Closed Bug 650647 Opened 14 years ago Closed 14 years ago

A Firefox setting should exist to disable "mixed content" so that secure SSL connections can be established

Categories

(Firefox :: Security, defect)

x86
Linux
defect
Not set
major

Tracking

()

RESOLVED DUPLICATE of bug 321022

People

(Reporter: nrundy, Unassigned)

References

()

Details

User-Agent: Mozilla/5.0 (X11; Linux i686; rv:2.0) Gecko/20100101 Firefox/4.0 Build Identifier: Mozilla/5.0 (X11; Linux i686; rv:2.0) Gecko/20100101 Firefox/4.0 The following message pops up a lot when I am navigating to webpages that I want to view securely: "You have requested an encrypted page that contains some unencrypted information. Information that you see or enter on this page could easily be read by a third party." This notice is all well and good. But WHY can't firefox block unencrypted content (i.e., disable mixed content) and display only the encrypted parts? I read in a forum post: http://forums.mozillazine.org/viewtopic.php?f=38&t=741735&start=0&st=0&sk=t&sd=a that Internet Explorer and Google Chrome allow users to disable mixed content (i.e., unencrypted content). That is, they can specify the browser only show the encrypted content and therefore establish a secure SSL connection. When I navigate to a page in Firefox where the message I quoted above pops up, I can return to that page in Google Chrome and view the same content in a fully encrypted session because it has (by default) prevented the unencrypted content from being displayed. Firefox has no setting that prevents the display of mixed content (i.e., unencrypted content). And by default it allows unencrypted content to show (as evidenced by the persistent popup notice). The result is that users of Firefox cannot view many webpages in a fully encrypted session, but they can using another web browser. Reproducible: Always Steps to Reproduce: 1. when I navigate to the webpage: https://duckduckgo.com/ and search for "omg ubuntu" the Firefox warning pops up that unencrypted parts of the webpage exist and the blue highlight is removed from the Firefox URL bar 2. there appears to be no way to view the webpage in a fully encrypted session from within Firefox 3. when I follow the same procedure using Chromium, it shows full HTTPS encryption and a secure session (i.e., it is not displaying mixed content) Actual Results: Firefox pops up a warning that unencrypted information exists on the webpage but provides no way to block/remove the unencrypted content. The user has no way to disable mixed content and view only the encrypted content and hence a fully encrypted page. Expected Results: Firefox should provide a setting that allows users to disable mixed content. Then users will be able to view fully encrypted webpages. As long as mixed content is allowed to be displayed, fully encrypted sessions cannot be established. The end result with the current setup is that Firefox users are unable to view many webpages in a fully encrypted session, but they can using another web browser. The topic is discussed in this forum post: http://forums.mozillazine.org/viewtopic.php?f=38&t=741735&start=0&st=0&sk=t&sd=a
Status: UNCONFIRMED → RESOLVED
Closed: 14 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.