Closed Bug 891378 Opened 11 years ago Closed 11 years ago

Mixed content blocker is not warning loudly enough

Categories

(Firefox :: Security, defect)

24 Branch
x86
macOS
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 834828

People

(Reporter: peterbe, Unassigned)

References

(Blocks 1 open bug)

Details

Attachments

(1 file)

Two problems with this screenshot from [0]:


1. It is NOT clear why the `http://youtube.com...` video doesn't show. Opening the web console didn't make it clear. Eventually I tried in Chrome whose web console made it clear that http:// content was being blocked. Incidentally, in Chrome the YouTube video loaded just fine.
The little "shield looking" icon to the left of the URL in the address bar is not "loud" enough. Considering that it's my only way to get to the content I think its color should be bolder and maybe pulsate the icon or some other animation.

2. Now, to watch the clip I would have to click the shield icon and select "Disable Protection on this Page" which, to me, is sub-optimal. I would rather say "Ok, I'm fine with loading stuff from http://youtube.com... but keep blocking http://analytics.upworthy.com"

I would file this under a UX component perhaps but that was not a choice. 

[0] https://www.upworthy.com/every-war-on-drugs-myth-thoroughly-destroyed-by-a-retired-police-captain?g=2&c=bl3
Thanks Peter for reporting this!

1) We will file a bug for the Mixed Content on https://www.upworthy.com.  We will see if we can find a contact there we can notify.

2) The FF 23 webconsole does show which content is blocked.  When I visit the link, open the webconsole, I can see the following in the "Security" panel:

Blocked loading mixed active content "http://www.youtube.com/embed/W8yYJ_oV6xk?rel=0&wmode=transparent&showinfo=0&controls=1&enablejsapi=1&rel=0" @ https://www.upworthy.com/every-war-on-drugs-myth-thoroughly-destroyed-by-a-retired-police-captain?g=2&c=bl3
Blocked loading mixed active content "http://fonts.googleapis.com/css?family=Droid+Serif:700,700italic|Source+Sans+Pro:400,700,400italic,700italic" @ https://www.upworthy.com/every-war-on-drugs-myth-thoroughly-destroyed-by-a-retired-police-captain?g=2&c=bl3
Blocked loading mixed active content "http://www.youtube.com/embed/W8yYJ_oV6xk?rel=0&wmode=transparent&showinfo=0&controls=1&enablejsapi=1&rel=0" @ https://d29sy0p5c9gskd.cloudfront.net/assets/application-451c5e6fa0d2a7828032e31dba8f1fbf.js:25
Blocked loading mixed active content "http://analytics.upworthy.com/event" @ https://d29sy0p5c9gskd.cloudfront.net/assets/application-451c5e6fa0d2a7828032e31dba8f1fbf.js:26

3) We have heard complaints about the Shield Doorhanger being more discoverable.  We have a bug open for it https://bugzilla.mozilla.org/show_bug.cgi?id=834828.  I have added your comments to that bug.

4) The youtube video is an HTTP iframe (mixed active content) and hence is blocked by the Mixed COntent Blocker.  IE's Mixed Content Blocker also blocks the video.  Chromes current release version does not block the video, but it's upcoming release (Chrome 29, Chrome Canary) does block the video.  Chrome 29 will hit regular users around the same time as Firefox 23 does (late July / early August).  This is because Chrome is making some changes to their Mixed Content Blocker that make it stricter.
Depends on: 834828
(In reply to Tanvi Vyas [:tanvi] from comment #1)
> 1) We will file a bug for the Mixed Content on https://www.upworthy.com.  We
> will see if we can find a contact there we can notify.

Filed bug https://bugzilla.mozilla.org/show_bug.cgi?id=892770
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: