New issue
Advanced search Search tips

Issue 620756 link

Starred by 0 users

Issue metadata

Status: WontFix
Owner:
Closed: Apr 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome , Mac
Pri: 2
Type: Bug



Sign in to add a comment

Insecure connection string for HTTP authentication should distinguish between server and proxy authentication

Project Member Reported by asanka@chromium.org, Jun 16 2016

Issue description

https://codereview.chromium.org/2067933002 adds the ability to warn the user when the proxy server that the user is authenticating with is insecure and may be spoofed.

It's using the same UI string used for warning about insecure servers and has the word "Server" in it. We should consider adding a new string for insecure proxies and perhaps reword both of them to indicate that not only can the passwords be sniffed by an attacker, Chrome also doesn't know if the endpoint is who it claims to be.
 

Comment 1 by asanka@chromium.org, Apr 11 2018

Status: WontFix (was: Assigned)
Obsolete. The login dialog clearly distinguishes between proxy and server authentication.

Sign in to add a comment