Skip to content

Comment on Firesheep, a day later

Comments

> In the past, an SSL service required a dedicated IP address. This isn’t true any more with the advent of Server Name Indication (RFC 3546) and improvements in TLS.

If any of your users are using Internet Explorer on Windows XP, then this seems to still be true, alas - http://www.alexanderkiel.net/2008/04/22/status-of-tls-sni/

This isn't an issue for the likes of Facebook, of course, but it is a problem for sites small enough to be on shared hosting.

About 60% of client computers are running Windows XP, according to http://marketshare.hitslink.com/operating-system-market-shar...

Clearly they're not all running Internet Explorer, but equally clearly it's far too early to lock out clients that lack SNI.

Since all of the browsers on Windows XP use the Windows SChannel API none of them support SNI. That includes the beloved Google Chrome, FireFox, and Safari. (Not sure about Opera on Windows XP)

http://en.wikipedia.org/wiki/Server_Name_Indication#Support

That is unfortunately an issue that only Microsoft can rectify unless developers on the Windows platform want to take the time and effort to re-implement parts of the SChannel API.

> none of them support SNI. That includes (..) Google Chrome, FireFox, and Safari

You're wrong about Firefox! I'm writing this from an XP box and I've just tested a SNI site with Firefox 3.6. It works with SNI just fine.

> Not sure about Opera

Opera also works with SNI.

My apologies regarding FireFox. I don't use FireFox and when I do it is from a Mac OS X machine.

Either way Internet Explorer doesn't support it and as such it is still a no-go from a usability stand point since XP still has such a large market share.

He's just saying that Facebook can deal with it much better than a small shop.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.