWTlCOXqpJ7RzhXlQqrUugakJZkNo4e0YUAAAFxdR7etQAABAMARjBEAiBqwSAH
8sKPb4Y818r3AtnliGWrGhqgtZ0GEZWyDGf+eAIgYYVrZ8xAfrWu83TLSHemxk1E
XvOQ9k8JJHyjVRmOxpQwDQYJKoZIhvcNAQELBQADggEBAGjuhZ9ypCuzqFPHmafF
8tSty5Fb/LsQQ5i6O2A8lgG33WinpVjYbmDvlCl3vEsdkEvarGjCihJgTsb0RwZs
cNBkoFr+kNiR4lm/YnhtAd0qv8+uLJzZ1i9MmhcKuOSTgIKw368Kh0i9C3xDlsPU
jxK1rASaJxAuYBNWcPsnrO/BipRlpK8DG6XlNIUn8PzsuTVNOVf+kjdoM0rAHhVG
kagbhBbKJFLSOqLAZiXgc954wy9VIkEUHOd6Z3asMamTFSyC7wPj6rD3tkGwKKc0
NQO6pYEvkXJRJeieYtla+a+Luly3Nxi8yHWDl98N6sqKgitjCBScs4bWaILw54E3
S1c=
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEtjCCA56gAwIBAgIQDHmpRLCMEZUgkmFf4msdgzANBgkqhkiG9w0BAQsFADBs
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
d3cuZGlnaWNlcnQuY29tMSswKQYDVQQDEyJEaWdpQ2VydCBIaWdoIEFzc3VyYW5j
ZSBFViBSb290IENBMB4XDTEzMTAyMjEyMDAwMFoXDTI4MTAyMjEyMDAwMFowdTEL
MAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
LmRpZ2ljZXJ0LmNvbTE0MDIGA1UEAxMrRGlnaUNlcnQgU0hBMiBFeHRlbmRlZCBW
YWxpZGF0aW9uIFNlcnZlciBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBANdTpARR+JmmFkhLZyeqk0nQOe0MsLAAh/FnKIaFjI5j2ryxQDji0/XspQUY
uD0+xZkXMuwYjPrxDKZkIYXLBxA0sFKIKx9om9KxjxKws9LniB8f7zh3VFNfgHk/
LhqqqB5LKw2rt2O5Nbd9FLxZS99RStKh4gzikIKHaq7q12TWmFXo/a8aUGxUvBHy
/Urynbt/DvTVvo4WiRJV2MBxNO723C3sxIclho3YIeSwTQyJ3DkmF93215SF2AQh
cJ1vb/9cuhnhRctWVyh+HA1BV6q3uCe7seT6Ku8hI3UarS2bhjWMnHe1c63YlC3k
8wyd7sFOYn4XwHGeLN7x+RAoGTMCAwEAAaOCAUkwggFFMBIGA1UdEwEB/wQIMAYB
Af8CAQAwDgYDVR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF
BQcDAjA0BggrBgEFBQcBAQQoMCYwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRp
Z2ljZXJ0LmNvbTBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8vY3JsNC5kaWdpY2Vy
dC5jb20vRGlnaUNlcnRIaWdoQXNzdXJhbmNlRVZSb290Q0EuY3JsMD0GA1UdIAQ2
MDQwMgYEVR0gADAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5j
b20vQ1BTMB0GA1UdDgQWBBQ901Cl1qCt7vNKYApl0yHU+PjWDzAfBgNVHSMEGDAW
gBSxPsNpA/i/RwHUmCYaCALvY2QrwzANBgkqhkiG9w0BAQsFAAOCAQEAnbbQkIbh
hgLtxaDwNBx0wY12zIYKqPBKikLWP8ipTa18CK3mtlC4ohpNiAexKSHc59rGPCHg
4xFJcKx6HQGkyhE6V6t9VypAdP3THYUYUN9XR3WhfVUgLkc3UHKMf4Ib0mKPLQNa
2sPIoc4sUqIAY+tzunHISScjl2SFnjgOrWNoPLpSgVh5oywM395t6zHyuqB8bPEs
1OG9d4Q3A84ytciagRpKkk47RpqF/oOi+Z6Mo8wNXrM9zwR4jxQUezKcxwCmXMS1
oVWNWlZopCJwqjyBcdmdqEU79OX2olHdx3ti6G8MdOu42vi/hw15UJGQmxg7kVkn
8TUoE6smftX3eg==
-----END CERTIFICATE-----

[toc] | [prev] | [next] | [standalone]


#243647

FromMark Allums <maa@allums.com>
Date2022-01-03 23:40 +0100
Message-ID<DBE9I-5zH-7@gated-at.bofh.it>
In reply to#243645
Did you click on a phishing link?

