New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 612035 link

Starred by 4 users

Issue metadata

Status: Archived
Owner: ----
Closed: May 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Helpful security/cipher info was removed from UI in Chromium 50+ versions

Reported by totallyf...@gmail.com, May 15 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.110 Safari/537.36

Steps to reproduce the problem:
1. Open any HTTPS secured website.
2. Click the padlock icon in the address bar.
3. Click the Connection tab.
4. Security/cipher info in newer Chromium versions (after 49) is NOT available unless the user clicks Details and then reloads the page.

What is the expected behavior?
I expect the info to be available for future Chromium versions and NOT removed.

What went wrong?
I expect that the encryption info present within the attached screenshot should NOT be removed from future versions of Chrome/Chromium.

Forcing a user to click 'Details' and reload the page makes them less likely to check the security of a website (banking) and opens them up to far more issues with zero-day phishing and other types of  malformed content.

I never understood why this was removed.  WHY!?
The user would have to click the padlock and then click the 'Connection' tab just to see the info in the first place.  It is already hidden well-enough for 

Did this work before? Yes Chromium v49

Chrome version: 49.0.2623.110  Channel: n/a
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: Shockwave Flash 21.0 r0

I don't get why these kinds of things keep happening.  Chromium used to be pretty good on info & security and just drops the ball hard far too often.

 
Illustration here: https://anony.ws/i/2016/05/20/ChromiumSecurityInfo.png
Also attached.
ChromiumSecurityInfo.png
89.9 KB View Download
I'll be updating this issue with a picture of how things look on Chromium v50+ versions.
I just reported https://bugs.chromium.org/p/chromium/issues/detail?id=613855 that is essentially the same.

This is a 50+ version information about a valid certificate without a matching cipher. I named the image no-info-page, because the security "debug" page contains no information about what happened!

no-info-page.png
54.2 KB View Download
Cc: lgar...@chromium.org
 Issue 613855  has been merged into this issue.
Here's an update with a picture of the issue I am having on Chromium versions 50 and higher not showing the security info like previous versions.

https://anony.ws/i/2016/05/24/ChromiumSecurityFail.png
ChromiumSecurityFail.png
85.9 KB View Download
The entire 'Connections' tab was removed and there's no good reason why that was done.  Having to click 'Details' and then reload the page are extra unnecessary steps.  Please revert this change to the original pre-v50 functionality that was present as of at least v49.

Comment 9 by hora...@gmail.com, May 24 2016

I agree with the notion..

The old, pre v50, security pane was very useful.

Comment 10 Deleted

I want to mention, that CIPHER Information is useful, not only for established SSL Connections, but for failed connections too!

  1. The user should be able to access the complete diagnostics of a failed SSL Handshake

  2. The user should be able to see a static list of built-in CIPHER Suites like the one that comes with openssl for example. See (on the command line)

    `openssl ciphers`

and/or

    `openssl ciphers -v`

for an example how such a list can be formatted.


Project Member

Comment 12 by sheriffbot@chromium.org, May 25 2017

Status: Archived (was: Unconfirmed)
Issue has not been modified or commented on in the last 365 days, please re-open or file a new bug if this is still an issue.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment