{"id":2095,"date":"2014-11-05T00:45:43","date_gmt":"2014-11-05T07:45:43","guid":{"rendered":"http:\/\/www.designersgate.com\/blogs\/?p=2095"},"modified":"2014-11-05T00:45:43","modified_gmt":"2014-11-05T07:45:43","slug":"secure-websites-responding-disable-sslv3","status":"publish","type":"post","link":"https:\/\/designersgate.com\/blog\/secure-websites-responding-disable-sslv3\/","title":{"rendered":"Secure Websites Not Responding &#8211; Disable SSLv3"},"content":{"rendered":"<p>With the latest news about the new SSL vulnerability, after the not so long ago HEARTBLEED vulnerability, now we are been threatened by a POODLE. Because of this, browsers are blocking the use of SSLv3 causing some HTTPS websites to stop responding, in my case either in Chromium and Firefox. I noticed that any other website was working fine but every time a tried to access Gmail or Outlook mail services, my browser kept hanging on with the loading icon twirling and twirling, after almost 3 minutes, then I\u00a0received a prompted error about SSL Certificate error.\u00a0Do you wonder why the name? Actually, this vulnerability was call POODLE\u00a0because of its acronym which\u00a0means,\u00a0Padding Oracle On Downgraded Legacy Encryption.<\/p>\n<p>If you are having the same problem, this means your browser is susceptible to the POODLE\u00a0nightmare :-). The only way to fix this problem is disabling SSLv3. These are the solutions for Chromium and Firefox in Ubuntu 14.04 LTS. See my configurations below.<\/p>\n<p><a href=\"http:\/\/www.designersgate.com\/blogs\/wp-content\/uploads\/2014\/11\/mysettings.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2098\" src=\"http:\/\/www.designersgate.com\/blogs\/wp-content\/uploads\/2014\/11\/mysettings.png\" alt=\"My computer configurations\" width=\"864\" height=\"470\" srcset=\"https:\/\/designersgate.com\/blog\/wp-content\/uploads\/2014\/11\/mysettings.png 864w, https:\/\/designersgate.com\/blog\/wp-content\/uploads\/2014\/11\/mysettings-600x326.png 600w, https:\/\/designersgate.com\/blog\/wp-content\/uploads\/2014\/11\/mysettings-300x163.png 300w, https:\/\/designersgate.com\/blog\/wp-content\/uploads\/2014\/11\/mysettings-768x418.png 768w\" sizes=\"auto, (max-width: 864px) 100vw, 864px\" \/><\/a><\/p>\n<p><em><strong style=\"font-size: 20px;\">Disabling SSLv3 in Chromium<\/strong><\/em><\/p>\n<p>To fix your problem in Chromium you have to get your hands dirty and open your Terminal with Ctrl+Alt+T and type in:<\/p>\n<pre>~$ sudo gedit \/usr\/share\/applications\/chromium-browser.desktop<\/pre>\n<p>Type in\u00a0your password when prompted and Enter\/Return. This will open your text editor with administration privileges. Find the line that says:<\/p>\n<pre>Exec=chromium-browser %U<\/pre>\n<p>and modify it to:<\/p>\n<pre>Exec=chromium-browser --ssl-version-min=tls1 %U<\/pre>\n<p>Save and close the editor and in the terminal enter command:<\/p>\n<pre>~$ sudo gedit \/etc\/chromium-browser\/default<\/pre>\n<p>This will allow you to edit the configuration file for Chromium browser, find the line that look something like:<\/p>\n<pre>CHROMIUM_FLAGS=\"\"<\/pre>\n<p>and modify it with:<\/p>\n<pre>CHROMIUM_FLAGS=\"--ssl-version-min=tls1\"<\/pre>\n<p>Save and close the browser for the settings to take effect. You might have to sign in again if you have your browser synced.<\/p>\n<p><em><strong style=\"font-size: 20px;\">Disabling SSLv3 in Mozilla Firefox<\/strong><\/em><\/p>\n<p>If you use Mozilla also, as I do, then open your Firefox browser and type in the address bar:<\/p>\n<pre>about:config<\/pre>\n<p>This will prompt a warning to be careful, press OK.