Mark Allums



On 1/3/22 16:16, local10 wrote:
> Jan 3, 2022, 22:11 by roberto@debian.org:
>
>> The site works fine for me.
>>
>> In FF, click on 'SSL_ERROR_BAD_CERT_DOMAIN', which should take you to
>> the full error output.  Then click 'Copy text to clipboard' and paste
>> the full text into an email.  Someone on the list ought to be able to
>> help diagnose further from there.
>>
>
> Weird. This is what I get:
>
>
> Websites prove their identity via certificates. Firefox does not trust this site because it uses a certificate that is not valid for tools.usps.com. The certificate is only valid for the following names: www.costco.ca <http://www.costco.ca>, costco.ca
>
> Error code: SSL_ERROR_BAD_CERT_DOMAIN
>
>
> https://tools.usps.com/go/TrackConfirmAction_input?origTrackNum=1234567890
>
> Unable to communicate securely with peer: requested domain name does not match the server’s certificate.
>
> HTTP Strict Transport Security: false
> HTTP Public Key Pinning: false
>
> Certificate chain:
>
> -----BEGIN CERTIFICATE-----
> MIIHTjCCBjagAwIBAgIQBOyIfmSb5tyeC53E3AQoqzANBgkqhkiG9w0BAQsFADB1
> MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
> d3cuZGlnaWNlcnQuY29tMTQwMgYDVQQDEytEaWdpQ2VydCBTSEEyIEV4dGVuZGVk
> IFZhbGlkYXRpb24gU2VydmVyIENBMB4XDTIwMDQxMzAwMDAwMFoXDTIyMDcxMjEy
> MDAwMFowgdsxHTAbBgNVBA8MFFByaXZhdGUgT3JnYW5pemF0aW9uMRMwEQYLKwYB
> BAGCNzwCAQMTAlVTMRswGQYLKwYBBAGCNzwCAQITCldhc2hpbmd0b24xFDASBgNV
> BAUTCzYwMSAwMjQgNjc0MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3Rv
> bjERMA8GA1UEBxMISXNzYXF1YWgxJTAjBgNVBAoTHENvc3RjbyBXaG9sZXNhbGUg
> Q29ycG9yYXRpb24xFjAUBgNVBAMTDXd3dy5jb3N0Y28uY2EwggEiMA0GCSqGSIb3
> DQEBAQUAA4IBDwAwggEKAoIBAQDaZN4KpbA4DhbWw+TT9c8mNUPeVKsYaysqMKJK
> jVUKCx4DfAa1xWdR3l/DcMfuA3oTfFhf1X9tpL7hcCQN+jr/WKKTR9usHzjFzP1O
> Q8QXPza0HjOaQbLwlO6MMrLfO/R5p1D2dhTAnGneL0ZR03DoqLIPqJT/aBEvQC2C
> D5wxtm1TbooHuQ3OeUW8kOp/UY/+mT3uuf1LBz5EdjJ8A0Kc5FX6Lo54vK5Jty4X
> VWASsj8W5DkLVL5k6zMUpRqKx9LEb1mYnKxYcTUQetCRBVo3zv7QUb+xNjhwEIiB
> qe8g7pFgTW5FORITPoeWLCS68YwxZ/DJ7jYnouQludCKEsaPAgMBAAGjggNxMIID
> bTAfBgNVHSMEGDAWgBQ901Cl1qCt7vNKYApl0yHU+PjWDzAdBgNVHQ4EFgQU34QV
> E4cZWcbn/7IWLK0nuAzCU9YwIwYDVR0RBBwwGoINd3d3LmNvc3Rjby5jYYIJY29z
> dGNvLmNhMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYB
> BQUHAwIwdQYDVR0fBG4wbDA0oDKgMIYuaHR0cDovL2NybDMuZGlnaWNlcnQuY29t
> L3NoYTItZXYtc2VydmVyLWcyLmNybDA0oDKgMIYuaHR0cDovL2NybDQuZGlnaWNl
> cnQuY29tL3NoYTItZXYtc2VydmVyLWcyLmNybDBLBgNVHSAERDBCMDcGCWCGSAGG
> /WwCATAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BT
> MAcGBWeBDAEBMIGIBggrBgEFBQcBAQR8MHowJAYIKwYBBQUHMAGGGGh0dHA6Ly9v
> Y3NwLmRpZ2ljZXJ0LmNvbTBSBggrBgEFBQcwAoZGaHR0cDovL2NhY2VydHMuZGln
> aWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkV4dGVuZGVkVmFsaWRhdGlvblNlcnZlckNB
