New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 700464 link

Starred by 2 users

Issue metadata

Status: Available
Owner:
(slow to respond to bugs. if it's i...
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Bug
Team-Security-UX



Sign in to add a comment

Re-enable Warnings doesn't work reliably in Incognito

Project Member Reported by elawrence@chromium.org, Mar 10 2017

Issue description

Chrome Version: 59.0.3037

What steps will reproduce the problem?
1. Visit https://wrong.host.badssl.com/ in a normal browser instance. 
2. Click through interstitial.  
3. Open a new incognito instance to https://wrong.host.badssl.com/.

Observe no warning interstitial. 

4. Click the lock to show Page Info. Click "Re-enable warnings".
5. Refresh the page.

Bug: No Interstitial.

Presumably because we're using a throwaway incognito profile and the base user profile still has the warning disabled?

(Do we even want to propagate certificate warning exceptions from the regular user profile into the Incognito profile?)
 

Comment 1 by est...@chromium.org, Mar 10 2017

Cc: mea...@chromium.org
Components: UI>Browser>Interstitials
Labels: OS-All
meacer, do you remember why we inherit certificate bypasses to incognito? I seem to remember that that was an intentional decision, but I can't remember what the reasoning was.
 Issue 718594  has been merged into this issue.

Comment 4 by est...@chromium.org, Nov 10 2017

Labels: Hotlist-EnamelAndFriendsFixIt

Comment 5 by est...@chromium.org, Feb 18 2018

Labels: -Hotlist-EnamelAndFriendsFixIt
Cc: rhalavati@chromium.org
Components: Privacy>Incognito
meacer@,

Has there been any activity on this?

We reset the permissions that sites have in incognito mode to safer states. I think this should be done for security warnings as well. Therefore I think this should be considered as bug and not intended.
Cc: f...@chromium.org
No activity apart from comment #2, as far as I know.

felt: Do you happen to remember whether we eventually decided to carry over cert exceptions to incognito? (see comment #2)
Gentle ping to bring this up.
Cc: -f...@chromium.org
Owner: f...@chromium.org
felt for comment #9

Sign in to add a comment