14 ms·
Camera and microphone require HTTPS in Firefox 68
- petters 7y agoIt will still work on localhost, which is nice. It would be nice if it also worked on local IPs, like 192.168... Those do not work on Chrome, I think, which make mobile testing a bit more cumbersome.
- nhumrich 7y agoYou could add a tunnel via iptables to just route one port on localhost to another ip
- klodolph 7y agoiptables on your phone? I think you would need to root your phone, if it's Android.
- lucb1e 7y agoI think it's not unreasonable for a techie to be the admin of their own phone. (I still don't get how this is an unpopular opinion.)
- deleted 7y ago[deleted]
- klodolph 7y agoI also think it’s not unreasonable to not want to have root access to your phone.
- untog 7y ago> (I still don't get how this is an unpopular opinion.) Not unpopular, just unrealistic. You can't do it on an iPhone, and if you're doing local web development you really ought to be checking it on an iPhone.
- rswail 7y agoIf you're doing local web development, then running the iOS simulator will give you the necessary Safari iOS Web view controls.
- untog 7y agoIt won't get you the necessary touch interactions if you're doing something that uses them, though. Broadly speaking, you want to test on the actual device your users are using, not an approximation of one.
- chipperyman573 7y agoIf you have a OnePlus (which come more or less rooted) or a Samsung (Which has a lot of community support), you can probably root it pretty easily. But a lot of other phones lack the manufacturer's blessing or the community's support, leaving you SOL unless you can find an exploit yourself. Also... iphone?
- kalleboo 7y agoAs I get older and get other responsibilities, I want to be admin of fewer and fewer things. Same reason I replaced my Linux fileserver with a Synology. I'll let someone else stay on top of the security issue du jour.
- Groxx 7y agoProbably possible with a local VPN on android? I believe those can do anything they please.
- numtel 7y agoNo need to root, with android in developer mode, run this to forward localhost:3000 to the same port on the phone. > adb reverse tcp:3000 tcp:3000
- varenc 7y agoFor local development, Chrome has a flag that lets you force specific origins to be treated as secure: chrome://flags/#unsafely-treat-insecure-origin-as-secure I don't think Firefox has anything equivalent though? This bug on the topic is unassigned: https://bugzilla.mozilla.org/show_bug.cgi?id=1410365 https://bugzilla.mozilla.org/show_bug.cgi?id=1410365
- mort96 7y agoI don't imagine that works on mobile chrome, which is what the parent comment was talking about.
- _fzslm 7y agoIt does, on Android.
- mort96 7y agoAh, TIL. Though it doesn't work on iOS Chrome, and you want to test on iOS too obviously.
- deleted 7y ago[deleted]
- Wowfunhappy 7y agoiOS Chrome is just Safari with a Google skin, Google has no control over this type of thing.
- mort96 7y agoThat's both true and completely irrelevant.
- Wowfunhappy 7y agoWell, it's relevant insofar as you're complaining to the wrong company. Does this behavior even exists in iOS Chrome? If it does, it exists in Mobile Safari as well.
- hannob 7y ago> It would be nice if it also worked on local IPs, like 192.168... That would defeat the security purpose. Anyone within your local network (which practically speaking very often means the next Wifi your device could find) could attack you.
- mort96 7y agoBut how do you do local development when you can't get an SSL cert for your dev machine's server? No, self signed certs don't always do what you need, especially on mobile where you can't just add your cert as a trusted cert easily.
- yeukhon 7y agoI know localhost is supported by Lets Encrypt but not sure about local lan network. One possible workaround is ssh forwarding. Create a tunnel. But I have not tried it myself.