> LmNydDAJBgNVHRMEAjAAMIIBewYKKwYBBAHWeQIEAgSCAWsEggFnAWUAdQCkuQmQ
> tBhYFIe7E6LMZ3AKPDWYBPkb37jjd80OyA3cEAAAAXF1Ht6gAAAEAwBGMEQCIDR/
> YSEr0iSj2uKBMQuc3YmvbFjlwH2+uEmd6NNbi9wGAiBTrfdlBpZJN6GyKMqded5g
> yCxxgCV4jUtLQiw7vBUN2gB1AFYUBpov18Ls0/XhvUSyPsdGdrm8mRFcwO+UmFXW
> idDdAAABcXUe3vcAAAQDAEYwRAIgJKh7x+t4g47X35aah89yser+f77yFRGzp9sj
> 6WryR2sCIHOa8cSDFzjBwPp3vTHAse1lJO4QGPtg/NXXfk4Veb75AHUAu9nfvB+K
> cbWTlCOXqpJ7RzhXlQqrUugakJZkNo4e0YUAAAFxdR7etQAABAMARjBEAiBqwSAH
> 8sKPb4Y818r3AtnliGWrGhqgtZ0GEZWyDGf+eAIgYYVrZ8xAfrWu83TLSHemxk1E
> XvOQ9k8JJHyjVRmOxpQwDQYJKoZIhvcNAQELBQADggEBAGjuhZ9ypCuzqFPHmafF
> 8tSty5Fb/LsQQ5i6O2A8lgG33WinpVjYbmDvlCl3vEsdkEvarGjCihJgTsb0RwZs
> cNBkoFr+kNiR4lm/YnhtAd0qv8+uLJzZ1i9MmhcKuOSTgIKw368Kh0i9C3xDlsPU
> jxK1rASaJxAuYBNWcPsnrO/BipRlpK8DG6XlNIUn8PzsuTVNOVf+kjdoM0rAHhVG
> kagbhBbKJFLSOqLAZiXgc954wy9VIkEUHOd6Z3asMamTFSyC7wPj6rD3tkGwKKc0
> NQO6pYEvkXJRJeieYtla+a+Luly3Nxi8yHWDl98N6sqKgitjCBScs4bWaILw54E3
> S1c=
> -----END CERTIFICATE-----
> -----BEGIN CERTIFICATE-----
> MIIEtjCCA56gAwIBAgIQDHmpRLCMEZUgkmFf4msdgzANBgkqhkiG9w0BAQsFADBs
> MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
> d3cuZGlnaWNlcnQuY29tMSswKQYDVQQDEyJEaWdpQ2VydCBIaWdoIEFzc3VyYW5j
> ZSBFViBSb290IENBMB4XDTEzMTAyMjEyMDAwMFoXDTI4MTAyMjEyMDAwMFowdTEL
> MAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3
> LmRpZ2ljZXJ0LmNvbTE0MDIGA1UEAxMrRGlnaUNlcnQgU0hBMiBFeHRlbmRlZCBW
> YWxpZGF0aW9uIFNlcnZlciBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
> ggEBANdTpARR+JmmFkhLZyeqk0nQOe0MsLAAh/FnKIaFjI5j2ryxQDji0/XspQUY
> uD0+xZkXMuwYjPrxDKZkIYXLBxA0sFKIKx9om9KxjxKws9LniB8f7zh3VFNfgHk/
> LhqqqB5LKw2rt2O5Nbd9FLxZS99RStKh4gzikIKHaq7q12TWmFXo/a8aUGxUvBHy
> /Urynbt/DvTVvo4WiRJV2MBxNO723C3sxIclho3YIeSwTQyJ3DkmF93215SF2AQh
> cJ1vb/9cuhnhRctWVyh+HA1BV6q3uCe7seT6Ku8hI3UarS2bhjWMnHe1c63YlC3k
> 8wyd7sFOYn4XwHGeLN7x+RAoGTMCAwEAAaOCAUkwggFFMBIGA1UdEwEB/wQIMAYB
> Af8CAQAwDgYDVR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF
> BQcDAjA0BggrBgEFBQcBAQQoMCYwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRp
> Z2ljZXJ0LmNvbTBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8vY3JsNC5kaWdpY2Vy
> dC5jb20vRGlnaUNlcnRIaWdoQXNzdXJhbmNlRVZSb290Q0EuY3JsMD0GA1UdIAQ2
> MDQwMgYEVR0gADAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5j
> b20vQ1BTMB0GA1UdDgQWBBQ901Cl1qCt7vNKYApl0yHU+PjWDzAfBgNVHSMEGDAW
> gBSxPsNpA/i/RwHUmCYaCALvY2QrwzANBgkqhkiG9w0BAQsFAAOCAQEAnbbQkIbh
> hgLtxaDwNBx0wY12zIYKqPBKikLWP8ipTa18CK3mtlC4ohpNiAexKSHc59rGPCHg
> 4xFJcKx6HQGkyhE6V6t9VypAdP3THYUYUN9XR3WhfVUgLkc3UHKMf4Ib0mKPLQNa
> 2sPIoc4sUqIAY+tzunHISScjl2SFnjgOrWNoPLpSgVh5oywM395t6zHyuqB8bPEs
> 1OG9d4Q3A84ytciagRpKkk47RpqF/oOi+Z6Mo8wNXrM9zwR4jxQUezKcxwCmXMS1
> oVWNWlZopCJwqjyBcdmdqEU79OX2olHdx3ti6G8MdOu42vi/hw15UJGQmxg7kVkn
> 8TUoE6smftX3eg==
> -----END CERTIFICATE-----
>

[toc] | [prev] | [next] | [standalone]


#243651 — Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

Fromlocal10 <local10@tutanota.com>
Date2022-01-03 23:50 +0100
SubjectRe: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBEjo-5DJ-11@gated-at.bofh.it>
In reply to#243647
Jan 3, 2022, 22:30 by maa@allums.com:

> Did you click on a phishing link?
>
> Mark Allums
>

No, I have some USPS.com tracking links bookmarked and they were working fine until about two weeks ago. Could it be perhaps related to the Firefox upgrade from 78esr to 91esr?

Regards,

[toc] | [prev] | [next] | [standalone]


#243650 — Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

Fromlocal10 <local10@tutanota.com>
Date2022-01-03 23:50 +0100
SubjectRe: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBEjo-5DJ-7@gated-at.bofh.it>
In reply to#243645
Jan 3, 2022, 22:29 by dsr@randomstring.org:

> Costco is definitely not the US Postal Service.
>

No argument here.


> flush caches. Restart Firefox. Check your net connection.
>

I've done this a number of times. The connection is direct, no proxy.

Regards,

[toc] | [prev] | [next] | [standalone]


#243653

FromDan Ritter <dsr@randomstring.org>
Date2022-01-04 00:30 +0100
Message-ID<DBEW5-662-1@gated-at.bofh.it>
In reply to#243650
local10 wrote: 
> Jan 3, 2022, 22:29 by dsr@randomstring.org:
> 
> > Costco is definitely not the US Postal Service.
> >
> 
> No argument here.
> 
> 
> > flush caches. Restart Firefox. Check your net connection.
> >
> 
> I've done this a number of times. The connection is direct, no proxy.

Alright. Put this into your /etc/hosts temporarily:

152.195.33.23  www.usps.com tools.usps.com www.usps.gov

That's unlikely to be an optimal IP from their CDN, but it is
currently working.

Oh. Are you using DNS-over-HTTPS? 

https://support.mozilla.org/en-US/kb/firefox-dns-over-https

-dsr-

[toc] | [prev] | [next] | [standalone]


#243659 — Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

Fromlocal10 <local10@tutanota.com>
Date2022-01-04 01:00 +0100
SubjectRe: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBFp7-6fB-1@gated-at.bofh.it>
In reply to#243650
Jan 3, 2022, 23:08 by dsr@randomstring.org:

> Alright. Put this into your /etc/hosts temporarily:
>
> 152.195.33.23  www.usps.com tools.usps.com www.usps.gov
>
> That's unlikely to be an optimal IP from their CDN, but it is
> currently working.
>

That fixed it, I got the USPS tracking page to load normally. Still not why it worked as tools.usps.com resolves for me to 152.195.33.23:

# dig tools.usps.com

; <<>> DiG 9.16.22-Debian <<>> tools.usps.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 45738
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
; COOKIE: 77e474050843f63a0100000061d38b021b182f925c475f14 (good)
;; QUESTION SECTION:
;tools.usps.com.                        IN      A

;; ANSWER SECTION:
tools.usps.com.         42      IN      CNAME   cs1799.wpc.upsiloncdn.net.
cs1799.wpc.upsiloncdn.net. 2078 IN      A       152.195.33.23

;; Query time: 0 msec
;; SERVER: 127.0.0.1#53(127.0.0.1)
;; WHEN: Mon Jan 03 18:47:14 EST 2022
;; MSG SIZE  rcvd: 126




> Oh. Are you using DNS-over-HTTPS? 
>

I used to but I have disabled it for now. Even with DNS-over-HTTPS disabled I was getting the certificate error until I put 152.195.33.23 into the /etc/hosts.


Regards,

[toc] | [prev] | [next] | [standalone]


#243662 — [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

Fromlocal10 <local10@tutanota.com>
Date2022-01-04 01:10 +0100
Subject[SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBFyN-6yp-3@gated-at.bofh.it>
In reply to#243650
Jan 3, 2022, 23:53 by local10@tutanota.com:

> Jan 3, 2022, 23:08 by dsr@randomstring.org:
>
>> Alright. Put this into your /etc/hosts temporarily:
>>
>> 152.195.33.23  www.usps.com tools.usps.com www.usps.gov
>>
>> That's unlikely to be an optimal IP from their CDN, but it is
>> currently working.
>>
>
> That fixed it, I got the USPS tracking page to load normally. Still not sure why it worked as tools.usps.com resolves for me to 152.195.33.23:
>
> # dig tools.usps.com
> ...
> ....
> ;; ANSWER SECTION:
> tools.usps.com.         42      IN      CNAME   cs1799.wpc.upsiloncdn.net.
> cs1799.wpc.upsiloncdn.net. 2078 IN      A       152.195.33.23
>

OK, I understand now what the problem was. Quite a while ago I added a line into the /etc/hosts to fix a temp DNS issue and completely forgot about it. So while DNS server was correctly resolving tools.usps.com to 152.195.33.23, my previous /etc/hosts entry was overriding it to 23.217.162.158 which was causing the certificate issue.

Thanks to everyone who responded.

[toc] | [prev] | [next] | [standalone]


#243689 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

FromMichael Stone <mstone@debian.org>
Date2022-01-04 19:20 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBWzE-b4-13@gated-at.bofh.it>
In reply to#243662
On Tue, Jan 04, 2022 at 01:09:06AM +0100, local10 wrote:
>> Jan 3, 2022, 23:08 by dsr@randomstring.org:
>>> Alright. Put this into your /etc/hosts temporarily:
[...]
>OK, I understand now what the problem was. Quite a while ago I added a line into the /etc/hosts to fix a temp DNS issue and completely forgot about it. So while DNS server was correctly resolving tools.usps.com to 152.195.33.23, my previous /etc/hosts entry was overriding it to 23.217.162.158 which was causing the certificate issue.

