12 ms·
Hey, I work on security at Facebook, and when you've turned on HTTPS mode you definitely should not be pulling javascript from anywhere over HTTP (and of course
by mkjones 15y ago
Hey, I work on security at Facebook, and when you've turned on HTTPS mode you definitely should not be pulling javascript from anywhere over HTTP (and of course our CDNs should all have valid certificates!). You're correct that this breaks a lot of the security that HTTPS offers. Do you have an example packet capture or list of HTTP CDN URLs that were referenced when you were in HTTPS mode? Or of the domain with an invalid certificate? I'll try to get that fixed ASAP.
I'd also love to debug your report getting ignored - do you know where you submitted it? We take white hat reports pretty seriously and I know I've seen a number of them resolved in less than a day after being reported. Check out https://www.facebook.com/whitehat https://www.facebook.com/whitehat to report stuff in the future (we'll even pay a bounty of $500 for most properly-disclosed security bugs: https://www.facebook.com/whitehat/bounty/ https://www.facebook.com/whitehat/bounty/).
- drivebyacct2 15y agoI'll take a capture next time and grab the <head> tag from the body. The biggest problem is that it's very sporadic. Some days it will work perfectly with no warnings and exceptions. Earlier today though, I got the "Security Warning" from Google and improper certificate (not even on the static assets) on a network that I trust to a high degree.
- mkjones 15y agoCool, thanks for the follow-up. Was the "Security Warning" you're talking about from google.com, or from facebook.com? If facebook, do you know what the specific domain was that caused the error (and the reason for the error)? Also, I'm curious where you reported this before? If there's an issue causing security bug reports to get dropped, that's something I want to fix ASAP. Thanks!
- drivebyacct2 15y agoThe security warning was the alarming red one generated by Chrome, but for the Facebook site and domain. I can't tell you if it was for the root domain or www, and I'm afraid I do not recall the error. I get a bit confused with Chrome (because it has various levels of warnings for various types of things (the page itself, scripts, stylesheets, etc) and it doesn't help that I'm on the dev channel, but sometimes I get the full blown red warning, sometimes I get the red X through the https in the url bar and sometimes I get "Insecure Script was Blocked" which occurs strangely, when I receive notifications. I honestly don't remember where I reported this before, it was not at the link you've offered above. I've got that bookmarked now. Like I said, if I have someone to contact or the whitehat link you mentioned, I will be sure to get a more detailed list of what happens when it occurs again. Thanks.