New issue
Advanced search Search tips

Issue 799771 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Bug
Team-Security-UX



Sign in to add a comment

"Load unsafe scripts" UI is too subtle

Reported by dan...@orodu.net, Jan 7 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36

Steps to reproduce the problem:
1. Go to https://chuo.fm/show/rockers/
2. Scroll down and click one of the dates on the left

What is the expected behavior?
The page or the browser responds visibly to the click

What went wrong?
Nothing happens on the page, and the browser only places a small icon in the omnibox. There is nothing to draw attention to this icon, and I doubt users will find it, nor know what to do with it.

Did this work before? Yes In M62 the page simply worked, now its blocked behind this undiscoverable icon

Chrome version: 63.0.3239.132  Channel: stable
OS Version: 10.0
Flash Version: 

Please make it clear to users that the browser has blocked something on the page and how they can make the page work. Punish developers for bad SSL practices, not users.
 

Comment 1 by dan...@orodu.net, Jan 7 2018

Attaching 2 screenshots of before and after clicking the Jan 6 button in the bottom left.

Note how small the change is between them. You have to know to look in the omnibox to find it. And I had to reload the page multiple times thinking it was broken before it worked.

Edge also has a similar UI, though their omnibox, and the icon, are both larger and thus more visible when they appear. We could do better.
before.png
623 KB View Download
after.png
500 KB View Download
Labels: Needs-Triage-M63 Needs-Bisect
Components: UI>Browser>Omnibox>SecurityIndicators
Labels: -Needs-Bisect -Type-Bug-Regression M-65 OS-Linux OS-Mac Type-Bug
Status: Untriaged (was: Unconfirmed)
Able to reproduce the issue on Mac 10.12.6, Win-10 and Ubuntu 14.04 using chrome reported version #63.0.3239.132 and latest canary #65.0.3314.0.
This is a non-regression issue as it is observed from M50 old builds. 
Attaching screenshot for reference from M-50 version.

Hence, marking it as untriaged to get more inputs from dev team.

Thanks...!!
799771.png
755 KB View Download
Labels: Triaged-ET
Cc: emilyschechter@chromium.org est...@chromium.org
Thanks for the report.

Adding PMily and SWEmily for thoughts.
This UI is deliberately subtle. The indicator could also be titled "Shoot self in face" and I think we're more likely to want to remove it than make it more prominent.

Comment 7 by danakj@chromium.org, Jan 29 2018

I appreciate that but it also breaks existing web content, and in this case had me switching to use edge instead of chromium, which is a much larger "shooting self" as you put it IMO.
Status: WontFix (was: Untriaged)
I don't think we have concrete plans to make this more obvious, and indeed, the site has the (i) icon next to the URL to indicate that the HTTPS setup isn't correct.

You can avoid this problem all together by correctly loading the unsafe scripts over HTTPS like the rest of the page. Then there is no need to load unsafe scripts at all. :)

Comment 9 by dan...@orodu.net, Feb 9 2018

> I don't think we have concrete plans to make this more obvious, and indeed, the site has the (i) icon next to the URL to indicate that the HTTPS setup isn't correct.

That's unfortunate. To most users it will only appear that this page is broken in Chrome.

> You can avoid this problem all together by correctly loading the unsafe scripts over HTTPS like the rest of the page. Then there is no need to load unsafe scripts at all. :)

Can you explain what you mean? How do I go about doing this when using a site such as this?
#9, ah sorry, I thought that the site was your site. The problem is they have some data loaded over HTTPS, but also load JavaScript over HTTP, which compromises the security of using HTTPS.

We are progressively working to mark HTTP as less secure in order to protect users, and part of that work is to try and incentivise sites to not have these fallbacks. Other browser vendors are also pursuing these goals in order to help improve the security of the web.

Comment 11 by dan...@orodu.net, Feb 9 2018

Ok yeah I get that, but this doesn't feel like it's in a good place for users to make choices atm. Like there are websites where I wanna not use http over https and it matters a lot. But here I wanna listen to music and I don't care if it's not secure, you know? So it just feels broken when it doesn't work, and I had no idea how to fix it until I noticed how in edge and came back to see.

Sign in to add a comment