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2097\" src=\"http:\/\/www.designersgate.com\/blogs\/wp-content\/uploads\/2014\/11\/firefox-config-warning.png\" alt=\"Firefox warning when configuring by hand\" width=\"995\" height=\"394\" srcset=\"https:\/\/designersgate.com\/blog\/wp-content\/uploads\/2014\/11\/firefox-config-warning.png 995w, https:\/\/designersgate.com\/blog\/wp-content\/uploads\/2014\/11\/firefox-config-warning-600x238.png 600w, https:\/\/designersgate.com\/blog\/wp-content\/uploads\/2014\/11\/firefox-config-warning-300x119.png 300w, https:\/\/designersgate.com\/blog\/wp-content\/uploads\/2014\/11\/firefox-config-warning-768x304.png 768w\" sizes=\"auto, (max-width: 995px) 100vw, 995px\" \/><\/p>\n<p>In the search bar type in:<\/p>\n<pre>security.tls.version.min<\/pre>\n<p>From all the\u00a0\u00a0options that show up use\u00a0the one that actually says security.tls.version.min, double click in the value column which will prompt you a text field, if the value is not 1 then change this value to 1.<\/p>\n<p>Also you can install the Mozilla extension to disable this by default, <a title=\"Mozilla SSL Version Control Extension\" href=\"https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/ssl-version-control\/\" target=\"_blank\" rel=\"noopener noreferrer\">found it here<\/a>.<\/p>\n<p>With this done, you should be able to log in to your email accounts, use your Facebook and any other service that requires SSL encryption. The only thing this does is to use TLS1, TLS2 and TLS3 as the main options for secure communication and avoid using the compromised SSL version 3 service.<\/p>\n<p>For more information about the Poodle thread follow this <a title=\"Wikipedia - POODLE Vulnerability\" href=\"http:\/\/en.wikipedia.org\/wiki\/POODLE\" target=\"_blank\" rel=\"noopener noreferrer\">link<\/a> or read this <a title=\"Whitepaper on Poodle vulnerability\" href=\"https:\/\/www.openssl.org\/~bodo\/ssl-poodle.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">PDF<\/a> file. If you need to information in how to accomplish this in other browsers and operating systems, you can visit this pages:<\/p>\n<ol>\n<li><a title=\"Disabling SSLv3\" href=\"https:\/\/disablessl3.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/disablessl3.com\/<\/a><\/li>\n<li><a title=\"How do I patch\/workaround SSLv3 POODLE vulnerability (CVE\u00ad-2014\u00ad-3566)?\" href=\"http:\/\/askubuntu.com\/questions\/537196\/how-do-i-patch-workaround-sslv3-poodle-vulnerability-cve-2014-3566\" target=\"_blank\" rel=\"noopener noreferrer\">Ask Ubuntu thread &#8211; really good<\/a><\/li>\n<\/ol>\n<p>I hope this help you guys&#8230; Happy Coding and Happy Developing!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>With the latest news about the new SSL vulnerability, after the not so long ago HEARTBLEED vulnerability, now we are been threatened by a POODLE. Because of this, browsers are blocking the use of SSLv3 causing some HTTPS websites to stop responding, in my case either in Chromium and Firefox. I noticed that any other [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[13],"tags":[193,33,194,195,98,196],"class_list":["post-2095","post","type-post","status-publish","format-standard","hentry","category-tips","tag-chromium","tag-firefox","tag-openssl","tag-ssl","tag-ubuntu","tag-vulnerability"],"acf":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/designersgate.com\/blog\/wp-json\/wp\/v2\/posts\/2095","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/designersgate.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/designersgate.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/designersgate.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/designersgate.com\/blog\/wp-json\/wp\/v2\/comments?post=2095"}],"version-history":[{"count":0,"href":"https:\/\/designersgate.com\/blog\/wp-json\/wp\/v2\/posts\/2095\/revisions"}],"wp:attachment":[{"href":"https:\/\/designersgate.com\/blog\/wp-json\/wp\/v2\/media?parent=2095"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/designersgate.com\/blog\/wp-json\/wp\/v2\/categories?post=2095"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/designersgate.com\/blog\/wp-json\/wp\/v2\/tags?post=2095"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}