Where did you install Firefox from? Help Mozilla uncover 3rd party websites that offer problematic Firefox installation by taking part in our campaign. There will be swag, and you'll be featured in our blog if you manage to report at least 10 valid reports!

Tìm kiếm hỗ trợ

Tránh các lừa đảo về hỗ trợ. Chúng tôi sẽ không bao giờ yêu cầu bạn gọi hoặc nhắn tin đến số điện thoại hoặc chia sẻ thông tin cá nhân. Vui lòng báo cáo hoạt động đáng ngờ bằng cách sử dụng tùy chọn "Báo cáo lạm dụng".

Learn More

HTTPS, Support.mozilla.org versus Firefox realeses

  • 2 trả lời
  • 1 gặp vấn đề này
  • 1 lượt xem
  • Trả lời mới nhất được viết bởi Mace2

more options

Why does Mozilla support HTTPS with E.V (Green https) for the forum but does not support Https E.V. for download of Firefox versions from "https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/"

Since downloading the correct authenticated version of Firefox is important to prevent counterfeit Firefox browsers. Why is the download site "https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/" not HTTPS E.V ?

Why does Mozilla support HTTPS with E.V (Green https) for the forum but does not support Https E.V. for download of Firefox versions from "https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/" Since downloading the correct authenticated version of Firefox is important to prevent counterfeit Firefox browsers. Why is the download site "https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/" not HTTPS E.V ?

Tất cả các câu trả lời (2)

more options

Hello!

The EV certificate has as minimal to no purpose when it comes to downloading Firefox. No user authentication or logging info is being sent out so there is less security risks. Secondly, even if there was an EV certificate for the Firefox download it would not play any role in protecting the user for a "counterfeit" Firefox. In cases for this website will post the md5 hash or sha-512 hash of the file so when the user downloads the file they are able to see if the hash matches. In any case, the chances of someone uploading a "counterfeit" Firefox on to the FTP server is slim to none.

more options

I strongly disagree Microbot. Mozilla is paying for the privilege to provide the service of a high Https EV just like banks. Since they Mozilla is already using it they should place the "https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/" under that additional protection.