<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.developerfriendly.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>security</title>
 <link>http://www.developerfriendly.com/taxonomy/term/42</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>Certificate Change Notifier </title>
 <link>http://www.developerfriendly.com/node/45</link>
 <description>&lt;p&gt;I&#039;m working on a simple extension for Firefox that would notify the user when an SSL/TLS site&#039;s certificate changes. This way an informed user could decide if the certificate change was valid / expected and opt out of an ssl session in questionable circumstances.  Is there any interest in such an extension?  My friend ask me whether there was a way to do it so I&#039;m working on proof of concept code, I will release it as open source if anyone cares.&lt;/p&gt;

&lt;h4&gt;Update:&lt;/h4&gt; Working proof of concept code released. See XPI attachment below. Note: this is tested in Firefox 3.0 beta 2 and it uses mozStorage (sqlite) to keep track of the url/certificate mappings. This isn&#039;t really usable, it&#039;s simply a proof of concept with no useful user interface. It will pop up an alert when you visit a site that has changed it&#039;s certificate since your last visit.

&lt;h4&gt;Update #2:&lt;/h4&gt; An updated version of this extension is now available on addons.mozilla.org (it&#039;s in the sandbox until it&#039;s been reviewed.)  You have to log in before you can view the sandbox: &lt;a href=&quot;https://addons.mozilla.org/en-US/firefox/addon/6415&quot;&gt;Addon #6415&lt;/a&gt;</description>
 <comments>http://www.developerfriendly.com/node/45#comments</comments>
 <category domain="http://www.developerfriendly.com/taxonomy/term/7">Mozilla</category>
 <category domain="http://www.developerfriendly.com/taxonomy/term/1">mozpad</category>
 <category domain="http://www.developerfriendly.com/taxonomy/term/42">security</category>
 <category domain="http://www.developerfriendly.com/taxonomy/term/41">ssl</category>
 <enclosure url="http://www.developerfriendly.com/files/CertificateChangeNotify-v02.xpi" length="5294" type="application/x-xpinstall" />
 <pubDate>Sat, 22 Dec 2007 02:20:20 -0600</pubDate>
 <dc:creator>20after4</dc:creator>
 <guid isPermaLink="false">45 at http://www.developerfriendly.com</guid>
</item>
</channel>
</rss>
