New issue
Advanced search Search tips

Issue 667386 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2016
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 1
Type: Bug



Sign in to add a comment

Payment Processing Pages broken

Reported by chrco...@gmail.com, Nov 21 2016

Issue description

Chrome Version       : 54.0.2840.99 (Official Build) m (64-bit)
URLs (if applicable) : tesco.com, justeat.co.uk
Other browsers tested:
     Safari:
    Firefox: OK 49.0.1
         IE:

What steps will reproduce the problem?
(1) Make an order on tesco.com (biggest supermarket in uk used by millions of people)
(2) Goto checkout page
(3) Click pay now on card details
(4) Auto verify payment which I think is processed by arcot.com fails with a "connection reset" message

What is the expected result?

To see the verified by visa page

What happens instead?

connection was reset error

Please provide any additional information below. Attach a screenshot if
possible.

it happens on all visa payment sites justeat.co.uk also affected
This may be related to stricter ssl processing requirements added to latest chrome version

Please note visa is a massive company and their payment processor been blocked is a big issue.
 
Labels: M-54

Comment 2 by chrco...@gmail.com, Nov 21 2016

Also to add, I tested with all extensions not loaded with same result.

Comment 3 by chrco...@gmail.com, Nov 21 2016

To ease testing I found a page that is broken and doesnt require to buy something to test

https://support.citrix.com/article/CTX127030

in chrome = connection reset

in FF 49.0.1 = loads
Components: Internals>Network>SSL
Labels: -Pri-3 Needs-Triage-M54 Pri-1

Comment 5 by chrco...@gmail.com, Nov 21 2016

 if I run chrome in safe mode the message changes into 
ERR_SSL_VERSION_OR_CIPHER_MISMATCH

On FF it uses AES 256 CBC

Please tell me someone hasnt done something as silly as disable AES256 CBC?

Some banking institutions wont allow aes128 to be used.

Comment 6 by mmenke@chromium.org, Nov 21 2016

Labels: Needs-Feedback
Hrm, I can't repro in M54 stable, M55 beta, or M56 dev.  Are you running an MITM proxy of some sort, or some SSL-modifying AV program?

Could you please provide an about:net-internals log (Instructions: https://sites.google.com/a/chromium.org/dev/for-testers/providing-network-details)?

Comment 7 by chrco...@gmail.com, Nov 21 2016

ok will get back to you

Comment 8 by chrco...@gmail.com, Nov 22 2016

ok going to attach file with email to you.

As far as I am aware I have no MITM proxy, I just disabled emsisoft surf protection but I think that only checks hostnames, eset I am aware scans https traffic so for that reason I always have its https scanning disabled.  No proxy is enabled in chrome either.

Comment 9 by chrco...@gmail.com, Nov 22 2016

right I found the cause, I had a look at the experimental flags I had enabled, and the one that enables TLS 1.3 was the cause.

Maximum TLS version enabled. Mac, Windows, Linux, Chrome OS, Android
Set maximum enabled TLS version. #ssl-version-max

I set it back to default now. :)
Status: WontFix (was: Unconfirmed)
Ah, yes, the experimental iteration of TLS 1.3 in M54 was before we successfully pushed through the version negotiation change that makes 1.3 deployable at all. Otherwise lots of buggy sites break and such. :-) In general, not everything in about:flags is ready for broader use yet.

Sign in to add a comment