And this is why putting stuff into /etc/hosts is basically never the 
right answer. :)

[toc] | [prev] | [next] | [standalone]


#243691 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

From"James H. H. Lampert" <jamesl@touchtonecorp.com>
Date2022-01-04 19:40 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBWSZ-hr-11@gated-at.bofh.it>
In reply to#243689
On 1/4/22 10:19 AM, Michael Stone wrote:
> And this is why putting stuff into /etc/hosts is basically never the 
> right answer. :)

Au contraire!

Among other things, the host table is the best possible place to block 
access to certain unwanted domains. For example, if you add these entries:

 > 0.0.0.0         facebook.com
 > 0.0.0.0         www.facebook.com
 > 0.0.0.0         hi-in.facebook.com
 > 0.0.0.0         gl-es.facebook.com
 > 0.0.0.0         twitter.com
 > 0.0.0.0         www.twitter.com

you can never be tricked into accessing Facebook or Twitter (for me, 
ONCE is far too many times), and if you add

 > 0.0.0.0         bing.com

then bing-redirections will fail every time (and alert you to their 
noisome and  all-too-common presence).

And likewise, you might want to access other machines within your LAN by 
name, but your operation is not big enough to warrant bothering with an 
internal DNS, or you might need to access outside systems that, for 
various perfectly legitimate reasons, are kept off the public DNS.

--
JHHL

[toc] | [prev] | [next] | [standalone]


#243692 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

From<tomas@tuxteam.de>
Date2022-01-04 19:40 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBWT0-hr-21@gated-at.bofh.it>
In reply to#243691

[Multipart message — attachments visible in raw view] — view raw

On Tue, Jan 04, 2022 at 10:34:48AM -0800, James H. H. Lampert wrote:
> On 1/4/22 10:19 AM, Michael Stone wrote:
> > And this is why putting stuff into /etc/hosts is basically never the
> > right answer. :)
> 
> Au contraire!
> 
> Among other things, the host table is the best possible place to block
> access to certain unwanted domains. For example, if you add these entries:
> 
> > 0.0.0.0         facebook.com

[...]

Oh, great minds think alike :)

I put them to 127.0.0.1, because then I can see them hitting the wall in
my local web server logs ;-)

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#243700 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

FromMichael Stone <mstone@debian.org>
Date2022-01-04 21:30 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBYBr-1mI-3@gated-at.bofh.it>
In reply to#243691
On Tue, Jan 04, 2022 at 10:34:48AM -0800, James H. H. Lampert wrote:
>On 1/4/22 10:19 AM, Michael Stone wrote:
>>And this is why putting stuff into /etc/hosts is basically never the 
>>right answer. :)
>
>Au contraire!
>
>Among other things, the host table is the best possible place to block 
>access to certain unwanted domains

Not really, but it certainly is something that people do.

[toc] | [prev] | [next] | [standalone]


#243693 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

From<tomas@tuxteam.de>
Date2022-01-04 19:40 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBWT0-hr-25@gated-at.bofh.it>
In reply to#243689

[Multipart message — attachments visible in raw view] — view raw

On Tue, Jan 04, 2022 at 01:19:37PM -0500, Michael Stone wrote:

[...]

> And this is why putting stuff into /etc/hosts is basically never the right
> answer. :)

Eye, beholder and things. I've got a couple of them like so:

  # Pest:
  127.0.0.1 www.google-analytics.com
  127.0.0.1 ajax.google.com
  127.0.0.1 ad.doublecklick.net
  127.0.0.1 www.gstatic.com
  ...

Yeah, some things stop working then. I want them to :)

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#243695 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2022-01-04 20:40 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBXP3-QH-9@gated-at.bofh.it>
In reply to#243693
On Tue 04 Jan 2022 at 19:37:34 (+0100), tomas@tuxteam.de wrote:
> On Tue, Jan 04, 2022 at 01:19:37PM -0500, Michael Stone wrote:
> 
> [...]
> 
> > And this is why putting stuff into /etc/hosts is basically never the right
> > answer. :)
> 
> Eye, beholder and things. I've got a couple of them like so:
> 
>   # Pest:
>   127.0.0.1 www.google-analytics.com
>   127.0.0.1 ajax.google.com
>   127.0.0.1 ad.doublecklick.net
>   127.0.0.1 www.gstatic.com
>   ...
> 
> Yeah, some things stop working then. I want them to :)

Agreed. I append a list of close to 14,000 addresses (including
comments) to the end of my own local /etc/hosts. I see very
few adverts. In fact, I was quite shocked when I just tried
DNS over HTTPS for a couple of minutes. The 10-day weather
profile that I screenshoot every day was plastered in popups.

