Willkommen bei den Thunderbird-Add-ons.
Fügen Sie Zusatzfunktionen und Stile hinzu, um sich Thunderbird zu Eigen zu machen.Schließen
Certificate Patrol 2.0.16 Benötigt Neustart
von Carlo v. Loesch, tg(x), 20after4
Dein Web-Browser vertraut vielen Zertifikationsautoritäten (CAs), welche wiederrum noch mehr Sub-CAs vertrauen. Legitim digital signierte Zertifikate können von irgendwo herkommen. Dieses Add-on hilft Dir den Überblick zu behalten.
Über dieses Add-on
You'll see certificate information pop up whenever you visit a
new https: website, including https://addons.mozilla.org for
example. "New" is anything Patrol hasn't seen and stored yet.
You are also prompted whenever a web site updates its certificate
and given the opportunity to compare the two certificates side by
side, line by line. See the screenshot for an example.
Even if you do not fully understand what is shown to you, you
get a chance of distinguishing legitimate from suspicious changes.
Here's a little list of things to look out for:
- If the old certificate is about to expire (Validity / Expires On),
it was necessary to replace it with a new one. CertPatrol
will check this for you.
- In most cases web sites keep using the same certification
authority (Issued By) over time. Should the web site have changed
its certification authority, make sure the old certificate was
about to expire. CertPatrol will assist you with this.
- You may want to consider the most popular CAs (like maybe CAcert, Entrust,
Equifax, GoDaddy, NetworkSolutions, Thawte and VeriSign.. to mention some)
to be less likely to help in MITM attacks, but that is only a guess.
Especially since in each country local CAs may be legitimately
- Comodo, GeoTrust, GlobalSign, QuoVadis, RSA WebTrust and StartCom
are known to offer intermediate CA for money. Still StartCom is extremely
popular with small and private web sites for its free services.
- If all certificates you see are always issued by the same
certification authority, you should be very suspicious. Try
searching for random https: sites and see if they still all seem
signed by the same CA.
- In case of doubt install the Perspectives or Convergence add-ons to make further checks on the credibility of a certificate. The downside of these add-ons is, you reveal who you communicate with to an external service — so better only use it when necessary. In theory you could have some tech savvy friends run notaries for you, the more the better, but would you want to expose your surfing habits to them?
- If the web site is important to you, make a research on the name of
the new CA. Make a phone call to the owner of the web site and ask them
to confirm the SHA1 fingerprint shown on your screen.
The fingerprint is currently close to impossible to falsify.
Ask them to send you future certificate fingerprints by snail mail
before they install it.
- Some clustered sites such as bookryanair.com make things
more complicated by using several inconsistent certificates for the same
domain name. That will look unnecessarily suspicious. Usually such
certificates will look very similar to each other and appear to be
changing frequently. We can only hope for these companies to fix
This extension is similar to the as yet unreleased 'Certlock'. More info on http://patrol.psyced.org.
Der Entwicklerkanal ermöglicht es Ihnen, eine experimentelle neue Version dieses Add-ons zu testen, bevor es der Öffentlichkeit zur Verfügung gestellt wird. Sobald Sie die Entwicklerversion installieren, erhalten Sie weiter Updates über diesen Kanal. Wenn Sie keine Updates der Entwicklerversion mehr erhalten möchten, installieren Sie die normale Version über obigen Link neu.
Achtung: Entwicklerversionen dieses Add-ons wurden nicht von Mozilla überprüft.
- Version 2.0.13rc