Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #243643 > unrolled thread
| Started by | local10 <local10@tutanota.com> |
|---|---|
| First post | 2022-01-03 23:10 +0100 |
| Last post | 2022-01-04 16:30 +0100 |
| Articles | 20 on this page of 42 — 13 participants |
Back to article view | Back to linux.debian.user
Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:10 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Roberto C. Sánchez <roberto@debian.org> - 2022-01-03 23:20 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:20 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Mark Allums <maa@allums.com> - 2022-01-03 23:40 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-04 00:30 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-04 01:00 +0100
[SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-04 01:10 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Michael Stone <mstone@debian.org> - 2022-01-04 19:20 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2022-01-04 19:40 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-04 19:40 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Michael Stone <mstone@debian.org> - 2022-01-04 21:30 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-04 19:40 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com David Wright <deblis@lionunicorn.co.uk> - 2022-01-04 20:40 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-04 21:00 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Celejar <celejar@gmail.com> - 2022-01-04 22:10 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-05 06:20 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 14:50 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-05 18:30 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 18:50 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-05 19:50 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Celejar <celejar@gmail.com> - 2022-01-05 22:00 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2022-01-04 21:00 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-04 22:30 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-05 06:20 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-05 13:50 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-04 19:50 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Dan Ritter <dsr@randomstring.org> - 2022-01-03 23:50 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-03 23:50 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Charles Curley <charlescurley@charlescurley.com> - 2022-01-03 23:40 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-03 23:50 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-04 00:30 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-04 00:40 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com Jeremy Ardley <jeremy@ardley.org> - 2022-01-04 00:50 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-04 00:50 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com RP <reyadmin@gmail.com> - 2022-01-04 00:50 +0100
Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-04 07:00 +0100
[SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com local10 <local10@tutanota.com> - 2022-01-04 13:00 +0100
Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com <tomas@tuxteam.de> - 2022-01-04 13:20 +0100
GUIs (was: Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com) rhkramer@gmail.com - 2022-01-04 15:00 +0100
Re: GUIs (was: Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com) <tomas@tuxteam.de> - 2022-01-04 16:30 +0100
Page 1 of 3 [1] 2 3 Next page →
| From | local10 <local10@tutanota.com> |
|---|---|
| Date | 2022-01-03 23:10 +0100 |
| Subject | Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBDGF-5pQ-5@gated-at.bofh.it> |
Hi, Am I the only one who's getting this error? When I go to the USPS.com[1] to track a package I get this "Warning: Potential Security Risk Ahead" error ( Error code: SSL_ERROR_BAD_CERT_DOMAIN ). It's been like this for a couple of weeks for me so it looks really strange that the USPS has fixed it after all this time. I tried the same URL[1] in Konqueror and it also complains about the bad certificate. Any ideas? Thanks 1 .https://tools.usps.com/go/TrackConfirmAction_input?origTrackNum=1234567890
