Closed Bug 1610431 Opened 4 years ago Closed 4 years ago

IBM idaas site is blocked by Firefox 71

Categories

(Core :: Privacy: Anti-Tracking, defect, P1)

72 Branch
defect

Tracking

()

RESOLVED FIXED

People

(Reporter: nalini.muthuraajan, Assigned: englehardt)

References

(Blocks 1 open bug)

Details

Attachments

(4 files)

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:72.0) Gecko/20100101 Firefox/72.0
Firefox for Android

Steps to reproduce:

We are trying to access the MCMP public site (https://acme.multicloud-ibm.com/aiops/client/inventory) using IBM ID in Firefox 71. Though I login using my IBM credentials. The Kibana reports under iFrame is not opening and it is showing the idaas site is blocked because cross site tracking cookies. .

Actual results:

The MCMP application is working in Firefox version 68. Recent cookie policy changes in Firefox version 71 blocking idaas site with cross site tracking issue.

Expected results:

The firefox 71 should allow the idaas site

So IBM as a third party is blocked from using cookies on that site? Does it work when you turn ETP off by clicking on the blue toggle button in the panel in your screenshot? Also, since I can not access the linked site, can you please show us a screenshot of the blocked resources (click on "Cross-Site Tracking Cookies" in the panel)?

Thanks!

Blocks: etp-breakage
Group: firefox-core-security
Component: Untriaged → Privacy: Anti-Tracking
Flags: needinfo?(nalini.muthuraajan)
Product: Firefox → Core
Flags: needinfo?(nalini.muthuraajan)

added har file from Firefox 7 1 for your reference

(In reply to nalini.muthuraajan from comment #0)

Created attachment 9121975 [details]
Screenshot 2020-01-06 at 11.42.17 PM.png

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:72.0) Gecko/20100101 Firefox/72.0
Firefox for Android

Steps to reproduce:

We are trying to access the MCMP public site using IBM ID in Firefox 71. Though I login using my IBM credentials. The Kibana reports under iFrame is not opening and it is showing the idaas site is blocked because cross site tracking cookies. .

Actual results:

The MCMP application is working in Firefox version 68. Recent cookie policy changes in Firefox version 71 blocking idaas site with cross site tracking issue.

Expected results:

The firefox 71 should allow the idaas site

Steve, is this a list issue, i.e. should these domains be associated?

Flags: needinfo?(senglehardt)

Looks like this multicloud domain is probably owned by IBM, meaning that it should be added to IBM's entity on the entitylist. I've filed https://github.com/disconnectme/disconnect-tracking-protection/issues/136 with Disconnect to request review. I'll give updates here as I receive them.

Assignee: nobody → senglehardt
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Flags: needinfo?(senglehardt)
Priority: -- → P1

Hi Team,
Any further updates on this issue. Seems it is severity issue for us now.

Regards,
Nalini

Peter, any chance you could please check in with the Disconnect folks to see if there is an update available on this? Thanks!

Flags: needinfo?(stpeter)

Team.. seems the github issue is closed now. Can you share the patch no or Firefox version number to test this change

(In reply to nalini.muthuraajan from comment #12)

Team.. seems the github issue is closed now. Can you share the patch no or Firefox version number to test this change

We will deploy the new list update today. I'll follow up once we do.

sure. Thank you.

This should now be fixed in all Firefox branches. You can confirm that you have new entitylist by going to about:url-classifier, changing the list type to whitelist and searching for https://multicloud-ibm.com/?resource=ibm.com.

cryptomining-annotation	
URI: https://multicloud-ibm.com/?resource=ibm.com
List of tables: mozstd-trackwhite-digest256
cryptomining-protection	
URI: https://multicloud-ibm.com/?resource=ibm.com
List of tables: mozstd-trackwhite-digest256
fingerprinting-annotation	
URI: https://multicloud-ibm.com/?resource=ibm.com
List of tables: mozstd-trackwhite-digest256
fingerprinting-protection	
URI: https://multicloud-ibm.com/?resource=ibm.com
List of tables: mozstd-trackwhite-digest256
socialtracking-annotation	
URI: https://multicloud-ibm.com/?resource=ibm.com
List of tables: mozstd-trackwhite-digest256
socialtracking-protection	
URI: https://multicloud-ibm.com/?resource=ibm.com
List of tables: mozstd-trackwhite-digest256
tracking-protection	
URI: https://multicloud-ibm.com/?resource=ibm.com
List of tables: mozstd-trackwhite-digest256
tracking-annotation	
URI: https://multicloud-ibm.com/?resource=ibm.com
List of tables: mozstd-trackwhite-digest256
Status: ASSIGNED → RESOLVED
Closed: 4 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: