Skip to content
This repository has been archived by the owner on May 10, 2024. It is now read-only.

Red icon for HTTPS upgrades #2554

Open
jumde opened this issue May 14, 2020 · 2 comments
Open

Red icon for HTTPS upgrades #2554

jumde opened this issue May 14, 2020 · 2 comments
Labels
bug Epic: Security priority/P3 The next thing for us to work on. priority/P4 Planned work. We expect to get to it "soon". QA/Yes release-notes/include security

Comments

@jumde
Copy link
Contributor

jumde commented May 14, 2020

Description:

HTTPS-Everywhere and HSTS upgrades show red-icon in the address bar

Steps to Reproduce

  1. Navigate to https-everywhere.badssl.com - Refresh - red icon
  2. Navigate to hsts.badssl.com - Refresh - red icon

Actual result:
Red icon in URL bar

Expected result:
Secure icon (Grey)

Reproduces how often: [Easily reproduced, Intermittent Issue]
Easily

Brave Version:
1.16.2

Device details:
iPhone 11

@jumde jumde added the security label May 14, 2020
@iccub
Copy link
Contributor

iccub commented May 14, 2020

Possibly related #1971

@Brandon-T
Copy link
Collaborator

Sometimes even after an upgrade, the website is still not secure as it loads insecure scripts still, so webView.hasOnlySecureContent is false. So even though it is https website and upgrade was successful, it doesn’t mean the web-page itself is fully secure.

Further discussion: https://bravesoftware.slack.com/archives/C06UXF3KJ/p1613027526101900

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug Epic: Security priority/P3 The next thing for us to work on. priority/P4 Planned work. We expect to get to it "soon". QA/Yes release-notes/include security
Projects
None yet
Development

No branches or pull requests

5 participants