https://torrentfreak.com/ and its subpages have ad/affiliate/share-button scripts blocked by mixed content blocking

RESOLVED FIXED

Status

Tech Evangelism Graveyard
English US
--
minor
RESOLVED FIXED
5 years ago
3 years ago

People

(Reporter: Aleksej, Assigned: Aleksej)

Tracking

(Blocks: 1 bug)

Details

(Whiteboard: [mcb-chrome][mcb-ie][mcb-thirdparty-notified], URL)

(Assignee)

Description

5 years ago
Mixed content blocking is a feature that prevents insecure elements on secure pages from loading. In Firefox 23, this feature will default to blocking "active" insecure content, which may break some web sites. 

More information on Firefox's Mixed Content Blocker is below: 
http://blog.mozilla.org/tanvi/2013/04/10/mixed-content-blocking-enabled-in-firefox-23/

Although content itself (including images used via http://) works at the HTTPS version of TorrentFreak, some scripts for advertisement or posting elsewhere are blocked.

Here is a list of the active, HTTP resources that were blocked: 

At https://torrentfreak.com/:
"http://partner.googleadservices.com/gampad/google_service.js" @ https://torrentfreak.com/

At the article page https://torrentfreak.com/how-the-copyright-industry-pushed-for-internet-surveillance-130630/:
[23:xx] Blocked loading mixed active content "http://platform.twitter.com/widgets.js" @ https://torrentfreak.com/how-the-copyright-industry-pushed-for-internet-surveillance-130630/
[23:xx] Blocked loading mixed active content "http://partner.googleadservices.com/gampad/google_service.js" @ https://torrentfreak.com/how-the-copyright-industry-pushed-for-internet-surveillance-130630/
[23:xx] Blocked loading mixed active content "http://www.facebook.com/plugins/like.php?href=https%3A%2F%2Ftorrentfreak.com%2Fhow-the-copyright-industry-pushed-for-internet-surveillance-130630%2F&send=false&layout=button_count&width=105&show_faces=false&action=like&colorscheme=light&font&height=21" @ https://torrentfreak.com/how-the-copyright-industry-pushed-for-internet-surveillance-130630/
[23:xx] Content Security Policy: Directive inline style base restriction violated @ https://disqus.com/embed/comments/?f=torrentfreak&t_i=72976%20http%3A%2F%2Ftorrentfreak.com%2F%3Fp%3D72976&t_u=https%3A%2F%2Ftorrentfreak.com%2Fhow-the-copyright-industry-pushed-for-internet-surveillance-130630%2F&t_t=How%20The%20Copyright%20Industry%20Pushed%20For%20Internet%20Surveillance&t_e=How%20The%20Copyright%20Industry%20Pushed%20For%20Internet%20Surveillance&t_d=How%20The%20Copyright%20Industry%20Pushed%20For%20Internet%20Surveillance%20%7C%20TorrentFreak&s_o=default&disqus_version=1372380899#3:16
[23:xx] Content Security Policy: Directive inline style base restriction violated @ https://disqus.com/embed/comments/?f=torrentfreak&t_i=72976%20http%3A%2F%2Ftorrentfreak.com%2F%3Fp%3D72976&t_u=https%3A%2F%2Ftorrentfreak.com%2Fhow-the-copyright-industry-pushed-for-internet-surveillance-130630%2F&t_t=How%20The%20Copyright%20Industry%20Pushed%20For%20Internet%20Surveillance&t_e=How%20The%20Copyright%20Industry%20Pushed%20For%20Internet%20Surveillance&t_d=How%20The%20Copyright%20Industry%20Pushed%20For%20Internet%20Surveillance%20%7C%20TorrentFreak&s_o=default&disqus_version=1372380899#3
[23:xx] Content Security Policy: Directive inline style base restriction violated @ https://disqus.com/embed/comments/?f=torrentfreak&t_i=72976%20http%3A%2F%2Ftorrentfreak.com%2F%3Fp%3D72976&t_u=https%3A%2F%2Ftorrentfreak.com%2Fhow-the-copyright-industry-pushed-for-internet-surveillance-130630%2F&t_t=How%20The%20Copyright%20Industry%20Pushed%20For%20Internet%20Surveillance&t_e=How%20The%20Copyright%20Industry%20Pushed%20For%20Internet%20Surveillance&t_d=How%20The%20Copyright%20Industry%20Pushed%20For%20Internet%20Surveillance%20%7C%20TorrentFreak&s_o=default&disqus_version=1372380899#3:1
Also causes errors in Chrome 26 and IE10.
Whiteboard: [mcb-chrome][mcb-ie]
(Assignee)