Anyone know how to combine DoH with resolving 14,000 addresses
to 127.0.0.1? Also, does that mean that DoH attempts to resolve
my local hosts before consulting /etc/hosts? I didn't stick
around DoH long enough to find out.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#243698 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

From<tomas@tuxteam.de>
Date2022-01-04 21:00 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBY8q-XI-9@gated-at.bofh.it>
In reply to#243695

[Multipart message — attachments visible in raw view] — view raw

On Tue, Jan 04, 2022 at 01:33:18PM -0600, David Wright wrote:
> On Tue 04 Jan 2022 at 19:37:34 (+0100), tomas@tuxteam.de wrote:
> > On Tue, Jan 04, 2022 at 01:19:37PM -0500, Michael Stone wrote:
> > 
> > [...]
> > 
> > > And this is why putting stuff into /etc/hosts is basically never the right
> > > answer. :)
> > 
> > Eye, beholder and things. I've got a couple of them like so:
> > 
> >   # Pest:
> >   127.0.0.1 www.google-analytics.com
> >   127.0.0.1 ajax.google.com
> >   127.0.0.1 ad.doublecklick.net
> >   127.0.0.1 www.gstatic.com
> >   ...
> > 
> > Yeah, some things stop working then. I want them to :)
> 
> Agreed. I append a list of close to 14,000 addresses (including
> comments) to the end of my own local /etc/hosts. I see very
> few adverts. In fact, I was quite shocked when I just tried
> DNS over HTTPS for a couple of minutes. The 10-day weather
> profile that I screenshoot every day was plastered in popups.
> 
> Anyone know how to combine DoH with resolving 14,000 addresses
> to 127.0.0.1? Also, does that mean that DoH attempts to resolve
> my local hosts before consulting /etc/hosts? I didn't stick
> around DoH long enough to find out.

No idea. I'd hope for it to be overridable, but I've been disappointed
by browsers (yes, firefox, I'm looking at you!) before.

The day it ain't a choice anymore will be the day I hide behind a proxy
*I* trust and control. That one can then look up things in /etc/hosts.
(Yes, that means some bricolage with trusted root CAs. So be it.)

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#243701 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

FromCelejar <celejar@gmail.com>
Date2022-01-04 22:10 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DBZe9-1P7-5@gated-at.bofh.it>
In reply to#243698
On Tue, 4 Jan 2022 20:58:27 +0100
<tomas@tuxteam.de> wrote:

> On Tue, Jan 04, 2022 at 01:33:18PM -0600, David Wright wrote:
> > On Tue 04 Jan 2022 at 19:37:34 (+0100), tomas@tuxteam.de wrote:
> > > On Tue, Jan 04, 2022 at 01:19:37PM -0500, Michael Stone wrote:
> > > 
> > > [...]
> > > 
> > > > And this is why putting stuff into /etc/hosts is basically never the right
> > > > answer. :)
> > > 
> > > Eye, beholder and things. I've got a couple of them like so:
> > > 
> > >   # Pest:
> > >   127.0.0.1 www.google-analytics.com
> > >   127.0.0.1 ajax.google.com
> > >   127.0.0.1 ad.doublecklick.net
> > >   127.0.0.1 www.gstatic.com
> > >   ...
> > > 
> > > Yeah, some things stop working then. I want them to :)
> > 
> > Agreed. I append a list of close to 14,000 addresses (including
> > comments) to the end of my own local /etc/hosts. I see very
> > few adverts. In fact, I was quite shocked when I just tried
> > DNS over HTTPS for a couple of minutes. The 10-day weather
> > profile that I screenshoot every day was plastered in popups.
> > 
> > Anyone know how to combine DoH with resolving 14,000 addresses
> > to 127.0.0.1? Also, does that mean that DoH attempts to resolve
> > my local hosts before consulting /etc/hosts? I didn't stick
> > around DoH long enough to find out.
> 
> No idea. I'd hope for it to be overridable, but I've been disappointed
> by browsers (yes, firefox, I'm looking at you!) before.