[toc] | [next] | [standalone]
| From | Roberto C. Sánchez <roberto@debian.org> |
|---|---|
| Date | 2022-01-03 23:20 +0100 |
| Message-ID | <DBDQl-5t1-1@gated-at.bofh.it> |
| In reply to | #243643 |
On Mon, Jan 03, 2022 at 11:01:34PM +0100, local10 wrote: > Hi, > > Am I the only one who's getting this error? When I go to the USPS.com[1] to track a package I get this "Warning: Potential Security Risk Ahead" error ( Error code: SSL_ERROR_BAD_CERT_DOMAIN ). It's been like this for a couple of weeks for me so it looks really strange that the USPS has fixed it after all this time. > I tried the same URL[1] in Konqueror and it also complains about the bad certificate. > > Any ideas? Thanks > The site works fine for me. In FF, click on 'SSL_ERROR_BAD_CERT_DOMAIN', which should take you to the full error output. Then click 'Copy text to clipboard' and paste the full text into an email. Someone on the list ought to be able to help diagnose further from there. Regards, -Roberto -- Roberto C. Sánchez
[toc] | [prev] | [next] | [standalone]
| From | local10 <local10@tutanota.com> |
|---|---|
| Date | 2022-01-03 23:20 +0100 |
| Subject | Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBDQl-5t1-5@gated-at.bofh.it> |
| In reply to | #243644 |
Jan 3, 2022, 22:11 by roberto@debian.org: > The site works fine for me. > > In FF, click on 'SSL_ERROR_BAD_CERT_DOMAIN', which should take you to > the full error output. Then click 'Copy text to clipboard' and paste > the full text into an email. Someone on the list ought to be able to > help diagnose further from there. > Weird. This is what I get: Websites prove their identity via certificates. Firefox does not trust this site because it uses a certificate that is not valid for tools.usps.com. The certificate is only valid for the following names: www.costco.ca <http://www.costco.ca>, costco.ca Error code: SSL_ERROR_BAD_CERT_DOMAIN https://tools.usps.com/go/TrackConfirmAction_input?origTrackNum=123456789 0 Unable to communicate securely with peer: requested domain name does not match the server’s certificate. HTTP Strict Transport Security: false HTTP Public Key Pinning: false Certificate chain: -----BEGIN CERTIFICATE----- MIIHTjCCBjagAwIBAgIQBOyIfmSb5tyeC53E3AQoqzANBgkqhkiG9w0BAQsFADB1 MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3 d3cuZGlnaWNlcnQuY29tMTQwMgYDVQQDEytEaWdpQ2VydCBTSEEyIEV4dGVuZGVk IFZhbGlkYXRpb24gU2VydmVyIENBMB4XDTIwMDQxMzAwMDAwMFoXDTIyMDcxMjEy MDAwMFowgdsxHTAbBgNVBA8MFFByaXZhdGUgT3JnYW5pemF0aW9uMRMwEQYLKwYB BAGCNzwCAQMTAlVTMRswGQYLKwYBBAGCNzwCAQITCldhc2hpbmd0b24xFDASBgNV BAUTCzYwMSAwMjQgNjc0MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3Rv bjERMA8GA1UEBxMISXNzYXF1YWgxJTAjBgNVBAoTHENvc3RjbyBXaG9sZXNhbGUg Q29ycG9yYXRpb24xFjAUBgNVBAMTDXd3dy5jb3N0Y28uY2EwggEiMA0GCSqGSIb3 DQEBAQUAA4IBDwAwggEKAoIBAQDaZN4KpbA4DhbWw+TT9c8mNUPeVKsYaysqMKJK jVUKCx4DfAa1xWdR3l/DcMfuA3oTfFhf1X9tpL7hcCQN+jr/WKKTR9usHzjFzP1O Q8QXPza0HjOaQbLwlO6MMrLfO/R5p1D2dhTAnGneL0ZR03DoqLIPqJT/aBEvQC2C D5wxtm1TbooHuQ3OeUW8kOp/UY/+mT3uuf1LBz5EdjJ8A0Kc5FX6Lo54vK5Jty4X VWASsj8W5DkLVL5k6zMUpRqKx9LEb1mYnKxYcTUQetCRBVo3zv7QUb+xNjhwEIiB qe8g7pFgTW5FORITPoeWLCS68YwxZ/DJ7jYnouQludCKEsaPAgMBAAGjggNxMIID bTAfBgNVHSMEGDAWgBQ901Cl1qCt7vNKYApl0yHU+PjWDzAdBgNVHQ4EFgQU34QV E4cZWcbn/7IWLK0nuAzCU9YwIwYDVR0RBBwwGoINd3d3LmNvc3Rjby5jYYIJY29z dGNvLmNhMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYB BQUHAwIwdQYDVR0fBG4wbDA0oDKgMIYuaHR0cDovL2NybDMuZGlnaWNlcnQuY29t L3NoYTItZXYtc2VydmVyLWcyLmNybDA0oDKgMIYuaHR0cDovL2NybDQuZGlnaWNl cnQuY29tL3NoYTItZXYtc2VydmVyLWcyLmNybDBLBgNVHSAERDBCMDcGCWCGSAGG /WwCATAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BT MAcGBWeBDAEBMIGIBggrBgEFBQcBAQR8MHowJAYIKwYBBQUHMAGGGGh0dHA6Ly9v Y3NwLmRpZ2ljZXJ0LmNvbTBSBggrBgEFBQcwAoZGaHR0cDovL2NhY2VydHMuZGln aWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkV4dGVuZGVkVmFsaWRhdGlvblNlcnZlckNB LmNydDAJBgNVHRMEAjAAMIIBewYKKwYBBAHWeQIEAgSCAWsEggFnAWUAdQCkuQmQ tBhYFIe7E6LMZ3AKPDWYBPkb37jjd80OyA3cEAAAAXF1Ht6gAAAEAwBGMEQCIDR/ YSEr0iSj2uKBMQuc3YmvbFjlwH2+uEmd6NNbi9wGAiBTrfdlBpZJN6GyKMqded5g yCxxgCV4jUtLQiw7vBUN2gB1AFYUBpov18Ls0/XhvUSyPsdGdrm8mRFcwO+UmFXW idDdAAABcXUe3vcAAAQDAEYwRAIgJKh7x+t4g47X35aah89yser+f77yFRGzp9sj 6WryR2sCIHOa8cSDFzjBwPp3vTHAse1lJO4QGPtg/NXXfk4Veb75AHUAu9nfvB+K cbWTlCOXqpJ7RzhXlQqrUugakJZkNo4e0YUAAAFxdR7etQAABAMARjBEAiBqwSAH 8sKPb4Y818r3AtnliGWrGhqgtZ0GEZWyDGf+eAIgYYVrZ8xAfrWu83TLSHemxk1E XvOQ9k8JJHyjVRmOxpQwDQYJKoZIhvcNAQELBQADggEBAGjuhZ9ypCuzqFPHmafF 8tSty5Fb/LsQQ5i6O2A8lgG33WinpVjYbmDvlCl3vEsdkEvarGjCihJgTsb0RwZs cNBkoFr+kNiR4lm/YnhtAd0qv8+uLJzZ1i9MmhcKuOSTgIKw368Kh0i9C3xDlsPU jxK1rASaJxAuYBNWcPsnrO/BipRlpK8DG6XlNIUn8PzsuTVNOVf+kjdoM0rAHhVG kagbhBbKJFLSOqLAZiXgc954wy9VIkEUHOd6Z3asMamTFSyC7wPj6rD3tkGwKKc0 NQO6pYEvkXJRJeieYtla+a+Luly3Nxi8yHWDl98N6sqKgitjCBScs4bWaILw54E3 S1c= -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- MIIEtjCCA56gAwIBAgIQDHmpRLCMEZUgkmFf4msdgzANBgkqhkiG9w0BAQsFADBs MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3 d3cuZGlnaWNlcnQuY29tMSswKQYDVQQDEyJEaWdpQ2VydCBIaWdoIEFzc3VyYW5j ZSBFViBSb290IENBMB4XDTEzMTAyMjEyMDAwMFoXDTI4MTAyMjEyMDAwMFowdTEL MAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3 LmRpZ2ljZXJ0LmNvbTE0MDIGA1UEAxMrRGlnaUNlcnQgU0hBMiBFeHRlbmRlZCBW YWxpZGF0aW9uIFNlcnZlciBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC ggEBANdTpARR+JmmFkhLZyeqk0nQOe0MsLAAh/FnKIaFjI5j2ryxQDji0/XspQUY uD0+xZkXMuwYjPrxDKZkIYXLBxA0sFKIKx9om9KxjxKws9LniB8f7zh3VFNfgHk/ LhqqqB5LKw2rt2O5Nbd9FLxZS99RStKh4gzikIKHaq7q12TWmFXo/a8aUGxUvBHy /Urynbt/DvTVvo4WiRJV2MBxNO723C3sxIclho3YIeSwTQyJ3DkmF93215SF2AQh cJ1vb/9cuhnhRctWVyh+HA1BV6q3uCe7seT6Ku8hI3UarS2bhjWMnHe1c63YlC3k 8wyd7sFOYn4XwHGeLN7x+RAoGTMCAwEAAaOCAUkwggFFMBIGA1UdEwEB/wQIMAYB Af8CAQAwDgYDVR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF BQcDAjA0BggrBgEFBQcBAQQoMCYwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRp Z2ljZXJ0LmNvbTBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8vY3JsNC5kaWdpY2Vy dC5jb20vRGlnaUNlcnRIaWdoQXNzdXJhbmNlRVZSb290Q0EuY3JsMD0GA1UdIAQ2 MDQwMgYEVR0gADAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5j b20vQ1BTMB0GA1UdDgQWBBQ901Cl1qCt7vNKYApl0yHU+PjWDzAfBgNVHSMEGDAW gBSxPsNpA/i/RwHUmCYaCALvY2QrwzANBgkqhkiG9w0BAQsFAAOCAQEAnbbQkIbh hgLtxaDwNBx0wY12zIYKqPBKikLWP8ipTa18CK3mtlC4ohpNiAexKSHc59rGPCHg 4xFJcKx6HQGkyhE6V6t9VypAdP3THYUYUN9XR3WhfVUgLkc3UHKMf4Ib0mKPLQNa 2sPIoc4sUqIAY+tzunHISScjl2SFnjgOrWNoPLpSgVh5oywM395t6zHyuqB8bPEs 1OG9d4Q3A84ytciagRpKkk47RpqF/oOi+Z6Mo8wNXrM9zwR4jxQUezKcxwCmXMS1 oVWNWlZopCJwqjyBcdmdqEU79OX2olHdx3ti6G8MdOu42vi/hw15UJGQmxg7kVkn 8TUoE6smftX3eg== -----END CERTIFICATE-----
[toc] | [prev] | [next] | [standalone]
| From | Mark Allums <maa@allums.com> |
|---|---|
| Date | 2022-01-03 23:40 +0100 |
| Message-ID | <DBE9I-5zH-7@gated-at.bofh.it> |
| In reply to | #243645 |
Did you click on a phishing link? Mark Allums On 1/3/22 16:16, local10 wrote: > Jan 3, 2022, 22:11 by roberto@debian.org: > >> The site works fine for me. >> >> In FF, click on 'SSL_ERROR_BAD_CERT_DOMAIN', which should take you to >> the full error output. Then click 'Copy text to clipboard' and paste >> the full text into an email. Someone on the list ought to be able to >> help diagnose further from there. >> > > Weird. This is what I get: > > > Websites prove their identity via certificates. Firefox does not trust this site because it uses a certificate that is not valid for tools.usps.com. The certificate is only valid for the following names: www.costco.ca <http://www.costco.ca>, costco.ca > > Error code: SSL_ERROR_BAD_CERT_DOMAIN > > > https://tools.usps.com/go/TrackConfirmAction_input?origTrackNum=1234567890 > > Unable to communicate securely with peer: requested domain name does not match the server’s certificate. > > HTTP Strict Transport Security: false > HTTP Public Key Pinning: false > > Certificate chain: > > -----BEGIN CERTIFICATE----- > MIIHTjCCBjagAwIBAgIQBOyIfmSb5tyeC53E3AQoqzANBgkqhkiG9w0BAQsFADB1 > MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3 > d3cuZGlnaWNlcnQuY29tMTQwMgYDVQQDEytEaWdpQ2VydCBTSEEyIEV4dGVuZGVk > IFZhbGlkYXRpb24gU2VydmVyIENBMB4XDTIwMDQxMzAwMDAwMFoXDTIyMDcxMjEy > MDAwMFowgdsxHTAbBgNVBA8MFFByaXZhdGUgT3JnYW5pemF0aW9uMRMwEQYLKwYB > BAGCNzwCAQMTAlVTMRswGQYLKwYBBAGCNzwCAQITCldhc2hpbmd0b24xFDASBgNV > BAUTCzYwMSAwMjQgNjc0MQswCQYDVQQGEwJVUzETMBEGA1UECBMKV2FzaGluZ3Rv > bjERMA8GA1UEBxMISXNzYXF1YWgxJTAjBgNVBAoTHENvc3RjbyBXaG9sZXNhbGUg > Q29ycG9yYXRpb24xFjAUBgNVBAMTDXd3dy5jb3N0Y28uY2EwggEiMA0GCSqGSIb3 > DQEBAQUAA4IBDwAwggEKAoIBAQDaZN4KpbA4DhbWw+TT9c8mNUPeVKsYaysqMKJK > jVUKCx4DfAa1xWdR3l/DcMfuA3oTfFhf1X9tpL7hcCQN+jr/WKKTR9usHzjFzP1O > Q8QXPza0HjOaQbLwlO6MMrLfO/R5p1D2dhTAnGneL0ZR03DoqLIPqJT/aBEvQC2C > D5wxtm1TbooHuQ3OeUW8kOp/UY/+mT3uuf1LBz5EdjJ8A0Kc5FX6Lo54vK5Jty4X > VWASsj8W5DkLVL5k6zMUpRqKx9LEb1mYnKxYcTUQetCRBVo3zv7QUb+xNjhwEIiB > qe8g7pFgTW5FORITPoeWLCS68YwxZ/DJ7jYnouQludCKEsaPAgMBAAGjggNxMIID > bTAfBgNVHSMEGDAWgBQ901Cl1qCt7vNKYApl0yHU+PjWDzAdBgNVHQ4EFgQU34QV > E4cZWcbn/7IWLK0nuAzCU9YwIwYDVR0RBBwwGoINd3d3LmNvc3Rjby5jYYIJY29z > dGNvLmNhMA4GA1UdDwEB/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYB > BQUHAwIwdQYDVR0fBG4wbDA0oDKgMIYuaHR0cDovL2NybDMuZGlnaWNlcnQuY29t > L3NoYTItZXYtc2VydmVyLWcyLmNybDA0oDKgMIYuaHR0cDovL2NybDQuZGlnaWNl > cnQuY29tL3NoYTItZXYtc2VydmVyLWcyLmNybDBLBgNVHSAERDBCMDcGCWCGSAGG > /WwCATAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5jb20vQ1BT > MAcGBWeBDAEBMIGIBggrBgEFBQcBAQR8MHowJAYIKwYBBQUHMAGGGGh0dHA6Ly9v > Y3NwLmRpZ2ljZXJ0LmNvbTBSBggrBgEFBQcwAoZGaHR0cDovL2NhY2VydHMuZGln > aWNlcnQuY29tL0RpZ2lDZXJ0U0hBMkV4dGVuZGVkVmFsaWRhdGlvblNlcnZlckNB > LmNydDAJBgNVHRMEAjAAMIIBewYKKwYBBAHWeQIEAgSCAWsEggFnAWUAdQCkuQmQ > tBhYFIe7E6LMZ3AKPDWYBPkb37jjd80OyA3cEAAAAXF1Ht6gAAAEAwBGMEQCIDR/ > YSEr0iSj2uKBMQuc3YmvbFjlwH2+uEmd6NNbi9wGAiBTrfdlBpZJN6GyKMqded5g > yCxxgCV4jUtLQiw7vBUN2gB1AFYUBpov18Ls0/XhvUSyPsdGdrm8mRFcwO+UmFXW > idDdAAABcXUe3vcAAAQDAEYwRAIgJKh7x+t4g47X35aah89yser+f77yFRGzp9sj > 6WryR2sCIHOa8cSDFzjBwPp3vTHAse1lJO4QGPtg/NXXfk4Veb75AHUAu9nfvB+K > cbWTlCOXqpJ7RzhXlQqrUugakJZkNo4e0YUAAAFxdR7etQAABAMARjBEAiBqwSAH > 8sKPb4Y818r3AtnliGWrGhqgtZ0GEZWyDGf+eAIgYYVrZ8xAfrWu83TLSHemxk1E > XvOQ9k8JJHyjVRmOxpQwDQYJKoZIhvcNAQELBQADggEBAGjuhZ9ypCuzqFPHmafF > 8tSty5Fb/LsQQ5i6O2A8lgG33WinpVjYbmDvlCl3vEsdkEvarGjCihJgTsb0RwZs > cNBkoFr+kNiR4lm/YnhtAd0qv8+uLJzZ1i9MmhcKuOSTgIKw368Kh0i9C3xDlsPU > jxK1rASaJxAuYBNWcPsnrO/BipRlpK8DG6XlNIUn8PzsuTVNOVf+kjdoM0rAHhVG > kagbhBbKJFLSOqLAZiXgc954wy9VIkEUHOd6Z3asMamTFSyC7wPj6rD3tkGwKKc0 > NQO6pYEvkXJRJeieYtla+a+Luly3Nxi8yHWDl98N6sqKgitjCBScs4bWaILw54E3 > S1c= > -----END CERTIFICATE----- > -----BEGIN CERTIFICATE----- > MIIEtjCCA56gAwIBAgIQDHmpRLCMEZUgkmFf4msdgzANBgkqhkiG9w0BAQsFADBs > MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3 > d3cuZGlnaWNlcnQuY29tMSswKQYDVQQDEyJEaWdpQ2VydCBIaWdoIEFzc3VyYW5j > ZSBFViBSb290IENBMB4XDTEzMTAyMjEyMDAwMFoXDTI4MTAyMjEyMDAwMFowdTEL > MAkGA1UEBhMCVVMxFTATBgNVBAoTDERpZ2lDZXJ0IEluYzEZMBcGA1UECxMQd3d3 > LmRpZ2ljZXJ0LmNvbTE0MDIGA1UEAxMrRGlnaUNlcnQgU0hBMiBFeHRlbmRlZCBW > YWxpZGF0aW9uIFNlcnZlciBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC > ggEBANdTpARR+JmmFkhLZyeqk0nQOe0MsLAAh/FnKIaFjI5j2ryxQDji0/XspQUY > uD0+xZkXMuwYjPrxDKZkIYXLBxA0sFKIKx9om9KxjxKws9LniB8f7zh3VFNfgHk/ > LhqqqB5LKw2rt2O5Nbd9FLxZS99RStKh4gzikIKHaq7q12TWmFXo/a8aUGxUvBHy > /Urynbt/DvTVvo4WiRJV2MBxNO723C3sxIclho3YIeSwTQyJ3DkmF93215SF2AQh > cJ1vb/9cuhnhRctWVyh+HA1BV6q3uCe7seT6Ku8hI3UarS2bhjWMnHe1c63YlC3k > 8wyd7sFOYn4XwHGeLN7x+RAoGTMCAwEAAaOCAUkwggFFMBIGA1UdEwEB/wQIMAYB > Af8CAQAwDgYDVR0PAQH/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF > BQcDAjA0BggrBgEFBQcBAQQoMCYwJAYIKwYBBQUHMAGGGGh0dHA6Ly9vY3NwLmRp > Z2ljZXJ0LmNvbTBLBgNVHR8ERDBCMECgPqA8hjpodHRwOi8vY3JsNC5kaWdpY2Vy > dC5jb20vRGlnaUNlcnRIaWdoQXNzdXJhbmNlRVZSb290Q0EuY3JsMD0GA1UdIAQ2 > MDQwMgYEVR0gADAqMCgGCCsGAQUFBwIBFhxodHRwczovL3d3dy5kaWdpY2VydC5j > b20vQ1BTMB0GA1UdDgQWBBQ901Cl1qCt7vNKYApl0yHU+PjWDzAfBgNVHSMEGDAW > gBSxPsNpA/i/RwHUmCYaCALvY2QrwzANBgkqhkiG9w0BAQsFAAOCAQEAnbbQkIbh > hgLtxaDwNBx0wY12zIYKqPBKikLWP8ipTa18CK3mtlC4ohpNiAexKSHc59rGPCHg > 4xFJcKx6HQGkyhE6V6t9VypAdP3THYUYUN9XR3WhfVUgLkc3UHKMf4Ib0mKPLQNa > 2sPIoc4sUqIAY+tzunHISScjl2SFnjgOrWNoPLpSgVh5oywM395t6zHyuqB8bPEs > 1OG9d4Q3A84ytciagRpKkk47RpqF/oOi+Z6Mo8wNXrM9zwR4jxQUezKcxwCmXMS1 > oVWNWlZopCJwqjyBcdmdqEU79OX2olHdx3ti6G8MdOu42vi/hw15UJGQmxg7kVkn > 8TUoE6smftX3eg== > -----END CERTIFICATE----- >
[toc] | [prev] | [next] | [standalone]
| From | local10 <local10@tutanota.com> |
|---|---|
| Date | 2022-01-03 23:50 +0100 |
| Subject | Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBEjo-5DJ-11@gated-at.bofh.it> |
| In reply to | #243647 |
Jan 3, 2022, 22:30 by maa@allums.com: > Did you click on a phishing link? > > Mark Allums > No, I have some USPS.com tracking links bookmarked and they were working fine until about two weeks ago. Could it be perhaps related to the Firefox upgrade from 78esr to 91esr? Regards,
[toc] | [prev] | [next] | [standalone]
| From | local10 <local10@tutanota.com> |
|---|---|
| Date | 2022-01-03 23:50 +0100 |
| Subject | Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBEjo-5DJ-7@gated-at.bofh.it> |
| In reply to | #243645 |
Jan 3, 2022, 22:29 by dsr@randomstring.org: > Costco is definitely not the US Postal Service. > No argument here. > flush caches. Restart Firefox. Check your net connection. > I've done this a number of times. The connection is direct, no proxy. Regards,
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2022-01-04 00:30 +0100 |
| Message-ID | <DBEW5-662-1@gated-at.bofh.it> |
| In reply to | #243650 |
local10 wrote: > Jan 3, 2022, 22:29 by dsr@randomstring.org: > > > Costco is definitely not the US Postal Service. > > > > No argument here. > > > > flush caches. Restart Firefox. Check your net connection. > > > > I've done this a number of times. The connection is direct, no proxy. Alright. Put this into your /etc/hosts temporarily: 152.195.33.23 www.usps.com tools.usps.com www.usps.gov That's unlikely to be an optimal IP from their CDN, but it is currently working. Oh. Are you using DNS-over-HTTPS? https://support.mozilla.org/en-US/kb/firefox-dns-over-https -dsr-
[toc] | [prev] | [next] | [standalone]
| From | local10 <local10@tutanota.com> |
|---|---|
| Date | 2022-01-04 01:00 +0100 |
| Subject | Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBFp7-6fB-1@gated-at.bofh.it> |
| In reply to | #243650 |
Jan 3, 2022, 23:08 by dsr@randomstring.org: > Alright. Put this into your /etc/hosts temporarily: > > 152.195.33.23 www.usps.com tools.usps.com www.usps.gov > > That's unlikely to be an optimal IP from their CDN, but it is > currently working. > That fixed it, I got the USPS tracking page to load normally. Still not why it worked as tools.usps.com resolves for me to 152.195.33.23: # dig tools.usps.com ; <<>> DiG 9.16.22-Debian <<>> tools.usps.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 45738 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1232 ; COOKIE: 77e474050843f63a0100000061d38b021b182f925c475f14 (good) ;; QUESTION SECTION: ;tools.usps.com. IN A ;; ANSWER SECTION: tools.usps.com. 42 IN CNAME cs1799.wpc.upsiloncdn.net. cs1799.wpc.upsiloncdn.net. 2078 IN A 152.195.33.23 ;; Query time: 0 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: Mon Jan 03 18:47:14 EST 2022 ;; MSG SIZE rcvd: 126 > Oh. Are you using DNS-over-HTTPS? > I used to but I have disabled it for now. Even with DNS-over-HTTPS disabled I was getting the certificate error until I put 152.195.33.23 into the /etc/hosts. Regards,
[toc] | [prev] | [next] | [standalone]
| From | local10 <local10@tutanota.com> |
|---|---|
| Date | 2022-01-04 01:10 +0100 |
| Subject | [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBFyN-6yp-3@gated-at.bofh.it> |
| In reply to | #243650 |
Jan 3, 2022, 23:53 by local10@tutanota.com: > Jan 3, 2022, 23:08 by dsr@randomstring.org: > >> Alright. Put this into your /etc/hosts temporarily: >> >> 152.195.33.23 www.usps.com tools.usps.com www.usps.gov >> >> That's unlikely to be an optimal IP from their CDN, but it is >> currently working. >> > > That fixed it, I got the USPS tracking page to load normally. Still not sure why it worked as tools.usps.com resolves for me to 152.195.33.23: > > # dig tools.usps.com > ... > .... > ;; ANSWER SECTION: > tools.usps.com. 42 IN CNAME cs1799.wpc.upsiloncdn.net. > cs1799.wpc.upsiloncdn.net. 2078 IN A 152.195.33.23 > OK, I understand now what the problem was. Quite a while ago I added a line into the /etc/hosts to fix a temp DNS issue and completely forgot about it. So while DNS server was correctly resolving tools.usps.com to 152.195.33.23, my previous /etc/hosts entry was overriding it to 23.217.162.158 which was causing the certificate issue. Thanks to everyone who responded.
