TLS handshake that kills Chrome(demo.cmrg.net)
demo.cmrg.net
TLS handshake that kills Chrome
https://demo.cmrg.net/
16 comments
Maybe put a warning (something in the title) which tells that opening the page may cause our browser to crash? I thought it would open a page where the issue is discussed, not a page which directly crashes my browser. (HN hides the subdomain: demo.cmrg.net, therefore removing the only indicator showing that this is a demo)
This does indeed kill Chrome (v33 on OS X 10.9.2). Firefox copes fine, with the error message ssl_error_weak_server_ephemeral_dh_key.
Anyone know what's going on here?
Anyone know what's going on here?
Tried it out from the console using Chromium on Linux. It's a segfault of some form, though it unfortunately doesn't log anything else to the terminal before segfaulting.
That's quite annoying. It doesn't indicate that clicking this link kills Chrome rather than a disclosure piece about something that could kill Chrome. I'd be even more annoyed if this crashed and lost unsaved work.
The corresponding bug report: https://code.google.com/p/chromium/issues/detail?id=348987
Does not kill Chrome Version 27.0.1453.110 on Redhat 6.4
Instead says:
"Server has a weak ephemeral Diffie-Hellman public key This error can occur when connecting to a secure (HTTPS) server. It means that the server is trying to set up a secure connection but, due to a disastrous misconfiguration, the connection wouldn't be secure at all!
In this case the server needs to be fixed. Google Chrome won't use insecure connections in order to protect your privacy."
Instead says:
"Server has a weak ephemeral Diffie-Hellman public key This error can occur when connecting to a secure (HTTPS) server. It means that the server is trying to set up a secure connection but, due to a disastrous misconfiguration, the connection wouldn't be secure at all!
In this case the server needs to be fixed. Google Chrome won't use insecure connections in order to protect your privacy."
I'm sure there's a perfectly good reason why I clicked on a link that told me it would kill my browser...
Yes, killed Chrome 33.0.1750.146 m on Win7 here.
Yes, killed Chrome 33.0.1750.146 m on Win7 here.
Wouldn't this potentially be eligible for an security award, and disclosing it this way negates that award?
Haha! Is there an actual link explaining the issue, not just the source? That's a fun demo.
[deleted]
Killed Google Chrome release 35.0.1862.2 Ubuntu unstable package too
[deleted]
Kills it on Windows 8 also. Chrome Version 33.0.1750.146 m
Did not kill chromium based epic browser.
That is very irresponsible.
Don't submit a direct link that crashes the whole browsers instead post a communication explaining the risks (also stop upvoting this!). It is also irresponsible since Google has a well publicized framework that enables responsible disclosure that this should have gone through first.
Don't submit a direct link that crashes the whole browsers instead post a communication explaining the risks (also stop upvoting this!). It is also irresponsible since Google has a well publicized framework that enables responsible disclosure that this should have gone through first.