- comex 7y agoIf you own a domain, you can add a subdomain that points to the local network IP, and get Let's Encrypt to give you a certificate using the dns-01 validation method (which doesn't require Let's Encrypt to actually access the IP address in the A record). This is clearly more complicated than ideal, but it should work. Edit: You can also use a custom CA root certificate, which can be installed on iOS etc. mkcert is a good starting point: https://github.com/FiloSottile/mkcert https://github.com/FiloSottile/mkcert
- mort96 7y ago> This is clearly more complicated than ideal, but it should work. Exactly. Imagine you're someone who just wants to play around with cool web technologies. Maybe you're fairly new to web dev; maybe you're fairly new to the world of programming in general and you're using the web to learn it, which has historically been one of the huge strengths of the web. You suddenly encounter a brick wall, where you figure out that programming isn't enough; you have to fork over money for a domain and learn how SSL works and how to set up let's encrypt and how to make root certs and how to install them on your phone, just because you wanted to play with something you found interesting. The web looks like it's going away from being a good platform to learn and play with programming in the name of security. It will be annoying but workable for most professional programmers who can just do whatever hacks they need to get by, but we're erecting some monumental barriers to learn this stuff. You already can't even include a fucking javascript module file from an html file without learning how to set up and configure a web server because Chrome blocks modules when using file://.
- vortico 7y agoIt's fantastic that it works with localhost (and I assume 127.0.0.1?), and it's fantastic that it doesn't work with anything else. This is the best middleground.
- mort96 7y agoWhen it doesn't work on anything other than localhost, you can't host a web server on your dev machine and test how it works on your phone. I've been through the hell of trying to test WebRTC applications on mobile Safari, and it's horrible. Specifically, you need HTTPS for WebRTC, but you obviously have to use a self signed cert because local IP. You can ignore the cert error and load the page, but connecting to the websocket for signaling will still fail because websocket on iOS requires a non-self-signed cert. Non-HTTPS websocket would work, but not from a HTTPS host. So you're in a situation where you need HTTPS due to WebRTC, but you can't use HTTPS due to websockets. In trying to push people to HTTPS by disabling features on HTTP, we're making development a _much_ worse experience. I'm not sure that's right.
- vortico 7y agoI see your point about mobile testing. (I don't do mobile work, so I didn't think of it.)
- Mister_Snuggles 7y agoYou can probably just create your own root CA and install it on your mobile device for testing. I've done this for my internal stuff at home and it works well. I use xca[0] to create/manage the root CA and the certificates, but there are other tools to do this. [0] https://hohnstaedt.de/xca/ https://hohnstaedt.de/xca/
- shkkmo 7y ago> you obviously have to use a self signed cert because local IP Not true at all, SSL certs have nothing to do with IP of the servers that use them, the servers just have to have the correct private key for that cert. You can make any domain point to local IPs by using the hosts file or even editing DNS directly.
- wlesieutre 7y agoMozilla’s previous blog post on the topic says > Mozilla will provide developer tools to ease the transition to secure contexts and enable testing without an HTTPS server. https://blog.mozilla.org/security/2018/01/15/secure-contexts-everywhere/ https://blog.mozilla.org/security/2018/01/15/secure-contexts... But the bugzilla entry they linked to with that has been unassigned for two years, so maybe they changed their minds or figure the localhost exception is sufficient. https://bugzilla.mozilla.org/show_bug.cgi?id=1410365 https://bugzilla.mozilla.org/show_bug.cgi?id=1410365 The last comment proposes a whitelist for development domains, but no response to it.
- webstudio 7y agofor easy bypass this guard - ( for rapid development / testing ) - and dont have a localhost environment ths helped me (with the 68.0 win edition): about:config set the media.getusermedia.insecure.enabled from false to true
- wlesieutre 7y agoGood to know! I'm leaving it alone on my main FF installation, but I've set that in Developer Edition.
- webstudio 7y agoon the developer-edition 69.0b3 it didn´t work - may there are some more flags needed. But on the normal edition 68.0 it worked / it is actually working.
- peterlk 7y agoTo any browser developers out there, I beg you, please, please, please whitelist lvh.me. I am so tired of security restrictions making everything painful for lvh.me.
- tty2300 7y agoWhy? That is just an ordinary domain name that someone pointed at local host. I don't see why it should get any security exemptions.