[toc] | [prev] | [next] | [standalone]
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Date | 2022-01-04 19:20 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBWzE-b4-13@gated-at.bofh.it> |
| In reply to | #243662 |
On Tue, Jan 04, 2022 at 01:09:06AM +0100, local10 wrote: >> Jan 3, 2022, 23:08 by dsr@randomstring.org: >>> Alright. Put this into your /etc/hosts temporarily: [...] >OK, I understand now what the problem was. Quite a while ago I added a line into the /etc/hosts to fix a temp DNS issue and completely forgot about it. So while DNS server was correctly resolving tools.usps.com to 152.195.33.23, my previous /etc/hosts entry was overriding it to 23.217.162.158 which was causing the certificate issue. And this is why putting stuff into /etc/hosts is basically never the right answer. :)
[toc] | [prev] | [next] | [standalone]
| From | "James H. H. Lampert" <jamesl@touchtonecorp.com> |
|---|---|
| Date | 2022-01-04 19:40 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBWSZ-hr-11@gated-at.bofh.it> |
| In reply to | #243689 |
On 1/4/22 10:19 AM, Michael Stone wrote: > And this is why putting stuff into /etc/hosts is basically never the > right answer. :) Au contraire! Among other things, the host table is the best possible place to block access to certain unwanted domains. For example, if you add these entries: > 0.0.0.0 facebook.com > 0.0.0.0 www.facebook.com > 0.0.0.0 hi-in.facebook.com > 0.0.0.0 gl-es.facebook.com > 0.0.0.0 twitter.com > 0.0.0.0 www.twitter.com you can never be tricked into accessing Facebook or Twitter (for me, ONCE is far too many times), and if you add > 0.0.0.0 bing.com then bing-redirections will fail every time (and alert you to their noisome and all-too-common presence). And likewise, you might want to access other machines within your LAN by name, but your operation is not big enough to warrant bothering with an internal DNS, or you might need to access outside systems that, for various perfectly legitimate reasons, are kept off the public DNS. -- JHHL
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2022-01-04 19:40 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBWT0-hr-21@gated-at.bofh.it> |
| In reply to | #243691 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Jan 04, 2022 at 10:34:48AM -0800, James H. H. Lampert wrote: > On 1/4/22 10:19 AM, Michael Stone wrote: > > And this is why putting stuff into /etc/hosts is basically never the > > right answer. :) > > Au contraire! > > Among other things, the host table is the best possible place to block > access to certain unwanted domains. For example, if you add these entries: > > > 0.0.0.0 facebook.com [...] Oh, great minds think alike :) I put them to 127.0.0.1, because then I can see them hitting the wall in my local web server logs ;-) Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Date | 2022-01-04 21:30 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBYBr-1mI-3@gated-at.bofh.it> |
| In reply to | #243691 |
On Tue, Jan 04, 2022 at 10:34:48AM -0800, James H. H. Lampert wrote: >On 1/4/22 10:19 AM, Michael Stone wrote: >>And this is why putting stuff into /etc/hosts is basically never the >>right answer. :) > >Au contraire! > >Among other things, the host table is the best possible place to block >access to certain unwanted domains Not really, but it certainly is something that people do.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2022-01-04 19:40 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBWT0-hr-25@gated-at.bofh.it> |
| In reply to | #243689 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Jan 04, 2022 at 01:19:37PM -0500, Michael Stone wrote: [...] > And this is why putting stuff into /etc/hosts is basically never the right > answer. :) Eye, beholder and things. I've got a couple of them like so: # Pest: 127.0.0.1 www.google-analytics.com 127.0.0.1 ajax.google.com 127.0.0.1 ad.doublecklick.net 127.0.0.1 www.gstatic.com ... Yeah, some things stop working then. I want them to :) Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2022-01-04 20:40 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBXP3-QH-9@gated-at.bofh.it> |
