New issue
Advanced search Search tips

Issue 816184 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Closed: Dec 3
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Mac
Pri: 2
Type: Bug



Sign in to add a comment

DevTools Security tab shows HTTP pages as broken HTTPS when the HTTP-bad flag is enabled

Reported by 93m4qau...@gmail.com, Feb 25 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3354.0 Safari/537.36

Steps to reproduce the problem:
1. Open chrome://flags/#enable-mark-http-as and enable the flag.
2. Relaunch Chrome as prompted.
3. Open an insecure HTTP site (not an invalid HTTPS site) such as http://www.chromium.org.
4. Press Ctrl+Shift+I to open Developer Tools.
5. Click on the Security tab.

What is the expected behavior?
Developer Tools reports the page security state as "This page is not secure (unencrypted HTTP)", and in red since the HTTP-bad flag is enabled.

What went wrong?
Developer Tools reports the page security state as "This page is not secure (broken HTTPS)". This is not true, as the page is actually plain HTTP, not broken HTTPS. This is only an issue when the HTTP-bad flag is enabled.

Did this work before? N/A 

Chrome version: 66.0.3354.0  Channel: canary
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version:
 
DevTools Security tab.PNG
141 KB View Download
Labels: Needs-Triage-M66
Cc: vamshi.kommuri@chromium.org
Labels: Triaged-ET Needs-Feedback
Thanks for filing the issue!

Unable top reproduce the issue on reported chrome version 66.0.3354.0 using windows 10 with the below mentioned steps.
1. Launched Chrome 
2. Enabled the flag mentioned in comment#0 and relaunched chrome
3. Navigated to http://www.chromium.org
4. Opened DevTools -> Security
We didn't observe any text like "This page is not secure (broken HTTPS)". Attaching the screen shot of the same.

@Reporter: Could you please have a look at the screen shot and let us know if anything missed from our end. Any further inputs from your end may help us.
816184.png
44.1 KB View Download
Can you provide a full screenshot with the browser chrome as well, so that I can confirm that the flag is actually enabled?
Project Member

Comment 4 by sheriffbot@chromium.org, Mar 1 2018

Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: Needs-Feedback
93m4qau783 Thanks for the feedback.

As per comment #3, attached is the screen shot with the chrome//version showing the flag #enable-mark-http-as Enabled.

Request you to please check and confirm if anything is missed from our end, which will help in further triaging.

Thanks..
816184.png
149 KB View Download
You may need to set the flag to "Always mark HTTP as actively dangerous", so you get a red "Not secure" next to the URL.
Project Member

Comment 7 by sheriffbot@chromium.org, Mar 2 2018

Cc: susan.boorgula@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding the requester to the cc list.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: M-67 Target-67 FoundIn-67 OS-Linux OS-Mac
Status: Untriaged (was: Unconfirmed)
Able to reproduce this issue on Mac 10.13.3, Win-10 and Ubuntu 14.04 using chrome reported version #66.0.3354.0 and latest canary #67.0.3362.0.
This is a non-regression issue as it is observed from M65 old builds i.e the flag got introduced in M-65 only. 

Hence, marking it as untriaged to get more inputs from dev team.

Thanks...!!
Owner: einbinder@chromium.org
Status: Assigned (was: Untriaged)
Owner: est...@chromium.org
Sorry, wrong triage. Emily, mind taking a look?
 Issue 882202  has been merged into this issue.
Cc: est...@chromium.org
Owner: cthomp@chromium.org
see  issue 882202  for further repro steps. Assigning to cthomp as estark is away.
Status: Started (was: Assigned)
Project Member

Comment 14 by bugdroid1@chromium.org, Oct 29

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/addf5286b849bdcc235e63e170c948f60cf8892c

commit addf5286b849bdcc235e63e170c948f60cf8892c
Author: Christopher Thompson <cthomp@chromium.org>
Date: Mon Oct 29 22:28:01 2018

Add security summary override for HTTP-Really-Bad

This adds a new summary and sets the explanation for non-secure form
edits on HTTP pages in the DevTools security panel. This fixes a bug
where HTTP pages downgraded to the DANGEROUS security level (under the
HTTP-Really-Bad changes) would get treated as broken HTTPS instead.

Bug:  816184 
Change-Id: I9440a20f970ff4daffd9c3a11a6a5a86a0b39160
Reviewed-on: https://chromium-review.googlesource.com/c/1277650
Reviewed-by: Adrienne Porter Felt <felt@chromium.org>
Commit-Queue: Christopher Thompson <cthomp@chromium.org>
Cr-Commit-Position: refs/heads/master@{#603657}
[modify] https://crrev.com/addf5286b849bdcc235e63e170c948f60cf8892c/components/security_state/content/content_utils.cc
[modify] https://crrev.com/addf5286b849bdcc235e63e170c948f60cf8892c/components/security_state/content/content_utils_unittest.cc
[modify] https://crrev.com/addf5286b849bdcc235e63e170c948f60cf8892c/components/security_state_strings.grdp

Status: Fixed (was: Started)
Marking this as fixed as I don't think there is anything remaining to do.

Sign in to add a comment