Sunday, 21 July 2019

Re: The 3.9 Release

In article <20190721164517.iurgjow5ipdsofkb@kyllikki.org>,
Vincent Sanders <vince@netsurf-browser.org> wrote:
> I am pleased to announce the latest release of NetSurf is now available.

> NetSurf 3.9 features support for CSS Media Queries (level 4) and
> improvements to JavaScript handling.

> Also included are many bug fixes and improvements.

> We recommend all users upgrade to NetSurf 3.9.

Many thanks, this is much appreciated.

--
_____________________________________________________________________

Brian Jordan
Virtual RPC-AdjustSA on Windows 10 Pro 64-bit
RISC OS 6.20
_____________________________________________________________________

Re: The 3.9 Release

On 21 Jul 2019 Vincent Sanders <vince@netsurf-browser.org> wrote:

> I am pleased to announce the latest release of NetSurf is now available.

> NetSurf 3.9 features support for CSS Media Queries (level 4) and
> improvements to JavaScript handling.

> Also included are many bug fixes and improvements.

> We recommend all users upgrade to NetSurf 3.9.

I have 3.10 (Dev CI#4720) at the moment here on RISC OS. Sorry about my
ignorance, but does this include these improvements?

Many thanks to the developers for all their work.

Best wishes,

Peter.

--
Peter Young (zfc Hg) and family
Prestbury, Cheltenham, Glos. GL52, England
http://pnyoung.orpheusweb.co.uk
pnyoung@ormail.co.uk

The 3.9 Release

I am pleased to announce the latest release of NetSurf is now available.

NetSurf 3.9 features support for CSS Media Queries (level 4) and
improvements to JavaScript handling.

Also included are many bug fixes and improvements.

We recommend all users upgrade to NetSurf 3.9.

--
Regards Vincent
http://www.kyllikki.org/

Friday, 5 July 2019

Re: TLS Security NS 3.8

My comment was based on the posted information that said it was still enabled. Good that it isn't.

TLS1.0 and 1.1 are being disabled by the major browsers in the first half of next year so shouldn't cause any disruption, as long as we're not first :)

Chris
(sorry, can't reply inline on this client)
On Jul 5, 2019, 10:53 +0100, John-Mark Bell <jmb@netsurf-browser.org>, wrote:
On 05/07/2019 10:00, Chris Young wrote:
I will note that we should be disabling SSL3 too,

Like this?:
https://git.netsurf-browser.org/netsurf.git/commit/?id=b2242c57e17fa71734c60aa9872970f4477a4bd5

and TLS 1.0 and 1.1 next year.
Possibly. It really depends how much breaks as a result.


J.

Re: TLS Security NS 3.8

On 05/07/2019 10:00, Chris Young wrote:
> I will note that we should be disabling SSL3 too,

Like this?:
https://git.netsurf-browser.org/netsurf.git/commit/?id=b2242c57e17fa71734c60aa9872970f4477a4bd5

> and TLS 1.0 and 1.1 next year.
Possibly. It really depends how much breaks as a result.


J.

Re: TLS Security NS 3.8

On 05/07/2019 05:01, ferrite61@yahoo.com wrote:
> Little more than a week ago I posted about the Security Certs for NS 3.8. I was not aware at that time that NS 3.9 was already available (I was using a link provided for D/L of 3.8). Since there has been other bugs/problems, I thought to provide the actual results. The location of this Qualys Client Test is
>
> https://www.ssllabs.com/ssltest/viewMyClient.html
>
> Presuming the Certs are within NS 3.8, it would appear that the "weak" certs be removed for added security. I did not receive an answer to the question if the certs are tapped from the Distribution or the Browser. So, here are the results...

This test does nothing with certificates. However, the answer as to
which certificates get used depends upon the platform you are using. If
Linux, it will, by default, use the standard system-wide CA certificate
store (usually found in /etc/ssl/certs).

>
> Protocols
> TLS 1.3 No
> TLS 1.2 Yes*
> TLS 1.1 Yes*
> TLS 1.0 Yes*
> SSL 3 Yes*
> SSL 2 No

These are not an accurate reflection of reality -- the test relies on
support for more Javascript (and associated things) than NetSurf has.

NetSurf supports TLS1.0/1.1/1.2. SSL2/3 are disabled. TLS1.2 will always
be used by preference.