| In reply to | #243693 |
On Tue 04 Jan 2022 at 19:37:34 (+0100), tomas@tuxteam.de wrote: > On Tue, Jan 04, 2022 at 01:19:37PM -0500, Michael Stone wrote: > > [...] > > > And this is why putting stuff into /etc/hosts is basically never the right > > answer. :) > > Eye, beholder and things. I've got a couple of them like so: > > # Pest: > 127.0.0.1 www.google-analytics.com > 127.0.0.1 ajax.google.com > 127.0.0.1 ad.doublecklick.net > 127.0.0.1 www.gstatic.com > ... > > Yeah, some things stop working then. I want them to :) Agreed. I append a list of close to 14,000 addresses (including comments) to the end of my own local /etc/hosts. I see very few adverts. In fact, I was quite shocked when I just tried DNS over HTTPS for a couple of minutes. The 10-day weather profile that I screenshoot every day was plastered in popups. Anyone know how to combine DoH with resolving 14,000 addresses to 127.0.0.1? Also, does that mean that DoH attempts to resolve my local hosts before consulting /etc/hosts? I didn't stick around DoH long enough to find out. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2022-01-04 21:00 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBY8q-XI-9@gated-at.bofh.it> |
| In reply to | #243695 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Jan 04, 2022 at 01:33:18PM -0600, David Wright wrote: > On Tue 04 Jan 2022 at 19:37:34 (+0100), tomas@tuxteam.de wrote: > > On Tue, Jan 04, 2022 at 01:19:37PM -0500, Michael Stone wrote: > > > > [...] > > > > > And this is why putting stuff into /etc/hosts is basically never the right > > > answer. :) > > > > Eye, beholder and things. I've got a couple of them like so: > > > > # Pest: > > 127.0.0.1 www.google-analytics.com > > 127.0.0.1 ajax.google.com > > 127.0.0.1 ad.doublecklick.net > > 127.0.0.1 www.gstatic.com > > ... > > > > Yeah, some things stop working then. I want them to :) > > Agreed. I append a list of close to 14,000 addresses (including > comments) to the end of my own local /etc/hosts. I see very > few adverts. In fact, I was quite shocked when I just tried > DNS over HTTPS for a couple of minutes. The 10-day weather > profile that I screenshoot every day was plastered in popups. > > Anyone know how to combine DoH with resolving 14,000 addresses > to 127.0.0.1? Also, does that mean that DoH attempts to resolve > my local hosts before consulting /etc/hosts? I didn't stick > around DoH long enough to find out. No idea. I'd hope for it to be overridable, but I've been disappointed by browsers (yes, firefox, I'm looking at you!) before. The day it ain't a choice anymore will be the day I hide behind a proxy *I* trust and control. That one can then look up things in /etc/hosts. (Yes, that means some bricolage with trusted root CAs. So be it.) Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2022-01-04 22:10 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DBZe9-1P7-5@gated-at.bofh.it> |
| In reply to | #243698 |
On Tue, 4 Jan 2022 20:58:27 +0100 <tomas@tuxteam.de> wrote: > On Tue, Jan 04, 2022 at 01:33:18PM -0600, David Wright wrote: > > On Tue 04 Jan 2022 at 19:37:34 (+0100), tomas@tuxteam.de wrote: > > > On Tue, Jan 04, 2022 at 01:19:37PM -0500, Michael Stone wrote: > > > > > > [...] > > > > > > > And this is why putting stuff into /etc/hosts is basically never the right > > > > answer. :) > > > > > > Eye, beholder and things. I've got a couple of them like so: > > > > > > # Pest: > > > 127.0.0.1 www.google-analytics.com > > > 127.0.0.1 ajax.google.com > > > 127.0.0.1 ad.doublecklick.net > > > 127.0.0.1 www.gstatic.com > > > ... > > > > > > Yeah, some things stop working then. I want them to :) > > > > Agreed. I append a list of close to 14,000 addresses (including > > comments) to the end of my own local /etc/hosts. I see very > > few adverts. In fact, I was quite shocked when I just tried > > DNS over HTTPS for a couple of minutes. The 10-day weather > > profile that I screenshoot every day was plastered in popups. > > > > Anyone know how to combine DoH