- missblit 7y agoBut nothing ensures that domain name will always point to localhost. So why should browsers trust it more than other HTTP domains? It's owned by one person, so DNS registration could lapse even with the best intentions.
- iwalton3 7y agoI wrote a script a while ago that automatically creates a subdomain on a domain I own and registers a Let’s Encrypt certificate for this exact purpose. I’ve found it very useful as it will work even for local addresses and dynamic addresses. (It will update the dns record and renew the cert on futher invocations.) I do wish there was a public solution offering this type of easy dynamic DNS with https. (Sharing the script I wrote could cost a lot on dns hosting and increased server expenses.)
- k_bx 7y agoIs generating localhost certs and then accepting them in your browser once is that hard? openssl genrsa -out key.pem 2048 openssl req -new -key key.pem -out certificate.csr openssl x509 -req -in certificate.csr -signkey key.pem -out certificate.pem
- baq 7y agoif all development servers for all frameworks just did that on first run of a project it'd be so much easier.
- k_bx 7y agoI just stopped using languages that require a "framework" or "development server" with monster json/yaml configurations to run a web server. In Haskell, a change from http to https is switching from warp.run to warp-tls.runTLS function (with certificate paths set).
- deleted 7y ago[deleted]
- mercora 7y agoin order to replicate or simulate a production environment i sometimes do something like this: ip route add local 192.0.2.123/32 table local dev lo which makes your system act like this is a local address without actually being one. EDIT: nvm i just realized that wont solve your issues with mobile development...
- joaobeno 7y agoWhile Mozilla puts users first, certain companies think they are entitled to run "their" arbitrary code on your PC, with just one click, zero warning... Oh, i forgot, they are big trustworthy companies that would never let someone explore the opening to find a way in... wink, wink...
- spaceribs 7y agoLove it, although I'm sure you can still send video/audio in non-encrypted ways right?
- asark 7y agoDear Apple: for Christmas I'd like physical, no-bullshit power shutoff switches for your camera and microphone on the Macbook Pro. Other devices too—if you can manage it, that'd be great. Sincerely, the people who put tape over their cameras, the people who don't because it's ugly and messes with closing the lid but wish they could, and the people who would be in one of those two camps if they understood the risk (so, altogether, 100% of your users).
- LeoPanthera 7y agoHave you noticed that the people who tape up their laptop camera almost always still carry around a smartphone in their pocket 100% of the time.
- mtrpcic 7y agoThe difference being that the smartphone camera isn't pointed at your face or room the entire time the device is in use.
- LeoPanthera 7y agoFrankly I don't think it's the camera that people should be most concerned about - it's the microphone.
- gsich 7y agoWhy?
- nothrabannosir 7y agoA smartphone is significantly more secure than a computer. I install lord knows what NPM package from God knows where on a weekly basis. Only since very recently does mic or camera access cause any kind of system prompt on Mac. Smartphones , for all their faults , at least are far less vulnerable to viruses than pcs. Or at least iOS vs Mac.
- progval 7y agoThis page's content is in a div named "mobile-pusher" with a 400px padding-right, which then gets disabled when loading a JS script from a third-party domain (ffp4g1ylyit3jdyti1hqcvtb-wpengine.netdna-ssl.com). wtf?
- indalo 7y agothat's wpengine's cdn, most likely the host of the blog.
- rolltiide 7y agoIts funny how everyone feels empowered to be a digital sleuth these days but makes ridiculous conclusions with the same material everyone else has
- Dylan16807 7y ago"wtf?" is not a ridiculous conclusion.
- ry4nolson 7y agoprobably related to the hamburger menu on mobile, which pushes that div over 300px
- user17843 7y agoChrome has been doing it since around 2016, it seems.
- OrgNet 7y agowhat kind of person still use chrome?
- idlewords 7y agoIn Firefox 73, they'll require consent!
