<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Firefox 3: Site Identification button</title>
	<atom:link href="http://www.dria.org/wordpress/archives/2008/05/06/635/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.dria.org/wordpress/archives/2008/05/06/635/</link>
	<description>intrepid girl reporter</description>
	<pubDate>Sat, 05 Jul 2008 09:37:00 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Jayson</title>
		<link>http://www.dria.org/wordpress/archives/2008/05/06/635/#comment-59376</link>
		<dc:creator>Jayson</dc:creator>
		<pubDate>Sat, 28 Jun 2008 18:58:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.dria.org/wordpress/?p=635#comment-59376</guid>
		<description>I also second (third, fourth) the objection about self-signed certificates; many web control panels, eg plesk, self-sign (or at least have to option to offer self-signed certificates). It also looks like the yellow state works in a similar way to how Google malicious site blocker works - by interrupting the browsing session. I think a lot of the smaller commerce sites will be “broken” by this feature.</description>
		<content:encoded><![CDATA[<p>I also second (third, fourth) the objection about self-signed certificates; many web control panels, eg plesk, self-sign (or at least have to option to offer self-signed certificates). It also looks like the yellow state works in a similar way to how Google malicious site blocker works - by interrupting the browsing session. I think a lot of the smaller commerce sites will be “broken” by this feature.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric</title>
		<link>http://www.dria.org/wordpress/archives/2008/05/06/635/#comment-59352</link>
		<dc:creator>Eric</dc:creator>
		<pubDate>Wed, 25 Jun 2008 12:45:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.dria.org/wordpress/?p=635#comment-59352</guid>
		<description>I found the yellow bar very useful and I am extremely disappointed to see it gone.

The yellow bar was never meant to distinguish between "good" and "evil" sites - it was only there to show that the communication with the site is encrypted. I think it did that job very well and would have liked it to stay. People are used the the yellow indicator for encryption. Why remove it? I don't understand the thinking here and think that the decision to remove it is flawed.

I also agree with VanillaMozilla above re. self-signed certificates. Encryption and identification are two different things. Why block access to an encrypted site just because the encryption is done by the site owner?

Also - how would I know that the button is clickable? It is not very obvious. I had no idea until I started searching for info about the missing yellow location bar.</description>
		<content:encoded><![CDATA[<p>I found the yellow bar very useful and I am extremely disappointed to see it gone.</p>
<p>The yellow bar was never meant to distinguish between &#8220;good&#8221; and &#8220;evil&#8221; sites - it was only there to show that the communication with the site is encrypted. I think it did that job very well and would have liked it to stay. People are used the the yellow indicator for encryption. Why remove it? I don&#8217;t understand the thinking here and think that the decision to remove it is flawed.</p>
<p>I also agree with VanillaMozilla above re. self-signed certificates. Encryption and identification are two different things. Why block access to an encrypted site just because the encryption is done by the site owner?</p>
<p>Also - how would I know that the button is clickable? It is not very obvious. I had no idea until I started searching for info about the missing yellow location bar.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.dria.org/wordpress/archives/2008/05/06/635/#comment-58718</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 06 Jun 2008 16:34:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.dria.org/wordpress/?p=635#comment-58718</guid>
		<description>On the Mac, the text in the green identity button is 1px higher than the URL. Was this intentional? It doesn't appear to be that was on Windows.</description>
		<content:encoded><![CDATA[<p>On the Mac, the text in the green identity button is 1px higher than the URL. Was this intentional? It doesn&#8217;t appear to be that was on Windows.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mozilla in Asia &#187; Blog Archive &#187; Firefox 3: UTF-8 support in location bar</title>
		<link>http://www.dria.org/wordpress/archives/2008/05/06/635/#comment-58452</link>
		<dc:creator>Mozilla in Asia &#187; Blog Archive &#187; Firefox 3: UTF-8 support in location bar</dc:creator>
		<pubDate>Fri, 23 May 2008 08:17:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.dria.org/wordpress/?p=635#comment-58452</guid>
		<description>[...] smart location bar (a.k.a. Awesomebar), the new bookmarks functionality, color profile support, the site identification button, the 3 new themes, to name just a [...]</description>
		<content:encoded><![CDATA[<p>[...] smart location bar (a.k.a. Awesomebar), the new bookmarks functionality, color profile support, the site identification button, the 3 new themes, to name just a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meandering wildly</title>
		<link>http://www.dria.org/wordpress/archives/2008/05/06/635/#comment-58442</link>
		<dc:creator>meandering wildly</dc:creator>
		<pubDate>Wed, 21 May 2008 16:23:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.dria.org/wordpress/?p=635#comment-58442</guid>
		<description>[...] it can be hard to tell your bank’s real web site from one of these fakes.  Firefox 3 includes some features to help you do that, but really, it would be far better to just not go there in the first place.  That’s why we keep [...]</description>
		<content:encoded><![CDATA[<p>[...] it can be hard to tell your bank’s real web site from one of these fakes.  Firefox 3 includes some features to help you do that, but really, it would be far better to just not go there in the first place.  That’s why we keep [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sorensen</title>
		<link>http://www.dria.org/wordpress/archives/2008/05/06/635/#comment-58425</link>
		<dc:creator>Sorensen</dc:creator>
		<pubDate>Mon, 19 May 2008 06:16:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.dria.org/wordpress/?p=635#comment-58425</guid>
		<description>Thanks for a, at least for me, very educational article. I have recently updated my Linux dist to Ubuntu 8.04. Mozilla Firefox 3 beta 5, the default browser of this dist, has the identity button. But strangely they have made the background of the button permanently grey. So absolute no information unless one actually move the cursor over the button. Maybe the colors did not match the Ubuntu folks color scheme!? Anyhow it is quite unfortunate - though not your problem ;-)</description>
		<content:encoded><![CDATA[<p>Thanks for a, at least for me, very educational article. I have recently updated my Linux dist to Ubuntu 8.04. Mozilla Firefox 3 beta 5, the default browser of this dist, has the identity button. But strangely they have made the background of the button permanently grey. So absolute no information unless one actually move the cursor over the button. Maybe the colors did not match the Ubuntu folks color scheme!? Anyhow it is quite unfortunate - though not your problem ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eddy Nigg</title>
		<link>http://www.dria.org/wordpress/archives/2008/05/06/635/#comment-58418</link>
		<dc:creator>Eddy Nigg</dc:creator>
		<pubDate>Mon, 19 May 2008 02:03:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.dria.org/wordpress/?p=635#comment-58418</guid>
		<description>To mario:

If no third party which is known and has proved to validate domain name ownership (at least) no certificate is worth the digital paper it's written on. Otherwise the MITM will simply use also a self-signed which you'll click through...Except with the new scheme where you add a specific certificate for a specific site, in which case it's your risk if you talk to a MITM, but it will certainly alert you if it happens in the future at some point.

To Bodi:

This certainly doesn't happen with any recent Firefox browser. You must be using a different product then...This CA is in later 1.5 versions on upwards.</description>
		<content:encoded><![CDATA[<p>To mario:</p>
<p>If no third party which is known and has proved to validate domain name ownership (at least) no certificate is worth the digital paper it&#8217;s written on. Otherwise the MITM will simply use also a self-signed which you&#8217;ll click through&#8230;Except with the new scheme where you add a specific certificate for a specific site, in which case it&#8217;s your risk if you talk to a MITM, but it will certainly alert you if it happens in the future at some point.</p>
<p>To Bodi:</p>
<p>This certainly doesn&#8217;t happen with any recent Firefox browser. You must be using a different product then&#8230;This CA is in later 1.5 versions on upwards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: &#187; Secure banking The Chris Gonyea Project</title>
		<link>http://www.dria.org/wordpress/archives/2008/05/06/635/#comment-58410</link>
		<dc:creator>&#187; Secure banking The Chris Gonyea Project</dc:creator>
		<pubDate>Sun, 18 May 2008 14:51:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.dria.org/wordpress/?p=635#comment-58410</guid>
		<description>[...] site identification button now shows up green when I log into my online banking page. They also now use 256-bit [...]</description>
		<content:encoded><![CDATA[<p>[...] site identification button now shows up green when I log into my online banking page. They also now use 256-bit [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chat Marchet News Digest &#187; The Identity Button - Firefox 3&#8217;s New Security UI</title>
		<link>http://www.dria.org/wordpress/archives/2008/05/06/635/#comment-58368</link>
		<dc:creator>Chat Marchet News Digest &#187; The Identity Button - Firefox 3&#8217;s New Security UI</dc:creator>
		<pubDate>Fri, 16 May 2008 05:14:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.dria.org/wordpress/?p=635#comment-58368</guid>
		<description>[...] The whole scoop.  This entry was posted on Friday, May 16th, 2008 at 2:12 am and is filed under le Chat Marchet. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site. [...]</description>
		<content:encoded><![CDATA[<p>[...] The whole scoop.  This entry was posted on Friday, May 16th, 2008 at 2:12 am and is filed under le Chat Marchet. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VanillaMozilla</title>
		<link>http://www.dria.org/wordpress/archives/2008/05/06/635/#comment-58330</link>
		<dc:creator>VanillaMozilla</dc:creator>
		<pubDate>Tue, 13 May 2008 16:52:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.dria.org/wordpress/?p=635#comment-58330</guid>
		<description>Two bug reports filed:
Bug 433412 – "Larry" button (site ID) needs an informative icon
Bug 433422 – Self-signed SSL certificates should not be labeled as "invalid"

Sorry for the comment spam.</description>
		<content:encoded><![CDATA[<p>Two bug reports filed:<br />
Bug 433412 – &#8220;Larry&#8221; button (site ID) needs an informative icon<br />
Bug 433422 – Self-signed SSL certificates should not be labeled as &#8220;invalid&#8221;</p>
<p>Sorry for the comment spam.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