One way "to combine DoH with resolving 14,000 addresses to 127.0.0.1"
is by using Pi-hole. Some people have *millions* of domains blacklisted
in Pi-hole:

https://www.reddit.com/r/pihole/comments/rrcmfk/why_am_i_making_a_personal_commitment_to_donating/
https://www.reddit.com/r/pihole/comments/7rzdzj/how_many_domains_do_you_have_on_your_setup/
https://www.reddit.com/r/pihole/comments/hkfyu4/domains_on_blocklist/

etc.

and using DoH with Pi-hole is well documented:

https://docs.pi-hole.net/guides/dns/cloudflared/
https://medium.com/codex/pi-hole-and-doh-f1a9f8acd0f7
https://github.com/devopsleigh/pihole

Celejar

[toc] | [prev] | [next] | [standalone]


#243706 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

From<tomas@tuxteam.de>
Date2022-01-05 06:20 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DC6Sm-6vm-7@gated-at.bofh.it>
In reply to#243701

[Multipart message — attachments visible in raw view] — view raw

On Tue, Jan 04, 2022 at 04:05:11PM -0500, Celejar wrote:

[...]

> One way "to combine DoH with resolving 14,000 addresses to 127.0.0.1"
> is by using Pi-hole. Some people have *millions* of domains blacklisted
> in Pi-hole:

Pi-hole won't help unles it also does HTTPS proxying (that means it
would have to play MITM). As far as I know it "just" does conventional
DNS proxying (which is a great thing to do, mind you).

But hey, full HTTP(S) proxying would be a great thing to do. Still,
you'd have to munge your browser's trusted certs for that trick to work.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#243710 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

FromCelejar <celejar@gmail.com>
Date2022-01-05 14:50 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DCePU-3a1-3@gated-at.bofh.it>
In reply to#243706
On Wed, 5 Jan 2022 06:10:48 +0100
<tomas@tuxteam.de> wrote:

> On Tue, Jan 04, 2022 at 04:05:11PM -0500, Celejar wrote:
> 
> [...]
> 
> > One way "to combine DoH with resolving 14,000 addresses to 127.0.0.1"
> > is by using Pi-hole. Some people have *millions* of domains blacklisted
> > in Pi-hole:
> 
> Pi-hole won't help unles it also does HTTPS proxying (that means it
> would have to play MITM). As far as I know it "just" does conventional
> DNS proxying (which is a great thing to do, mind you).

Why won't it help? What won't it help with? If you mean that the
queries won't be secure during the leg between the client and
the Pi-hole, we're talking about running Pi-hole within one's trusted
network (or connecting to it over a VPN, etc.)
> 
> But hey, full HTTP(S) proxying would be a great thing to do. Still,
> you'd have to munge your browser's trusted certs for that trick to work.

Celejar

[toc] | [prev] | [next] | [standalone]


#243729 — Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com

From<tomas@tuxteam.de>
Date2022-01-05 18:30 +0100
SubjectRe: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com
Message-ID<DCigN-5pq-3@gated-at.bofh.it>
In reply to#243710

[Multipart message — attachments visible in raw view] — view raw

On Wed, Jan 05, 2022 at 08:43:23AM -0500, Celejar wrote:
> On Wed, 5 Jan 2022 06:10:48 +0100
> <tomas@tuxteam.de> wrote:
> 
> > On Tue, Jan 04, 2022 at 04:05:11PM -0500, Celejar wrote:
> > 
> > [...]
> > 
> > > One way "to combine DoH with resolving 14,000 addresses to 127.0.0.1"
> > > is by using Pi-hole. Some people have *millions* of domains blacklisted
> > > in Pi-hole:
> > 
> > Pi-hole won't help unles it also does HTTPS proxying (that means it
> > would have to play MITM). As far as I know it "just" does conventional
> > DNS proxying (which is a great thing to do, mind you).
> 
> Why won't it help? What won't it help with?

(See also Dan's response: it seems that a compliant DoH client first
sends a local DNS request first, so you might have a handle through
this)

With this caveat: how would you intercept a DNS request over HTTPS if
not by proxying HTTPS traffic? And that is exactly what MITM means.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web