mozilla / contain-facebook

Facebook Container isolates your Facebook activity from the rest of your web activity in order to prevent Facebook from tracking you outside of the Facebook website via third party cookies.
Mozilla Public License 2.0
985 stars 177 forks source link

"cdn.fbsbx" domain is opened in a normal tab when downloading a file from Messenger #102

Closed SoftVision-CarmenFat closed 4 years ago

SoftVision-CarmenFat commented 6 years ago

[Affected versions]:

[Affected Platforms]:

[Prerequisites]:

[Steps to reproduce]:

  1. Open the browser with the profile from prerequisites.
  2. Navigate to www.messenger.com website.
  3. Select the conversation where the .gif file is displayed.
  4. Click the .gif file.
  5. Click the "Download" button and observe what happens next.

[Expected result]:

[Actual result]:

[Notes]:

download files

ryanfeeley commented 6 years ago

Seems like we should be mainaining a curated like like Disconnect, but for Facebook properties and CDNs. Users should not have to think about this one the add-on is installed (unless it is breaking something).

TanviHacks commented 6 years ago

What else is this cdn used for? Given it’s breaking a bunch of messenger functionality around downloads, It would be a good candidate to add today, but not without at least a little more information on what else this domain does.

TanviHacks commented 6 years ago

googling this, I don't know what it is and there are all these references to malware and viruses. Not 1.3.0, unless Ryan you can tell us what this domain is about.

@ryanfeeley

TanviHacks commented 6 years ago

Does the download fail?

TanviHacks commented 6 years ago

Is this an issue with jpgs or pngs?

SoftVision-CarmenFat commented 6 years ago

Does the download fail?

The download doesn't fail. The issue here is that Facebook's related domain (cdn.fbsbx) opens in a normal tab, so the user's downloads can be easily tracked.

Is this an issue with jpgs or pngs?

This issue is not reproducible when downloading .jpg, .png or .mp4 files. Before downloading these files, they are opened in Facebook's (or Messenger's) image/video built-in viewer, therefore, there isn't any newly opened tab.

groovecoder commented 6 years ago

Thanks for being so diligent in finding these issues @SoftVision-CarmenFat, @SoftVision-PaulOiegas, and team!

I will feel better if we punt this to 1.3.1 release and make our 1.3.0 release with these known issues that we can fix later.

ryanfeeley commented 6 years ago

I'm not sure I understand the harm is erring on the side of adding too many sites to the FB container. I think it's a better user experience as it reduces breakage.

groovecoder commented 6 years ago

The only risk is that we find additional buggy behavior on the same day as the release. I'll add more domains and bug-fixes for 1.3.1 so it can go thru more testing before release.

pdehaan commented 6 years ago

Unable to repro in 1.3.1 using an embedded GIF. Interestingly, when I posted an imgur link to a GIF and it embedded, it never seemed to hit the FB CDN, and would just redirect immediately to imgur instead of giving me a download prompt. But when I used the GIF button in the Messenger conversation to embed a GIF, I was able to see the Download option, and the image downloaded without opening new tabs to the CDN or anything weird or unexpected.

nico123dsa commented 4 years ago

please help me guys. some one hacked my friend fb account. please. :((

maxxcrawford commented 4 years ago

Per https://www.whois.com/whois/fbsbx.com, this is a Facebook domain.

maxxcrawford commented 3 years ago

@Tiffdh84 I've removed your post as it violates our community participation guidelines. Thanks!

marilouplatero commented 2 years ago

Plse help me cause I'm new here.

Parkmij commented 2 months ago

I'm very happy

Parkmij commented 2 months ago

Very happy

Parkmij commented 2 months ago