Closed Bug 271103 Opened 20 years ago Closed 20 years ago

inactive tab redirects

Categories

(Firefox :: General, defect)

defect
Not set
critical

Tracking

()

RESOLVED WONTFIX

People

(Reporter: tonglebeak, Assigned: bugzilla)

References

()

Details

User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041114 Firefox/1.0
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041114 Firefox/1.0

Not sure if this is a bug or not, but an inactive tab has the ability to
redirect without the user ever knowing. This could be a problem for cases where
someone will have their bank account login opened in one tab, but surf on
another. If for any reason the tab were to redirect (hijacker, etc) to a site
that looks exactly like the bank site, the user may never know about it and end
up going back to the tab to login with all their sensitive information. I think
that a warning, or a focus onto the redirected tab, should be shown to alert the
user to an inactive tab that is redirecting, since the user might not even know
about it, and can become a possible security problem.

Reproducible: Always
Steps to Reproduce:
1.Open the URL given in a new tab, then go back to another tab and wait 10
seconds, leaving the new tab inactive.
2.
3.

Actual Results:  
Tab redirects without the user knowing (if not paying attention to the tab of
course).

Expected Results:  
It should alert the user of a redirect, either via a warning dialog or a focus
onto the tab, something to let the user know that inactive tab has changed
without them authorizing it.
The tab will redirect, but the activity indicator (in the tab) will show that
something is happening in the tab (automatic reload, redirect). If the page it
loads looks similar to bank site for example, the user could look at the url bar
or the status bar (security lock) to check if it's really the site they think it
is. However, bug 262887 and bug 124750 could be added to this. So this bug isn't
a dupe. Either INVALID or WONTFIX. But after reading "It should alert the user
of a redirect, either via a warning dialog or a focus onto the tab, something to
let the user know that inactive tab has changed without them authorizing it."
this bug would be WONTFIX. The tab does say that there's activity in the tab
(reload, redirect).
Status: UNCONFIRMED → RESOLVED
Closed: 20 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.