SSleuth

Author(s):



Please Note : SSleuth is not compatible with Firefox 57+ due to a missing API from Mozilla. Mozilla bug 1322748

SSleuth was developed to rate the cipher suites used in an SSL/TLS connection. The project maintains a list of cipher suite algorithms that are shipped with Firefox and a rating for each. An overall rating for any secure page visited by the user will be computed and displayed next to the URL. This is an attempt to enhance cipher suites and certificate visibility of the user, by rating the parameters and color coding it.
The add-on panel also gives information on perfect forward secrecy, Firefox connection status and the certificate details. For a quick view of SSleuth panel use the keyboard shortcut 'Ctrl' + 'Shift' + '}'

Find more details at the project page : https://github.com/sibiantony/ssleuth

Update - 4th Aug 2016
* Support for e10s is in.
* The certificate fingerprint will now show SHA-2 instead of SHA-1.
* Added support for ChaCha20-Poly1305.
* Removed support for older versions of Firefox < 42.0. If you have a Firefox version older than 42.0, the add-on will not be upgraded. Please consider moving to a recent version of Firefox.
* Preferences right-click menu has been removed.

Update - 31st Oct 2015
* Minor bug fixes.
* French translation (Thanks to Thomas PORTASSAU)
* Please note : the multi-process version of Firefox (e10s) is not fully supported.There are many things broken (Domains tab doesn't work, tab change doesn't reflect in main panel). If you're using e10s, you may need to reload the current page to see the main panel information.


Update - 13th April 2015
* Average domains rating : Users with domains observer enabled will see a tiny notification icon and rating numeric in the panel next to the star ratings. This is an average rating for all the cross-domain requests. The icon will also turn red if there are insecure (unencrypted) requests, or if the average rating is less than 5 out of 10.
* Copy to clipboard: A new clipboard icon is visible in the panel next to the preferences icon for copying text in the panel main view.
* HTTP/unencrypted pages will be notified in red from now on.
* AES 128 and 256 are ranked the same. GCM suites ranked highest.
* German translations (Thanks to Jei Four)
* Added 'Reset all', 'Custom list' buttons in the panel ciphersuites tab.
* Toggle urlbar notifier colorizing from preferences.


Update - 17th October 2014
* New release - version 0.3.2 has the SSL/TLS protocol version displayed on the main panel. Since many people had been asking for this feature, and in the wake of POODLE attack, it could be beneficial for users to quickly see the protocol version.
- requires Firefox 29+
- It is necessary to have the SSleuth Domains observer enabled [default = enabled]
- the protocol version is obtained from an interface which wouldn't work for cached HTTP content. So it might be required to do cache-overriding reload of the page to see the connection SSL/TLS version

* The Domains tab now occupies the full height of the panel. (The domains feature is still in beta. Expect changes in future)
* + Other minor bug fixes.

Update - 19th July 2014
This release brings in some major features and improvements
* The certificate signature algorithm, public key size are visible.
* Signature algorithm is included for overall ratings.
* An HTTP observer to monitor background requests and grouped per domain. Can be enabled/disabled from preferences. (Beta)
* The panel UI is split to 3 tabs - a main tab for the general content, a domains tab and another for toggling cipher suites.
* The cipher suites toggling will now result in automatic page reload.
* A URL bar colorizing option - as per the rating (Disabled by default).

Update - 2nd May 2014
* The new version 0.2.4 brings in restartless installation and immediate preferences changes.
* The panel information is slightly re-arranged, and the visibility of some cipher suite parameters/certificate parameters can be toggled in preferences.
* The ratings for individual items are displayed next to them
* The rating mechanism is configurable now! More details at project wiki..
* The preferences are moved to a tab and is accessible from the notifier right-click menu.
* Support for enabling/disabling cipher suites. A list of cipher suites can be created, and the new list will show up in the right click menu of the notifier. Do a reload overriding cache (Shift+Ctrl+R) after changing states. Read more about enabling/disabling cipher suites..
* Optional display of SHA-1 fingerprint of the certificate.

Download files:

ssleuth-0.1.3.1-signed.xpi
ssleuth-0.1.4.1-signed.xpi
ssleuth-0.2.4.1-signed.xpi
ssleuth-0.3.1.1-signed.xpi
ssleuth-0.3.2.1-signed.xpi
ssleuth-0.3.3.1-signed.xpi
ssleuth-0.3.4.1-signed.xpi
ssleuth-0.4.2.1-signed.xpi
ssleuth-0.4.3.xpi
ssleuth-0.4.4.xpi
ssleuth-0.4.5.xpi
ssleuth-0.5.1.xpi
ssleuth-0.5.3.xpi


This page is part of the LegacyCollector website.
Disclaimer: All material on this site is property of their respective owners and available under
open licenses to the best of our knowledge. If you are an author and would like anything removed,
then please write an e-mail to legacy [at] collector dot org.