Comment 2

5 years ago
FWIW (not blocked by default), some passive content (images) is also fetched through HTTP.
(Assignee)

Comment 3

5 years ago
E-mailed.
Assignee: english-us → deletesoftware+moz
Status: NEW → ASSIGNED
(Assignee)

Updated

5 years ago
Whiteboard: [mcb-chrome][mcb-ie] → [mcb-chrome][mcb-ie][mcb-thirdparty-notified]
(Assignee)

Comment 4

5 years ago
As of now,

* Main page https://torrentfreak.com/ shows no ac blocking.

* Article page https://torrentfreak.com/movie-studios-get-uk-isps-to-block-torrent-site-proxies-130905/ has these URLs blocked:

[17:20:45.047] Blocked loading mixed active content "http://platform.twitter.com/widgets.js" @ https://torrentfreak.com/movie-studios-get-uk-isps-to-block-torrent-site-proxies-130905/
[17:20:46.224] Blocked loading mixed active content "http://www.facebook.com/plugins/like.php?href=https%3A%2F%2Ftorrentfreak.com%2Fmovie-studios-get-uk-isps-to-block-torrent-site-proxies-130905%2F&send=false&layout=button_count&width=105&show_faces=false&action=like&colorscheme=light&font&height=21" @ https://torrentfreak.com/movie-studios-get-uk-isps-to-block-torrent-site-proxies-130905/
[17:20:50.352] Content Security Policy: Directive inline script base restriction violated @ https://disqus.com/embed/comments/?f=torrentfreak&t_i=76560%20http%3A%2F%2Ftorrentfreak.com%2F%3Fp%3D76560&t_u=https%3A%2F%2Ftorrentfreak.com%2Fmovie-studios-get-uk-isps-to-block-torrent-site-proxies-130905%2F&t_e=Movie%20Studios%20Get%20UK%20ISPs%20to%20Block%20Torrent%20Site%20Proxies&t_d=Movie%20Studios%20Get%20UK%20ISPs%20to%20Block%20Torrent%20Site%20Proxies%20%7C%20TorrentFreak&t_t=Movie%20Studios%20Get%20UK%20ISPs%20to%20Block%20Torrent%20Site%20Proxies&s_o=default&l=&disqus_version=1378324593#1
[17:20:51.089] Blocked loading mixed active content "http://mediacdn.disqus.com/1378324593/fonts/next/embed-icons.woff" @ https://securecdn.disqus.com/1378324593/build/next/common.js:3
[17:20:51.090] Blocked loading mixed active content "http://mediacdn.disqus.com/1378324593/fonts/next/embed-icons.ttf" @ https://securecdn.disqus.com/1378324593/build/next/common.js:3


Are the disqus ones a problem with disqus itself?
(Assignee)

Comment 5

4 years ago
Seems to work now.  Feel free to reopen if it does not and you think that's important.
Status: ASSIGNED → RESOLVED
Last Resolved: 4 years ago
Resolution: --- → FIXED
(Assignee)

Comment 6

4 years ago
I forgot to enable mixed display content blocking.

Now that I did, I see that article illustrations are on http, and do not show then.  But I've seen no notification from Firefox.
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
(Assignee)

Comment 7

4 years ago
The bug was about mixed active content.  Web Console mentions the mpc, but no mac.
Status: REOPENED → RESOLVED
Last Resolved: 4 years ago4 years ago
Resolution: --- → FIXED
Product: Tech Evangelism → Tech Evangelism Graveyard
You need to log in before you can comment on or make changes to this bug.