Closed Bug 1723578 Opened 4 years ago Closed 4 years ago

No Certificate information on Fenix nightly

Categories

(Fenix :: General, defect)

Unspecified
Android
defect

Tracking

(firefox90 unaffected, firefox91 unaffected, firefox92+ fixed)

RESOLVED FIXED
Tracking Status
firefox90 --- unaffected
firefox91 --- unaffected
firefox92 + fixed

People

(Reporter: agi, Unassigned)

References

()

Details

(Keywords: csectype-spoof, regression, sec-high)

Not sure if this qualifies as a security problem but, on the latest Fenix Nightly #2015825547, clicking on the URL lockpad icon doesn't display the certificate information, the screen dims but that's it.

Android 11, Samsung S10e.

yeah, it's a problem -- no way to check provenance of spoof sites and see the whole URL in case they tried to hide things by making the domain longer than the visible part of the URL bar.

Site permissions were on the same panel and are also missing. They generally only showed up if you blocked or granted a permission request, so you can undo your choice. There are hypothetical situations where you might not be able to undo an unsafe choice you made, but I imagine it's more of a usability problem than a security one.

91 beta 4 seems fine: nightly only regression.

Thanks for filing the ticket.
This was a regression from cca7892e912e2f682ce1ccc4b0a06a4f67511bc9 and we backed it out on 525e5e7c25ecd42a8cca53916cfed54ee0dd3707 on the latest nightly 92.0a1 (Build #2015826123) the panes are showing as expected.

Group: mobile-core-security → core-security-release
Status: NEW → RESOLVED
Closed: 4 years ago
Resolution: --- → FIXED
Group: core-security-release
Component: Security: Android → General
OS: Unspecified → Android
You need to log in before you can comment on or make changes to this bug.