Thunderbird bz 579023 still not fixed even though there is an upstream fix available

Kevin Kofler kevin.kofler at chello.at
Tue Apr 27 22:37:21 UTC 2010


Bruno Wolff III wrote:
> The way Firefox does it, is more to help companies sell certificates than
> to actually help security.

+1

All it does is it leads people to use completely unencrypted HTTP instead, 
to avoid the "big scary warnings". How does that provide any added security?

I like the way Konqueror handles this: it does complain about self-signed or 
otherwise invalid certs, but it allows you to accept them either temporarily 
(for the duration of the session) or permanently in 2 clicks (one to accept 
and one to choose whether to accept it for the session or forever).

        Kevin Kofler



More information about the devel mailing list