Mozilla Dials Back on Firefox Opportunistic Encryption

Published: Apr 7, 2015
Updated: Feb 2, 2021
2 minute read
Mozilla Firefox security
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Mozilla has had a change of heart regarding opportunistic encryption—for now. The company rolled out its open-source Firefox 37 Web browser on March 31, with one of the key new features being a capability known as opportunistic encryption. However, due to a security issue related to opportunistic encryption, Mozilla disabled the feature in the Firefox 37.0.1 update released April 3.

The security issue is located in Mozilla’s HTTP Alternative Services (Alt-Svc) implementation, which is connected to the opportunistic encryption capability.

“If an Alt-Svc header is specified in the HTTP/2 response, Secure Sockets Layer (SSL) certificate verification can be bypassed for the specified alternate server,” Mozilla warned in its security advisory. “As a result of this, warnings of invalid SSL certificates will not be displayed, and an attacker could potentially impersonate another site through a man-in-the-middle (MTIM), replacing the original certificate with their own.”

Opportunistic encryption is designed to encrypt potentially sensitive data that would otherwise have been sent unencrypted and in the clear. The opportunistic encryption capability makes use of the new HTTP/2 protocol, which is the next generation of the HTTP protocol that dominates the Web today.

“Opportunistic encryption is a related but separate feature that depends on Alt-Svc,” Chad Weiner, director of product management at Mozilla, told eWEEK. “Opportunistic encryption was disabled because of its use of Alt-Svc.”

When asked whether the Alt-Svc vulnerability was a protocol problem or just a misconfiguration issue, Weiner explained that the issue is an implementation problem in Firefox Alt-Svc handling. There is currently an Internet Engineering Task Force (IETF) draft of the Alt-Svc approach. According to the IETF abstract, Alt-Svc enables “alternative service for HTTP, which allows an origin’s resources to be authoritatively available at a separate network location, possibly accessed with a different protocol configuration.”

Rather than try and quickly fix the Alt-Svc issue, Weiner said that Mozilla decided that the quickest and safest approach was to disable Alt-Svc.

“We plan to re-enable this feature once we’ve had time to fully investigate the issue,” Weiner said.

Advertisement

It’s not known at this point if Alt-Svc and the associated opportunistic encryption capability will be re-enabled in the Firefox 37 browser or if it will take until Firefox 38 for the feature to re-emerge. Mozilla develops Firefox on an agile rapid release cycle with new major milestone releases approximately every six weeks.

Firefox 38, currently in beta, is scheduled to debut May 12. However, it will be a significant release in that it is set to be the base for the next Firefox Extended Support Release (ESR), which is a version of Firefox that is maintained for approximately one year.

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。