with resolving 14,000 addresses > > to 127.0.0.1? Also, does that mean that DoH attempts to resolve > > my local hosts before consulting /etc/hosts? I didn't stick > > around DoH long enough to find out. > > No idea. I'd hope for it to be overridable, but I've been disappointed > by browsers (yes, firefox, I'm looking at you!) before. One way "to combine DoH with resolving 14,000 addresses to 127.0.0.1" is by using Pi-hole. Some people have *millions* of domains blacklisted in Pi-hole: https://www.reddit.com/r/pihole/comments/rrcmfk/why_am_i_making_a_personal_commitment_to_donating/ https://www.reddit.com/r/pihole/comments/7rzdzj/how_many_domains_do_you_have_on_your_setup/ https://www.reddit.com/r/pihole/comments/hkfyu4/domains_on_blocklist/ etc. and using DoH with Pi-hole is well documented: https://docs.pi-hole.net/guides/dns/cloudflared/ https://medium.com/codex/pi-hole-and-doh-f1a9f8acd0f7 https://github.com/devopsleigh/pihole Celejar
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2022-01-05 06:20 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DC6Sm-6vm-7@gated-at.bofh.it> |
| In reply to | #243701 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Jan 04, 2022 at 04:05:11PM -0500, Celejar wrote: [...] > One way "to combine DoH with resolving 14,000 addresses to 127.0.0.1" > is by using Pi-hole. Some people have *millions* of domains blacklisted > in Pi-hole: Pi-hole won't help unles it also does HTTPS proxying (that means it would have to play MITM). As far as I know it "just" does conventional DNS proxying (which is a great thing to do, mind you). But hey, full HTTP(S) proxying would be a great thing to do. Still, you'd have to munge your browser's trusted certs for that trick to work. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2022-01-05 14:50 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DCePU-3a1-3@gated-at.bofh.it> |
| In reply to | #243706 |
On Wed, 5 Jan 2022 06:10:48 +0100 <tomas@tuxteam.de> wrote: > On Tue, Jan 04, 2022 at 04:05:11PM -0500, Celejar wrote: > > [...] > > > One way "to combine DoH with resolving 14,000 addresses to 127.0.0.1" > > is by using Pi-hole. Some people have *millions* of domains blacklisted > > in Pi-hole: > > Pi-hole won't help unles it also does HTTPS proxying (that means it > would have to play MITM). As far as I know it "just" does conventional > DNS proxying (which is a great thing to do, mind you). Why won't it help? What won't it help with? If you mean that the queries won't be secure during the leg between the client and the Pi-hole, we're talking about running Pi-hole within one's trusted network (or connecting to it over a VPN, etc.) > > But hey, full HTTP(S) proxying would be a great thing to do. Still, > you'd have to munge your browser's trusted certs for that trick to work. Celejar
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2022-01-05 18:30 +0100 |
| Subject | Re: [SOLVED] Re: Firefox: Warning: Potential Security Risk Ahead for the USPS.com |
| Message-ID | <DCigN-5pq-3@gated-at.bofh.it> |
| In reply to | #243710 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Jan 05, 2022 at 08:43:23AM -0500, Celejar wrote: > On Wed, 5 Jan 2022 06:10:48 +0100 > <tomas@tuxteam.de> wrote: > > > On Tue, Jan 04, 2022 at 04:05:11PM -0500, Celejar wrote: > > > > [...] > > > > > One way "to combine DoH with resolving 14,000 addresses to 127.0.0.1" > > > is by using Pi-hole. Some people have *millions* of domains blacklisted > > > in Pi-hole: > > > > Pi-hole won't help unles it also does HTTPS proxying (that means it > > would have to play MITM). As far as I know it "just" does conventional > > DNS proxying (which is a great thing to do, mind you). > > Why won't it help? What won't it help with? (See also Dan's response: it seems that a compliant DoH client first sends a local DNS request first, so you might have a handle through this) With this caveat: how would you intercept a DNS request over HTTPS if not by proxying HTTPS traffic? And that is exactly what MITM means. Cheers -- t
[toc] | [prev] | [next] | [standalone]
Page 1 of 3 [1] 2 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web