Closed Bug 1786462 Opened 4 years ago Closed 2 years ago

FF blocks images from twitter as "social media trackers"

Categories

(Core :: Privacy: Anti-Tracking, defect, P3)

Firefox 104
defect

Tracking

()

RESOLVED WONTFIX

People

(Reporter: bugzilla, Unassigned)

Details

Attachments

(1 file)

Attached image Untitled.png —

Steps to reproduce:

Open https://sites.google.com/view/ffbug/home with "social media trackers" enabled

Actual results:

Embedded image from Twitter is not shown

Expected results:

Embedded image from Twitter should have been shown

The embedded image is https://pbs.twimg.com/media/FazxOqnXEAEn2nM.jpg

I will attempt to embed it here. If tracking protection of "social media trackers" is enabled on this site, it will not be displayed

--- img begin ---

--- img end ---

(In reply to Alex from comment #1)
Never mind, it does not display regardless. Is the markdown broken?

Twitter serves images and videos from pbs.twimg.com
Categorizing it as tracker breaks all sites that embed media from twitter.

The Bugbug bot thinks this bug should belong to the 'Core::Audio/Video: Playback' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.

Component: Untriaged → Audio/Video: Playback
Product: Firefox → Core
Component: Audio/Video: Playback → Privacy: Anti-Tracking

This is what i get in the console :

ontent Security Policy: Ignoring “'unsafe-inline'” within script-src: nonce-source or hash-source specified 2
Cookie “SEARCH_SAMESITE” with the “SameSite” attribute value “Lax” or “Strict” was omitted because of a cross-site redirect. home
Some cookies are misusing the “SameSite“ attribute, so it won’t work as expected 10
Cookie “” has been rejected as third-party. css
Cookie “” has been rejected as third-party. css
Cookie “” has been rejected as third-party. rs=AGEqA5nX4LP1LEvGXjwV7WbHlRiIsjHagw
This page uses the non standard property “zoom”. Consider using calc() in the relevant property values, or using “transform” along with “transform-origin: 0 0”. home
Content Security Policy: Ignoring “'unsafe-inline'” within script-src: nonce-source or hash-source specified
Cookie “” has been rejected as third-party. m=view
Cookie “” has been rejected as third-party. simple-header-blended-small.png
Content Security Policy: Ignoring “'unsafe-inline'” within script-src: nonce-source or hash-source specified 3
Cookie “” has been rejected as third-party. intermediate-frame-minified.html
Request to access cookie or storage on “<URL>” was blocked because we are blocking all third-party storage access requests and content blocking is enabled. 3
Cookie “” has been rejected as third-party. intermediate-frame-minified.html
Cookie “” has been rejected as third-party. m=sy19,sy1a,sy18,FoQBg
Cookie “” has been rejected as third-party. m=sy2l,TRvtze
Cookie “” has been rejected as third-party. m=MpJwZc,n73qwf,A4UTCb,qAKInc,sy13,TGYpv,syy,X85Uvc,syw,YXyON,sy2n,abQiW,W26a5e,sy10,sy15,sy11,sy12,sy14,fuVYe,hJUyqe,KUM7Z,XDKZTc,syz,qkPXAf,qEW1W,oNFsLb,sy3k,yxTchf,sy3l,sy3m,xQtZb,yf2Bs,sy3,sy9,yyxWAc,qddgKe,sy2p,SM1lmd,sy7,sy6,syv,RRzQxe,zZvHmd,syx,YV8yqd,sy8,syb,syl,sya,fNFZH,sy2o,sy1e,sy1p,sym,RrXLpc,cgRV2c,sy1q,o1L5Wb,X4BaPc,syg,Md9ENb,sy1g,sy1h,sy1i,syo,sy1c,sy1d,sy1f,sy1o,syp,syu,KlrXId,NlqxW,sy1l,sy1m,sy1n,sy1k,sy4,syc,sy1j,sy1s,sy1v,sy1x,sy22,sy1t,sy21,sy29,sy1r,sy17,sy1u,sy1z,sy1w,sy20,sy23,sy26,sy28,sy2b,sy2c,sy2d,sy1b,T807ad,sy1y,ZDEHrf,sy24,sy25,sy27,sy2a,oy3iwb,dBhIIb,syq,Yr1Pcb,LUQjOd,J9ssyb,SB123c,UubMM,YoEZUb,JKfHhb,DJtOxf,pA2mAb,gypOCd,X4FC5,kYfebb,XMtvld,rrOIJc,ZdZQ6b,Euz7Lc,sAbmxd,heobjb,R4KMEc,sy2e,sy2f,sy2g,sy2h,UYjpC,vVEdxc,VYKRW,sy16,CG0Qwb,RZ9OZ,N0NZx
Cookie “” has been rejected as third-party. m=sy3b,IZT63,vfuNJf,sy34,sy38,sy3c,sy3n,sy3o,siKnQd,sy32,sy3a,sy3e,YNjGDd,sy3d,sy3f,PrPYRd,iFQyKf,hc6Ubd,sy3p,SpsfSb,sy35,sy37,wR5FRb,pXdRYb,dIoSBb,zbML3c
Cookie “” has been rejected as third-party. api.js
Cookie “” has been rejected as third-party. m=m9oV,sy3g,NTMZac,RAnnUd,sy2q,uu7UOe,nAFL3,sy2k,gJzDyc,sy2r,sy3q,soHxf,syr,syt,HYv29e,sy2s,uY3Nvd
Cookie “” has been rejected as third-party. cb=gapi.loaded_0
Content Security Policy: Ignoring “'unsafe-inline'” within script-src: nonce-source or hash-source specified 3
Cookie “” has been rejected as third-party. intermediate-frame-minified.html
Cookie “” has been rejected as third-party. FazxOqnXEAEn2nM.jpg
The resource at “https://pbs.twimg.com/media/FazxOqnXEAEn2nM.jpg” was blocked because content blocking is enabled.
intermediate-frame-minified.html
Cookie “” has been rejected as third-party. intermediate-frame-minified.html
Cookie “” has been rejected as third-party. api.js
Request to access cookie or storage on “<URL>” was blocked because we are blocking all third-party storage access requests and content blocking is enabled. 3
Cookie “” has been rejected as third-party. cb=gapi.loaded_0
Cookie “” has been rejected as third-party. FazxOqnXEAEn2nM.jpg
The resource at “https://pbs.twimg.com/media/FazxOqnXEAEn2nM.jpg” was blocked because content blocking is enabled.
intermediate-frame-minified.html
Cookie “” has been rejected as third-party. favicon.ico

​

This is expected when ETP is set to "strict" mode. See Bug 1628176.

Thanks for reporting.

Do you enable the ETP strict mode? If you do, then this is expected behavior.

Severity: -- → S3
Flags: needinfo?(bugzilla)
Priority: -- → P3

No, it is set to custom, but just ticking "trackers" causes the behaviour.
See https://i.imgur.com/DjIN05D.jpg

(for some reason didn't get an email notification)

Flags: needinfo?(bugzilla)

From the image you provided, I can see that you have enabled blocking tracking content in all windows. This includes the social trackers, so any third-party context from twitter will be blocked including images.

Status: UNCONFIRMED → RESOLVED
Closed: 2 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: