Closed Bug 1753590 Opened 4 years ago Closed 1 year ago

https://threadreaderapp.com does not work correctly with ETP set to STRICT

Categories

(Web Compatibility :: Privacy: Site Reports, defect, P3)

Firefox 96

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: frank, Unassigned)

References

(Blocks 1 open bug, )

Details

(Keywords: webcompat:tracker-blocking)

Attachments

(2 files)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:96.0) Gecko/20100101 Firefox/96.0

Steps to reproduce:

Attempting to unravel and twitter thread by using https://threadreaderapp.com leads to a result without showing images. Works in other browsers.

Actual results:

No images shown

Expected results:

Images should be shown.

Hello,
I have tried to reproduce the issue with Win 10x64 with Firefox 96.0 and 98.0a1(2022-02-07), unfortunately I wasn't able to reproduce it and I have given my results as per the attached images.

Could you please answer the following questions in order for us to investigate it further.

Does this issue happen with a new profile? Here is a link on how to create one: https://support.mozilla.org/en-US/kb/profile-manager-create-remove-switch-firefox-profiles
Does this issue happen in the latest nightly? Here is a link from where you can download it: https://www.mozilla.org/en-US/firefox/channel/desktop/
Do you have any addons installed if so can you list them?

On a new profile, this issue does not happen.

If returning to the regular default profile, and if I disable all add-ons on , the issue remains.

The Bugbug bot thinks this bug should belong to the 'Core::DOM: Security' component, and is moving the bug to that component. Please revert this change in case you think the bot is wrong.

Component: Untriaged → DOM: Security
Product: Firefox → Core

The twitter images are being blocked by tracking protection. I don't know if we can make a back-end exception for threadreader app or if you need to make one for yourself, but it's definitely the same domain that twitter does use for social tracking.

It's possible the tracking protection team will be able to distinguish between user images and "twitter" images base on URL path?

Component: DOM: Security → Privacy: Anti-Tracking
Flags: needinfo?(pbz)

I can reproduce the issue with "strict" ETP enabled. On "standard" the tweets load properly.
To confirm, do you have strict tracking protection enabled and does it fix the issue if you switch to standard? Here is an article on how to update this setting.

(In reply to Daniel Veditz [:dveditz] from comment #6)

The twitter images are being blocked by tracking protection. I don't know if we can make a back-end exception for threadreader app or if you need to make one for yourself, but it's definitely the same domain that twitter does use for social tracking.

It's possible the tracking protection team will be able to distinguish between user images and "twitter" images base on URL path?

That's an interesting idea. Unfortunately our tracking protection block lists are domain based so we can't distinguish between paths. Disconnect classifies all of twimg.com as a tracker. Also see https://github.com/disconnectme/disconnect-tracking-protection/issues/60

Status: UNCONFIRMED → NEW
Ever confirmed: true
Flags: needinfo?(pbz) → needinfo?(frank)
Summary: https://threadreaderapp.com does not work correctly → https://threadreaderapp.com does not work correctly with ETP set to STRICT
Severity: -- → S3
Priority: -- → P3
No longer blocks: tp-breakage
Flags: needinfo?(frank)
Component: Privacy: Anti-Tracking → Privacy: Site Reports
Product: Core → Web Compatibility

Fixed by SmartBlock Embeds (Bug 1901602)

Status: NEW → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: