[aklug] Re: [SOLVED] Re: Slightly off Topic: site doesn't behave the same for https as it does for http

From: Christopher Howard <ch.howard@zoho.com>
Date: Sat Dec 13 2014 - 16:58:04 AKST

Allowing mix-mode HTTPS is technically a security vulnerability, and it
is a controversial issue deciding how the browser should handle it:

blogs.msdn.com/b/ieinternals/archive/2009/06/22/https-mixed-content-in-ie8.aspxx
https://blog.mozilla.org/security/2013/05/16/mixed-content-blocking-in-firefox-aurora/

On Sat, 13 Dec 2014 16:37:15 -0900
Mike <alaskabarsalou@gmail.com> wrote:

> Nevermind.
>
> Firefox was blocking the content and I tripped over the solution by
> clicking around.
>
> Not sure I understand why it was blocking the content, but was able
> to tell it not to block the content.
>
> In this case, the content in question was some java script.
>
> It is weird to me that it would block it for https, but not http.
>
> So if someone has an explanation for that....that would be
> informative.
>
> Thanks for listening...
>
> Mike B.
>
> Quoting Mike <alaskabarsalou@gmail.com>:
>
> > Can someone explain why a site wouldn't behave the same under
> > https as it does for http?
> >
> > When I go to the site using http.... there is some javascript code
> > that scrolls four random pictures and it works how I would expect
> > it.
> >
> > However, when going to the same site with https, it doesn't scroll
> > the pictures...from what I can tell, it just stacks them atop of
> > each other.
> >
> > This particular site is using a self-signed certificate, but that
> > doesn't seem to matter.
> >
> > Thoughts?
> >
> > Mike B.
> >
> >
> > Troubleshooting Background:
> >
> > This isn't true for all browsers, so far only firefox 34 on my
> > ubuntu machine.
> >
> > Works fine for ipad, haven't tested others.
> >
> > Site is https://frontierfunflyers.org
>
>
> ---------
> To unsubscribe, send email to <aklug-request@aklug.org>
> with 'unsubscribe' in the message body.
>

---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Sat Dec 13 17:01:01 2014

This archive was generated by hypermail 2.1.8 : Sat Dec 13 2014 - 17:01:01 AKST