duckduckgo/Android

handling of SSL/TLS errors

jmue opened this issue · 1 comments

jmue commented

DDG does not show any cert chain errors, it simply do not load such sites. This is bad, as the user do not get informed about the reason for that (like a not trusted CA, expired certificate or self signed certificate). It is even worse, as DDG shows a green lock icon with 'Encrypted connection' text beside in the privacy dashboard.
https://badssl.com/ hosts a set of cert chain error tests.

Hello, we are reviewing old issues and we are going to close this one as we have plans to improve certificate handling.

#963
#1063