Adam Caudill

Security Leader, Researcher, Developer, Writer, & Photographer

Fiddler2 – Now Available

A new version of the popular debugging proxy Fiddler has been announced. The new version, dubbed Fiddler2, adds support debugging HTTPS traffic just as you would unsecured HTTP traffic. Per the FAQs, this new version effectively runs a MITM attack to do its job, while this is the most effective way of doing this, there is the downside of the browser showing an error, though you should be able to continue by ignoring these warnings.

If you develop or maintain secure web sites, this enhanced version of Fiddler will be a great help. Though this is still an alpha version, it’s based on a fairly stable code base and seems to work well. This is one to keep an eye on.

Adam Caudill

Related Posts

  • Millions of Jobs

    It has been 20 years since I first used machine learning to solve a complex business problem. The underlying problem was simple: the company was selling a new service and wanted to know who was most likely to buy it. We had millions of records, and each record had hundreds of fields. A vast amount of data, but no idea how to extract insight from it. Countless hours from various data analysts had been invested into finding a pattern, but none was forthcoming.

  • Parasitic & Symbiotic Business Models

    Does your business model thrive as your customer thrives, or does it drain the life from your customers? After a recent1 conversation on the impact of improved privacy tools (i.e., the eventual elimination of third-party tracking cookies), I realized that the most significant effect of these improvements would be to companies with a parasitic business model. A business model which I see no problem in disrupting. For many years, the web has existed as an advertiser’s dream2 — minimal privacy limitations, technical controls that had little impact, and a strong lobbying arm that has been able to derail many efforts to improve the situation.

  • Write Like You Are Running Out of Time

    The cultural phenomenon that is Hamilton, brought back to the forefront due to its streaming release, is an artistic feat, but it also serves as an opportunity to refresh our memories on the history behind these characters, and look for opportunities to learn lessons that apply today. This is exactly what I’ve been doing. For all of his flaws, one thing that I have to respect about Alexander Hamilton (as well as his wife, Eliza) is the understanding of the long-term impact of the written word.

  • Looking for value in EV Certificates

    When you are looking for TLS (SSL) certificates, there are three different types available, and vary widely by price and level of effort required to acquire them. Which one you choose impacts how your certificate is treated by browsers; the question for today is, are EV certificates worth the money? To answer this, we need to understand what the differences are just what you are getting for your money. The Three Options For many, the choice of certificate type has more to do with price than type – and for that matter, not that many people even understand that there are real differences in the types of certificates that a certificate authority (CA) can issue.