Skip to content

GitLab

  • Menu
Projects Groups Snippets
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • Trac Trac
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Issues 246
    • Issues 246
    • List
    • Boards
    • Service Desk
    • Milestones
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
  • Wiki
    • Wiki
  • Activity
  • Create a new issue
  • Issue Boards
Collapse sidebar
  • Legacy
  • TracTrac
  • Issues
  • #15575

Closed
Open
Created Apr 03, 2015 by Trac@tracbot

Add test for HTTP Opportunistic Encryption

With Firefox and Chrome now supporting Opportunistic Encryption of HTTP in order to avoid a passive attacker stripping or modifying that header may be a worthwhile attack. It should probably be explicitly checked for, as modifying this particular header has a great chance for being an actual attack on a website supporting it.

Blog Articles on the Header: http://bitsup.blogspot.co.at/2015/03/opportunistic-encryption-for-firefox.html http://blog.alteroot.org/articles/2015-03-28/HTTP-alternative-services-and-opportunistic-encryption.html

RFC explaining the Header: https://tools.ietf.org/html/draft-ietf-httpbis-alt-svc-04

Trac:
Username: reezer

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information
Assignee
Assign to
Time tracking