> Cipher Suites (in order of preference)
> TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030) Forward Secrecy 256
> TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 (0xc02c) Forward Secrecy 256
> TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028) WEAK 256
> TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 (0xc024) WEAK 256
> TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f) Forward Secrecy 128
> TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (0xc02b) Forward Secrecy 128
> TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027) WEAK 128
> TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 (0xc023) WEAK 128
> TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (0x9f) Forward Secrecy 256
> TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 (0x6b) WEAK 256
> TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (0x9e) Forward Secrecy 128
> TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 (0x67) WEAK 128
> TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014) WEAK 256
> TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (0xc00a) WEAK 256
> TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013) WEAK 128
> TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (0xc009) WEAK 128
> TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x39) WEAK 256
> TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x33) WEAK 128
> TLS_RSA_WITH_AES_128_CBC_SHA (0x2f) WEAK 128
> TLS_EMPTY_RENEGOTIATION_INFO_SCSV (0xff) -
> (1) When a browser supports SSL 2, its SSL 2-only suites are shown only on the very first connection to this site. To see the suites, close all browser windows, then open this exact page directly. Don't refresh.

Qualys currently marks all CBC ciphersuites as "weak", as a result of a
preponderance of padding oracle issues in implementations. If built
against a modern OpenSSL, there are no currently known issues here. CBC
suites will remain enabled in NetSurf until such time as they are not
required for compatibility with web servers that don't support GCM.


J.

Re: TLS Security NS 3.8

I will note that we should be disabling SSL3 too, and TLS 1.0 and 1.1 next year.

(moved to dev list where it is more appropriate)

Chris
On Jul 5, 2019, 05:32 +0100, ferrite61@yahoo.com, wrote:
Little more than a week ago I posted about the Security Certs for NS 3.8. I was not aware at that time that NS 3.9 was already available (I was using a link provided for D/L of 3.8). Since there has been other bugs/problems, I thought to provide the actual results. The location of this Qualys Client Test is

https://www.ssllabs.com/ssltest/viewMyClient.html

Presuming the Certs are within NS 3.8, it would appear that the "weak" certs be removed for added security. I did not receive an answer to the question if the certs are tapped from the Distribution or the Browser. So, here are the results...


Protocols
TLS 1.3 No
TLS 1.2 Yes*
TLS 1.1 Yes*
TLS 1.0 Yes*
SSL 3 Yes*
SSL 2 No

Cipher Suites (in order of preference)
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030) Forward Secrecy 256
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 (0xc02c) Forward Secrecy 256
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028) WEAK 256
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 (0xc024) WEAK 256
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f) Forward Secrecy 128
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (0xc02b) Forward Secrecy 128
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027) WEAK 128
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 (0xc023) WEAK 128
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (0x9f) Forward Secrecy 256
TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 (0x6b) WEAK 256
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (0x9e) Forward Secrecy 128
TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 (0x67) WEAK 128
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014) WEAK 256
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (0xc00a) WEAK 256
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013) WEAK 128
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (0xc009) WEAK 128
TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x39) WEAK 256
TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x33) WEAK 128
TLS_RSA_WITH_AES_128_CBC_SHA (0x2f) WEAK 128
TLS_EMPTY_RENEGOTIATION_INFO_SCSV (0xff) -
(1) When a browser supports SSL 2, its SSL 2-only suites are shown only on the very first connection to this site. To see the suites, close all browser windows, then open this exact page directly. Don't refresh.

Protocol Details
Server Name Indication (SNI) Yes
Secure Renegotiation Yes
TLS compression No
Session tickets Yes
OCSP stapling No
Signature algorithms SHA512/RSA, SHA512/DSA, SHA512/ECDSA, SHA384/RSA, SHA384/DSA, SHA384/ECDSA, SHA256/RSA, SHA256/DSA, SHA256/ECDSA, SHA224/RSA, SHA224/DSA, SHA224/ECDSA, SHA1/RSA, SHA1/DSA, SHA1/ECDSA
Named Groups secp256r1, secp521r1, brainpoolP512r1, brainpoolP384r1, secp384r1, brainpoolP256r1, secp256k1, sect571r1, sect571k1, sect409k1, sect409r1, sect283k1, sect283r1
Next Protocol Negotiation Yes
Application Layer Protocol Negotiation No
SSL 2 handshake compatibility No


Regards
Paul S. in CT