We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

HTTPS Everywhere Update: Now Reports Website Weaknesses

The EFF updated its HTTPS Everywhere software to include a "Decentralized SSL Observatory" that detects encryption weaknesses in websites.

HTTPS Everywhere, a collaborative security project produced by The Tor Project and the Electronic Frontier Foundation (EFF), has been updated to identify security weaknesses in websites visited with Mozilla Firefox.

The new optional feature, called the "Decentralized SSL Observatory," detects encryption weaknesses in websites and notifies users about said weaknesses. Such weaknesses can be used by hackers to snoop on users' web activity or pose "man in the middle" attacks against the browser.

"In recent weeks, an unexpected weakness in the encryption used by many routers, firewalls and VPN devices made big news," EFF Technology Projects Director Peter Eckersley said in a statement.

"The new version of HTTPS Everywhere for Firefox will let users know when they connect to a website or device that has a security problem--including weak key problems like the ones that were disclosed two weeks ago--giving people the information they need to protect themselves."

The security flaw in network devices was discovered earlier this month by security researchers. They found that four out of every 1000 security keys generated for protecting webmail, online banking, and other sensitive net services provide no cryptographic security. It's estimated that more than a million Internet sites use such technology to prevent eavesdropping.

The EFF also released a beta version of HTTPS Everywhere for Chrome.

Follow freelance technology writer John P. Mello Jr. and Today@PCWorld on Twitter.

IDG UK Sites

Nexus 6 vs Samsung Galaxy Note 4 comparison: What's the best Android phablet?

IDG UK Sites

The iPhone is doomed. Doomed to be marginally less successful than a very successful thing.

IDG UK Sites

How to prototype native mobile apps without writing code

IDG UK Sites

How to prepare for and update to OS X Yosemite: Get your Mac ready to download & install Apple's...