- marknadal 7y agoThis sucks, my community[1] has a local offline-first video/audio call app that we run on a physical mesh network. This will make it impossible for people to talk to each other, without first needing to be connected online to some certificate authority, or without some extraordinarily difficult pre-installation process, which is often not even possible on a phone. HTTPS was important, but now its being used to shoe horn dependency on centralized online-only authority. Perfectly ripe to censor anyone. 1. https://gitter.im/amark/gun https://gitter.im/amark/gun
- comex 7y agoA browser doesn't need to connect to the certificate authority to validate a cert; only the server hosting the app 'needs' to be online (at least long enough to obtain a signed certificate every so often). The bigger problem is that there has to be a single server hosting the app in the first place, which IMO is a severe flaw in the Web's architecture. But this change doesn't really make the situation worse.
- marknadal 7y agoSubnet IPs are always different tho. Can I really get a cert for all subnet addresses? That'd be awesome! Please please educate me. I want to be clear though, I need it so that the user doesn't have to install the cert themselves, or have to be online to approve. Previously, a user would connect to the local wireless network, then the router would open them up to a directory listing of the local apps available on the network (like the video/audio call), they click the link (just points to the dynamic subnet IP of a static file server) to load the offline HTML page which then connects to call anyone in the network, including users on neighbor and neighbor-of-neighbors routers. Basically our own decentralized telecom!
- comex 7y agoSSL certificates are typically issued for domains and aren't tied to a specific IP address. So you need a domain name, and clients need to be able to resolve that domain to your IP, which means the network needs a DNS server – but the DNS server itself doesn't have to be online at all times, it just has to know what IP to return for your domain. I am not sure how that works with your mesh setup. Note that some domain validation methods involve the certificate authority resolving the domain to an IP address and trying to connect to it on the public Internet – but not all. Let's Encrypt, for example, supports the dns-01 method, which just requires a custom TXT record to be set on the domain. (But of course the TXT record itself needs to be on the public Internet.) That said, since your goal is to work offline, you may want to use a different CA that issues longer-lived SSL certificates, since Let's Encrypt only gives you 3 months at a time.
- 0xNippon 7y agoDo not want.
- jeffk_teh_haxor 7y agoWhat took them so long?
- lightedman 7y agoThey cant even get firefox to properly load (let alone let me pick) all 10 of my webcams. How about making that work, first?
- vinay_ys 7y agoIn general, I'm NOT happy with how camera/microphone, GPS and sensors like Gyro/accel/magnetometers and beacons (radio/wifi/bluetooth/nfc), screen size/resolution, battery level, hardware port identifiers etc are accessed by any website or app on my laptop/phone. This developed over the years without any input or choice from the end-user. The device manufacturers, platform owners (Apple, Google, Microsoft, Mozilla) and app developers joined together and forced this surveillance aparatus on all end-users. This power balance has to change.
- chii 7y agoThere's no problem with having the capability in a web app. It's only a problem if those capabilities are not consented to b the user first.
- vinay_ys 7y agoThere is definitely no problem in having the capabilities in the hardware. But appropriate assured controls should have been built and provided to the end-user. The challenge is these controls are not in hardware-switch-esque form. They are left to the whims and fancies of individual apps. That blame goes to platforms.
- m463 7y agoI disagree. Having things like this rolled into the browser means it's one security vulnerability or corporate decsion away from hurting someone.
- Traubenfuchs 7y agoThis is very annoying for development in my eyes. What is the preferred way to include https in your development flow? Have an nginx or apache running? What about automated tests against a running application?
- roblabla 7y agolocalhost is considered "secure" and doesn't need https - this can be used by most development and automated testing flows. For remote development, I tend to setup a caddy server which makes it very easy to get an SSL certificate. This is still mildly annoying.
- anilakar 7y agoDoes anyone still remember the times when MSIE actually warned you if you were POSTing anything over an unencrypted connection?
- d33 7y agoYes and it basically showed how it doesn't work. Applications were designed around the assumption that the user would click through the warnings. It looks like Firefox and Chromium are doing far better by restricting features to SSL, though I would be happier if they were also trying to push something more resistant to nation-state abuse...