Closed Bug 1998677 Opened 4 months ago Closed 3 months ago

Inactive split view domain indicator should not include favicon (at least not for non-https sites)

Categories

(Firefox :: Tabbed Browser, defect, P1)

Desktop
All
defect

Tracking

()

VERIFIED FIXED
147 Branch
Tracking Status
firefox147 --- verified

People

(Reporter: Gijs, Assigned: Gijs)

References

(Blocks 1 open bug)

Details

(Keywords: csectype-spoof, sec-vector, Whiteboard: [fidefe-sidebar] [adv-main147-])

Attachments

(1 file)

Some ground assumptions for this ticket:

  1. the design shows the domain with favicon
  2. favicons used to be displayed in the address bar (in all browsers)
  3. all browsers stopped doing this because it enabled spoofing (cf. bug 588270 , bug 742419 )
  4. the split view implementation shows insecure state indicators for websites that are not secure (e.g. http://httpforever.com/)

This combination means that the resulting experience for insecure sites can be confusing, because the site favicon can try to pretend the site is secure anyway, cf. attachment 9524721 [details] .

I think we should not show the favicon - at least in the non-https case. Even in the https case it can be a little spoofy (e.g. with lookalike domains and a "right" favicon), but given we display the domain name it shouldn't be any more spoofy than the address bar already is.

Blocks: 1980370
Severity: -- → S2
Priority: -- → P1
Assignee: nobody → gijskruitbosch+bugs
Status: NEW → ASSIGNED
Status: ASSIGNED → RESOLVED
Closed: 3 months ago
Resolution: --- → FIXED
Target Milestone: --- → 147 Branch

Verified that the favicon is no longer displayed for http sites in split view with Firefox 147.0a1 (2025-12-02) on Windows 11, macOS 26 and Ubuntu 24.

Status: RESOLVED → VERIFIED
QA Whiteboard: [qa-ver-done-c147/b146]
Whiteboard: [fidefe-sidebar] → [fidefe-sidebar] [adv-main147-]
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: