unfortunately I can’t access your homepage http://www.agilebits.com. Not with Safari or Firefox.

joojoo
joojoo
Community Member

Both browsers deny access cause of „insecure“ connection.
OSX 10.11.3.


1Password Version: Not Provided
Extension Version: Not Provided
OS Version: Not Provided
Sync Type: Not Provided
Referrer: forum-search:unfortunately I can’t access your homepage http://www.agilebits.com/ I wanted to install your 1P-add-in into firefox 44.0.2 for Mac El Capitan.

Comments

  • nathanvf
    nathanvf
    1Password Alumni

    Hi @joojoo,

    Have you tried https://agilebits.com? That is a secure connection because it uses HTTPS to connect to the AgileBits website.

    Hope this helps.

  • joojoo
    joojoo
    Community Member

    yes. I tried both.

  • joojoo
    joojoo
    Community Member

    The same as I use the link above (Main Site):
    Firefox message in German:
    "_Fehler: Gesicherte Verbindung fehlgeschlagen

    Die Verbindung zu agilebits.com wurde unterbrochen, während die Seite geladen wurde.

    Die Website kann nicht angezeigt werden, da die Authentizität der erhaltenen Daten nicht verifiziert werden konnte.
    Kontaktieren Sie bitte den Inhaber der Website, um ihn über dieses Problem zu informieren._"
    

    Translation:
    "Error: Secure Connection Failed

    The connection to agilebits.com was interrupted while the page was loading.

         The site can not be shown because the authenticity of the received data could not be verified.
         Please contact the website owners to inform them of this problem."

  • littlebobbytables
    littlebobbytables
    1Password Alumni

    Hello @joojoo,

    Do you use any anti-virus software that has web scanning functionality? Some anti-virus software will scan secure connections but they can only do this by using a certificate and attempting to place it in the certificate chain of every site you visit. Our site though is set up so that if anything attempts to inject itself into the chain that it should be considered at risk, a sensible approach I'm sure you agree.

    Could this be a possibility at all? If you have an anti-virus product you could try disabling the web protection (it may also require disabling a browser extension if there is one) and seeing if you can then visit our site.

    Do please keep us updated as if it isn't this we'll want to continue working with you to resolve it.

  • joojoo
    joojoo
    Community Member

    thanks for this advice! It works. I use Avast (anti-virus software). To deactivate the add-on module inside the browers did not help. I have to define your server address inside the Mac App module "Web-Schutz" to get access to your web site.

  • Great! Glad to hear it's working again. AV software is often a double-edged sword. It protects you, but sometimes a little too much. :wink:

    Cheers,
    Kevin

  • AGAlumB
    AGAlumB
    1Password Alumni
    edited March 2016

    Ah! I knew that sounded familiar. For anyone else who might run into a similar issue, "Web-Schutz" is the German name of the same (English) "Web Shield" feature from Avast. Avast is decrypting the traffic in both directions to analyze it, and then re-encrypting it. From the Avast blog:

    How Avast’s HTTPS scanning feature works (the short version)
    Avast is able to detect and decrypt TLS/SSL protected traffic in our Web-content filtering component. To detect malware and threats on HTTPS sites, Avast must remove the SSL certificate and add its self-generated certificate. Our certificates are digitally signed by Avast’s trusted root authority and added into the root certificate store in Windows and in major browsers to protect against threats coming over HTTPS; traffic that otherwise could not be detected.

    The problem with this practice is that it means connections that are presumed both secure and private are neither. In these cases, the communications you're sending are going through an intermediary (Avast). The expectation is that when you see the HTTPS and/or 'padlock' icon in the address bar, that you're communicating directly with that site and no one else; but that simply isn't true if another entity can use the secure connection you've established with them instead to decrypt your communications.

This discussion has been closed.