New issue
Advanced search Search tips

Issue 646667 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner: ----
Closed: Dec 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: iOS
Pri: 3
Type: Bug
Team-Security-UX

Blocking:
issue 533581


Show other hotlists

Hotlists containing this issue:
EnamelAndFriendsFixIt


Sign in to add a comment

Security indicators: iOS shows page icon on mixed content sites

Project Member Reported by maxwalker@chromium.org, Sep 14 2016

Issue description

iOS shows the page icon on mixed content sites, instead it should not show any icon in this state.
 
iOS Mixed Content.png
148 KB View Download
Complement: the page (or info) icon should never be shown on iPhone, on iPad the info icon should be shown instead of the page icon.
This is working as intended, since there is no other way to get security details for downgraded HTTPS otherwise. We could poke iOS folks to finally implement Issue 533581, though.

Also note that the icon is no ⓘ on iOS (Canary).
Blocking: 533581
For iPad, we should show the (i) for all HTTP and mixed content sites, there should be no problem. This bug should be fixed.

For iPhone, yes, this is a problem. I will investigate.
How should this relate to  Issue 646545  (Show ⓘ for HTTP on iPhones behind a flag)?

Should there be a single flag for showing the icon for neutral pages, or one for mixed content and one for HTTP?
Labels: Hotlist-SecurityIndicators
Cc: justincohen@chromium.org
Owner: lgar...@chromium.org
Status: Assigned (was: Untriaged)
Mixed content is a separate issue that has not been approved by ui-review and is not explicitly in the HTTP-bad plan right now.

I think there are a few approaches:
(1) We should indeed think about whether mixed content should be a part of HTTP bad. This is not clear to me right now. We *could* do this but it's not Approved or explicit right now.
(2) We should prioritize 533581. I will talk to the iOS PMs separately to see what we should do.
Cc: pinkerton@chromium.org pkl@chromium.org mard...@chromium.org
iOS PM here :). 

Regarding issue 533581, is this something that the security team can tackle with code review support from Bling? We haven't addressed the issue in comment #5 also.

A related question: have we agreed on the design for verbose security state for iOS? The mocks I've seen were for Android. iOS has very little horizontal space so if we put all that, the URL won't have any space (there are back/forward buttons on iOS)
> Regarding issue 533581, is this something that the security team can tackle with code review support from Bling? We haven't addressed the issue in comment #5 also.

I've been tackling more and more of these, but we have limited time on the Enamel side for anything that isn't a small (≈10 lines) fix.
Hello! :)

Re: issue 533581, I could help PM the necessary mocks, but I don't know if we have implementation time if it's not a small fix. Do you have an estimate for how large of a change this would be? Re: c#5 on that bug I agree we should try to preserve that behavior and that would depend on an updated design, I think.

Re: verbose security states -- Clank shares the same concerns (there are some Clank models with another back button) and for these reasons the plan right now is to only implement on tablets (or for iPhone in landscape mode, if that is >=600dp.) Does that sound acceptable to you?
Components: UI>Browser>Omnibox>SecurityIndicators
Sorry for the delay in replying, Emily.
justincohen@ or lgarron@ would know better than me how large of a change this would be. Are there new mocks ?

Re: verbose security states, that sounds acceptable. I don't see how we can squeeze in more verbosity in compact views.

Thanks. 
Components: -Security>UX
Labels: Hotlist-EnamelAndFriendsFixIt
Owner: ----
Status: Available (was: Assigned)
Looks like this had been fixed. iOS Stable shows the info icon for mixed content sites which is working as intended. Please feel free to close the issue.
Status: Fixed (was: Available)

Sign in to add a comment