Closed Bug 1458915 Opened 8 years ago Closed 5 years ago

Tracking protection blocks images hosted on pbs.twitter.com

Categories

(Core :: Privacy: Anti-Tracking, defect, P3)

59 Branch
defect

Tracking

()

RESOLVED DUPLICATE of bug 1628176

People

(Reporter: jonathan, Unassigned)

References

(Blocks 1 open bug, )

Details

(Whiteboard: [tp-social][tp-yellowlist-passive][tp-embedded-media])

User Story

twitter.com

Attachments

(2 files)

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:59.0) Gecko/20100101 Firefox/59.0 Build ID: 20180323154952 Steps to reproduce: Sprout Social is a social media management platform used by organizations to talk to people on social media, for purposes like support channel. Tracking Protection is interfering with the operation of our product, and I think this is unintended. Actual results: Tracking Protection is blocking the loading of social network profile images. These images are desired by the users of Sprout/Firefox and we'd like them to load. Demo: https://cl.ly/2H2h0f2c4623 Expected results: We can train our users to whitelist our domains (app.sproutsocial.com and app.getbambu.com) but we have ~50,000 daily users and would like more of them, so maybe you could add us to your whitelist? I support and understand the importance of the Tracking Protection feature. In this case, 100% of our users are intending to interact with the social networks while in our app, so I hope you can help us out.
Component: Untriaged → Tracking Protection
I can't test this because the actual app is behind a login, but I suspect that this is due to the images being hosted on third-party servers that are identified as trackers on the Disconnect list. Jonathan, can you confirm this by opening the devtools and copying the tracking protection messages you see there? If that's the case, there's not much we can do. The purpose of TP in Firefox is to prevent network loads from third-party trackers. Unless a social provider is able to host profile images on a domain where they don't perform third-party tracking, then Disconnect won't unblock them.
Flags: needinfo?(jonathan)
The Twitter profile images and twitter message contents being blocked are hosted by Twitter at pbs.twimg.com We are a social media management platform, and the people using the application know they are interacting with Twitter content, which makes them a first party, not a third party, at least in intent. For example: - https://cl.ly/3a052s2X0j0O - https://cl.ly/3K3O3l2c3M3Z - https://cl.ly/0K260F3Z1g1X Here's the console logs -- I see Tracking Protection block messages for New Relic, Google Analytics, Zendesk and Intercom, which are all appropriate. - https://cl.ly/15143L2T433M Also: we have a 30-day free trial, so please take advantage if it is helpful to see this yourself.
Flags: needinfo?(jonathan)
The resources that are blocked are all hosted on pbs.twitter.com and so they get blocked because twitter.com is on the Disconnect list: https://github.com/mozilla-services/shavar-prod-lists/blob/f16248d7f33367bb3c48d72fb32fdb239dbe0c8e/disconnect-blacklist.json#L8965 I don't know enough about Twitter to know whether or not they use that hostname for tracking as well as hosting images. You could try reporting it to Disconnect: https://disconnect.me/trackerprotection. As far as the Firefox feature is concerned, we don't change the list. So while the effect is unfortunate on your site, this is the expected behavior. Another option, though there is certainly a cost, would be for your backend to proxy/cache the images through. That will prevent Twitter from setting cookies on your users and it will prevent tracking protection from blocking these images. If you wanted to only proxy when needed, you can look for the DNT header. Tracking protection forces the DNT header to be turned ON.
Blocks: tp-breakage
Component: Tracking Protection → Desktop
Product: Firefox → Tech Evangelism
Summary: False positive by Firefox tracking protection blocks image loads → Tracking protection blocks images hosted on pbs.twitter.com
Whiteboard: tp-base
Version: 59 Branch → Firefox 59
Thanks for the follow up and prompt responses throughout.
Priority: -- → P5
Blocks: tpimages
No longer blocks: tp-breakage
User Story: (updated)
Whiteboard: tp-base → tp-social
Product: Tech Evangelism → Web Compatibility

It seems like the Twitter domains from the Disconnect blacklist result in Firefox not showing Twitter content in at least some cases. This seems like a horrible experience even for savvy users.

Examples:

I went to http://twitter.com/mozilla and clicked the menu for the most recent tweet to get the embed code. I wrapped that in an <html> and <body> tag, then tried to view the result in Firefox, but the JS the embed snippet includes is blocked, resulting in the content being completely unstyled:

The resource at “https://platform.twitter.com/widgets.js” was blocked because content blocking is enabled.

Here's a direct link to an image from a tweet from the Firefox account: https://pbs.twimg.com/media/D3E96MwX0AAxUvA.jpg:large

If you try to directly place that on a page (e.g. <img src="https://pbs.twimg.com/media/D3E96MwX0AAxUvA.jpg:large">), it will also be blocked:

The resource at “https://pbs.twimg.com/media/D3E96MwX0AAxUvA.jpg:large” was blocked because content blocking is enabled.

Here's a URL where I put both examples: http://sheap.net/~fyren/twitter.html

What is the user to do? As far as I can tell, there's no way to modify the blacklist or whitelist domains, so even experienced users are stuck. The less experienced user probably just views this as Firefox being broken or content blocking being a detriment.

Component: Desktop → Protections UI
Product: Web Compatibility → Firefox
Version: Firefox 59 → 59 Branch

We really need to do something here, if only to show something besides a blocked image (image with a shield and an explanation?) and possibility the ability to right click on the image and unblock the domain.

We just look broken.

Component: Protections UI → Privacy: Anti-Tracking
Product: Firefox → Core

This is another case like bug 1475959 where we should be able to resolve by allowing the user to yellow-list Twitter resources by providing an opt-in placeholder on the images in question, and shimming platform.js to allow users to similarly see any other resources like posts.

Blocks: tp-twitter
Whiteboard: tp-social → [tp-social][tp-yellowlist-passive][tp-embedded-media]
Priority: P5 → P3

If embedded Twitter contents require cookies from twitter.com (third party cookie) to embed contents, this is the right behavior.

No longer blocks: tp-twitter
Status: UNCONFIRMED → RESOLVED
Closed: 5 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: