<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Gemal&apos;s Psyched Blog - Comments on bugzilla.mozilla.org protected with SSL encryption</title>
		<link>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/index.html</link>
		<description>This evening I installed an SSL certificate for bugzilla.mozilla.org and started redirecting all Bugzilla URLs to their encrypted equivalents. You now need an SSL-enabled browser to access bugzilla.mozilla.org, and communication between the server and its users is encrypted while in...</description>
		<language>en-us</language>
		<copyright>Copyright 2009</copyright>
		<lastBuildDate>Wed, 28 Jan 2009 22:48:53 +0100</lastBuildDate>
		<pubDate>Mon, 16 Feb 2009 09:36:53 +0100</pubDate>
		<generator>http://www.movabletype.org/?v=3.17</generator>
		<docs>http://blogs.law.harvard.edu/tech/rss</docs>
		<image>
			<link>http://gemal.dk/</link>
			<url>http://gemal.dk//pics/favicon.png</url>
			<title>Gemal&apos;s Psyched Blog</title>
		</image>
		
			<item>
				<title>By Fabián Rodríguez</title>
				<description>This is great news! It&apos;s nice to see Bugzilla&apos;s resources protection increased.</description>
				<content:encoded><![CDATA[<p>This is great news! It's nice to see Bugzilla's resources protection increased.</p>]]></content:encoded>
				<link>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/#comment1?from=rss-comment</link>
				<guid>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/#comment1</guid>
				<pubDate>Tue, 21 Sep 2004 20:40:02 +0100</pubDate>
				<author>
					<name>Fabián Rodríguez</name>
					<email>magicfab@gmail.com</email>
				</author>
			</item>
		
			<item>
				<title>By minghong</title>
				<description>But visiting http://bugzilla.mozilla.org doesn&apos;t redirect me to https://bugzilla.mozilla.org. Is it intended? :-P</description>
				<content:encoded><![CDATA[<p>But visiting <a href="http://bugzilla.mozilla.org" rel="nofollow">http://bugzilla.mozilla.org</a> doesn't redirect me to <a href="https://bugzilla.mozilla.org." rel="nofollow">https://bugzilla.mozilla.org.</a> Is it intended? :-P</p>]]></content:encoded>
				<link>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/#comment2?from=rss-comment</link>
				<guid>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/#comment2</guid>
				<pubDate>Tue, 21 Sep 2004 20:46:31 +0100</pubDate>
				<author>
					<name>minghong</name>
					<email>minghong@gmail.com</email>
				</author>
			</item>
		
			<item>
				<title>By Neil</title>
				<description>I have one question for you... why?  Why has everything been moved over to a secure connection?I could see if for security related bugs but other then that I can&apos;t think of any reason why you&apos;d want to do this.- Can&apos;t submit from Thunderbird to this list :(</description>
				<content:encoded><![CDATA[<p>I have one question for you... why?  Why has everything been moved over to a secure connection?</p>

<p>I could see if for security related bugs but other then that I can't think of any reason why you'd want to do this.</p>

<p>- Can't submit from Thunderbird to this list :(</p>]]></content:encoded>
				<link>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/#comment3?from=rss-comment</link>
				<guid>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/#comment3</guid>
				<pubDate>Tue, 21 Sep 2004 21:00:24 +0100</pubDate>
				<author>
					<name>Neil</name>
					<email>neil@eightlines.com</email>
				</author>
			</item>
		
			<item>
				<title>By berkut</title>
				<description>Will this reduce the ammount of spam bugzilla account email addresses get in anyway?The least they can do is hide email addresses for anyone that&apos;s not loged in..</description>
				<content:encoded><![CDATA[<p>Will this reduce the ammount of spam bugzilla account email addresses get in anyway?</p>

<p>The least they can do is hide email addresses for anyone that's not loged in..</p>]]></content:encoded>
				<link>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/#comment4?from=rss-comment</link>
				<guid>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/#comment4</guid>
				<pubDate>Tue, 21 Sep 2004 21:57:00 +0100</pubDate>
				<author>
					<name>berkut</name>
					<email>a@b.com</email>
				</author>
			</item>
		
			<item>
				<title>By Jeff Walden</title>
				<description>Two reasons, Neil:It&apos;s the bugs which deal with relations with other companies.  Say, for instance, the Mozilla Foundation has a bug on working with Google (hypothetically, of course).  The bug can be marked as private to only a certain group of Bugzilla accounts easily.  However, if someone&apos;s eavesdropping on even one connection with the bug page using a properly permissioned account, the privateness of the bug is compromised.Without a secure connection, it&apos;s also possible to do the same thing for login attempts.  Find someone with the proper permissions and you can see anything.Personally, I&apos;d guess securing Bugzilla connections is something that&apos;s been strongly encourage by outside companies more than by insiders with the Foundation itself (tho doubtless they played at least some part in making this happen).</description>
				<content:encoded><![CDATA[<p>Two reasons, Neil:</p>

<p>It's the bugs which deal with relations with other companies.  Say, for instance, the Mozilla Foundation has a bug on working with Google (hypothetically, of course).  The bug can be marked as private to only a certain group of Bugzilla accounts easily.  However, if someone's eavesdropping on even one connection with the bug page using a properly permissioned account, the privateness of the bug is compromised.</p>

<p>Without a secure connection, it's also possible to do the same thing for login attempts.  Find someone with the proper permissions and you can see anything.</p>

<p>Personally, I'd guess securing Bugzilla connections is something that's been strongly encourage by outside companies more than by insiders with the Foundation itself (tho doubtless they played at least some part in making this happen).</p>]]></content:encoded>
				<link>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/#comment5?from=rss-comment</link>
				<guid>http://gemal.dk/blog/2004/09/21/bugzillamozillaorg_protected_with_ssl_encryption/#comment5</guid>
				<pubDate>Tue, 21 Sep 2004 22:38:56 +0100</pubDate>
				<author>
					<name>Jeff Walden</name>
					<email>jwalden@mit.edu</email>
				</author>
			</item>
		
	</channel>
</rss>

