Payment Processing Pages broken
Reported by
chrco...@gmail.com,
Nov 21 2016
|
||||
Issue descriptionChrome Version : 54.0.2840.99 (Official Build) m (64-bit) URLs (if applicable) : tesco.com, justeat.co.uk Other browsers tested: Safari: Firefox: OK 49.0.1 IE: What steps will reproduce the problem? (1) Make an order on tesco.com (biggest supermarket in uk used by millions of people) (2) Goto checkout page (3) Click pay now on card details (4) Auto verify payment which I think is processed by arcot.com fails with a "connection reset" message What is the expected result? To see the verified by visa page What happens instead? connection was reset error Please provide any additional information below. Attach a screenshot if possible. it happens on all visa payment sites justeat.co.uk also affected This may be related to stricter ssl processing requirements added to latest chrome version Please note visa is a massive company and their payment processor been blocked is a big issue.
,
Nov 21 2016
Also to add, I tested with all extensions not loaded with same result.
,
Nov 21 2016
To ease testing I found a page that is broken and doesnt require to buy something to test https://support.citrix.com/article/CTX127030 in chrome = connection reset in FF 49.0.1 = loads
,
Nov 21 2016
,
Nov 21 2016
if I run chrome in safe mode the message changes into ERR_SSL_VERSION_OR_CIPHER_MISMATCH On FF it uses AES 256 CBC Please tell me someone hasnt done something as silly as disable AES256 CBC? Some banking institutions wont allow aes128 to be used.
,
Nov 21 2016
Hrm, I can't repro in M54 stable, M55 beta, or M56 dev. Are you running an MITM proxy of some sort, or some SSL-modifying AV program? Could you please provide an about:net-internals log (Instructions: https://sites.google.com/a/chromium.org/dev/for-testers/providing-network-details)?
,
Nov 21 2016
ok will get back to you
,
Nov 22 2016
ok going to attach file with email to you. As far as I am aware I have no MITM proxy, I just disabled emsisoft surf protection but I think that only checks hostnames, eset I am aware scans https traffic so for that reason I always have its https scanning disabled. No proxy is enabled in chrome either.
,
Nov 22 2016
right I found the cause, I had a look at the experimental flags I had enabled, and the one that enables TLS 1.3 was the cause. Maximum TLS version enabled. Mac, Windows, Linux, Chrome OS, Android Set maximum enabled TLS version. #ssl-version-max I set it back to default now. :)
,
Nov 22 2016
Ah, yes, the experimental iteration of TLS 1.3 in M54 was before we successfully pushed through the version negotiation change that makes 1.3 deployable at all. Otherwise lots of buggy sites break and such. :-) In general, not everything in about:flags is ready for broader use yet. |
||||
►
Sign in to add a comment |
||||
Comment 1 by manoranj...@chromium.org
, Nov 21 2016