webcompat / web-bugs

A place to report bugs on websites.
https://webcompat.com
Mozilla Public License 2.0
737 stars 63 forks source link

www.netvibes.com - site is not usable #18267

Closed webcompat-bot closed 6 years ago

webcompat-bot commented 6 years ago

URL: https://www.netvibes.com/signin

Browser / Version: Firefox 63.0 Operating System: Windows 10 Tested Another Browser: Yes

Problem type: Site is not usable Description: Site rendered completely differently from what it should be. Login fields do not appear, other functionality simply broken. Works fine in Edge. Steps to Reproduce: Upgraded to latest Nightly. Screenshot Description

Browser Configuration
  • mixed active content blocked: false
  • buildID: 20180815100249
  • tracking content blocked: false
  • gfx.webrender.blob-images: true
  • gfx.webrender.all: false
  • mixed passive content blocked: false
  • gfx.webrender.enabled: false
  • image.mem.shared: true
  • channel: nightly

From webcompat.com with ❤️

adamopenweb commented 6 years ago

Works fine in Firefox 61 and is also broken in Chrome Canary. I'm assuming this is Symantec distrust related.

screen shot 2018-08-15 at 12 29 56 pm
eDave56 commented 6 years ago

I created this report before creating this GitHub ID. The site netvibes.com works in the Mac and Linux versions of 63.0a1 with same build ID with my plugins enabled (MacBook Air 2015 OS X High Sierra, Linux Mint 19 Cinnamon running in VBox). Here's the troubleshooting info from the Linux version (and screen shot showing the site working in Linux version if uploader cooperates):

Application Basics

Name: Firefox Version: 63.0a1 Build ID: 20180815100249 Update Channel: nightly User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:63.0) Gecko/20100101 Firefox/63.0 OS: Linux 4.15.0-30-generic Multiprocess Windows: 1/1 (Enabled by default) Web Content Processes: 3/4 Enterprise Policies: Inactive Google Key: Found Mozilla Location Service Key: Found Safe Mode: false

Crash Reports for the Last 3 Days

All Crash Reports Nightly Features

Name: Application Update Service Helper Version: 2.0 ID: aushelper@mozilla.org

Name: Firefox Monitor Version: 2.0 ID: fxmonitor@mozilla.org

Name: Firefox Screenshots Version: 33.0.0 ID: screenshots@mozilla.org

Name: Form Autofill Version: 1.0 ID: formautofill@mozilla.org

Name: Photon onboarding Version: 1.0 ID: onboarding@mozilla.org

Name: Pocket Version: 1.0.5 ID: firefox@getpocket.com

Name: Web Compat Version: 2.0 ID: webcompat@mozilla.org

Name: WebCompat Reporter Version: 1.0.0 ID: webcompat-reporter@mozilla.org

Extensions

Name: 1-Click Downloader (Video or Photo) Version: 1.0.2 Enabled: true ID: {bdfd9428-8d65-4ff5-bc97-4a883c2aba9c}

Name: Autoplay No More Version: 0.3.6 Enabled: true ID: jid1-XQEcUtyD5PwB8w@jetpack

Name: Bulk Media Downloader Version: 0.2.1 Enabled: true ID: {72b2e02b-3a71-4895-886c-fd12ebe36ba3}

Name: Decentraleyes Version: 2.0.6 Enabled: true ID: jid1-BoFifL9Vbdl2zQ@jetpack

Name: Firefox Multi-Account Containers Version: 6.0.0 Enabled: true ID: @testpilot-containers

Name: First Party Isolation Version: 1.3.1 Enabled: true ID: {33c93ccc-ceed-47d2-9645-805ea58c8a07}

Name: Forecastfox (fix version) Version: 4.19 Enabled: true ID: forecastfox@s3_fix_version

Name: Ghostery – Privacy Ad Blocker Version: 8.2.3 Enabled: true ID: firefox@ghostery.com

Name: LastPass: Free Password Manager Version: 4.16.2.1 Enabled: true ID: support@lastpass.com

Name: No Coin - Block miners on the web! Version: 0.4.14 Enabled: true ID: {5657c026-efc3-4860-b43b-16e4eaa8a9aa}

Name: Sea Containers Version: 0.9 Enabled: true ID: {d975a11d-08cd-4aea-b7c0-989209ad860f}

Name: StickyNotes Version: 1.1.5 Enabled: true ID: sticky@filenamezero.dip.jp

Name: Tab Session Manager Version: 3.2.0 Enabled: true ID: Tab-Session-Manager@sienori

Name: Tree Style Tab Version: 2.4.24 Enabled: true ID: treestyletab@piro.sakura.ne.jp

Name: uBlock Origin Version: 1.16.16 Enabled: true ID: uBlock0@raymondhill.net

Name: uMatrix Version: 1.3.12 Enabled: true ID: uMatrix@raymondhill.net

Name: User-Agent Switcher Version: 0.2.4 Enabled: true ID: {75afe46a-7a50-4c6b-b866-c43a1075b071}

Name: Xmarks Bookmark Sync Version: 4.5.0.8 Enabled: true ID: foxmarks@kei.com

Name: Ageless Version: 1.3 Enabled: false ID: 2341n4m3@gmail.com

Name: Bitwarden - Free Password Manager Version: 1.29.0 Enabled: false ID: {446900e4-71c2-419f-a6a7-df9c091e268b}

Name: Blur Version: 7.8.2431 Enabled: false ID: donottrackplus@abine.com

Name: Bookmarks Organizer Version: 2.0.1 Enabled: false ID: bookmarksorganizer@agenedia.com

Name: Cookie Manager Version: 1.4 Enabled: false ID: cookie-manager@robwu.nl

Name: Disable HTML5 Autoplay Version: 2017.12.20 Enabled: false ID: disable-html5-autoplay@afnankhan

Name: Disconnect Version: 5.18.21 Enabled: false ID: 2.0@disconnect.me

Name: Evernote Web Clipper Version: 6.13.2 Enabled: false ID: {E0B8C461-F8FB-49b4-8373-FE32E9252800}

Name: Facebook Messenger as a Sidebar Version: 1.0 Enabled: false ID: {2b8225c9-b41b-464d-a3bb-62beff3d6b74}

Name: Firefox Lightbeam Version: 2.1.0 Enabled: false ID: jid1-F9UJ2thwoAm5gQ@jetpack

Name: Flash and Video Download Version: 3.1.9 Enabled: false ID: {bee6eb20-01e0-ebd1-da83-080329fb9a3a}

Name: Flash Block (Plus) Version: 0.1.8 Enabled: false ID: jid1-n8wH2cBfc2QaUj@jetpack

Name: FoxyTab Version: 2.11 Enabled: false ID: foxytab@eros.man

Name: In My Pocket Version: 0.9.4 Enabled: false ID: {cd7e22de-2e34-40f0-aeff-cec824cbccac}

Name: New Tab Tools Version: 89.1 Enabled: false ID: newtabtools@darktrojan.net

Name: NoScript Version: 10.1.8.16 Enabled: false ID: {73a6fe31-595d-460b-a920-fcc0f8843232}

Name: Open Link with New Tab Version: 1.0 Enabled: false ID: Open-Link-with-New-Tab@sienori

Name: Personas Plus Version: 2.0.1 Enabled: false ID: personas@christopher.beard

Name: Pocket Sidebar Version: 1.0.0 Enabled: false ID: {64690374-6b5e-4948-90dd-336ed1ac1b6b}

Name: RoboForm Password Manager Version: 8.5.1.2 Enabled: false ID: rf-firefox@siber.com

Name: Stylus Version: 1.4.13 Enabled: false ID: {7a7a4a92-a2a0-41d1-9fd7-1e92480d612d}

Name: Tab Center Redux Version: 0.5.6 Enabled: false ID: {0ad88674-2b41-4cfb-99e3-e206c74a0076}

Name: tabzen Version: 1.2.4 Enabled: false ID: tabzen@tabzen.org

Name: Tile Tabs WE Version: 10.1 Enabled: false ID: tiletabs-we@DW-dev

Name: Turn Off the Lights Version: 4.0.20.0 Enabled: false ID: stefanvandamme@stefanvd.net

Name: Twitter as a Sidebar Version: 2.0 Enabled: false ID: {3119ae66-3c2f-47e2-b1b1-1c76cb9c4ec1}

Security Software ----------------- Type:

Type:

Type:

Graphics

Features Compositing: Basic Asynchronous Pan/Zoom: wheel input enabled; scrollbar drag enabled; keyboard enabled; autoscroll enabled WebGL 1 Driver WSI Info: - WebGL 1 Driver Renderer: WebGL creation failed: Refused to create native OpenGL context because of blacklist entry: Exhausted GL driver options. WebGL 1 Driver Version: - WebGL 1 Driver Extensions: - WebGL 1 Extensions: - WebGL 2 Driver WSI Info: - WebGL 2 Driver Renderer: WebGL creation failed: * Refused to create WebGL2 context because of blacklist entry: WebGL 2 Driver Version: - WebGL 2 Driver Extensions: - WebGL 2 Extensions: - Off Main Thread Painting Enabled: true Off Main Thread Painting Worker Count: 1 GPU #1 Active: Yes Description: Humper -- Chromium Vendor ID: Humper Device ID: Chromium Driver Version: 2.1 Chromium 1.9

Diagnostics AzureCanvasAccelerated: 0 AzureCanvasBackend: skia AzureContentBackend: skia AzureFallbackCanvasBackend: none CairoUseXRender: 0 Device Reset: Trigger Device Reset Decision Log HW_COMPOSITING: blocked by default: Acceleration blocked by platform OPENGL_COMPOSITING: unavailable by default: Hardware compositing is disabled WEBRENDER: opt-in by default: WebRender is an opt-in feature unavailable by runtime: Hardware compositing is disabled WEBRENDER_QUALIFIED: blocked by env: No qualified hardware

Media

Audio Backend: remote Max Channels: 2 Preferred Sample Rate: 48000 Output Devices Name: Group Built-in Audio Analog Stereo: /devices/pci0000:00/0000:00:05.0/sound/card0 Input Devices Name: Group Monitor of Built-in Audio Analog Stereo: /devices/pci0000:00/0000:00:05.0/sound/card0 Built-in Audio Analog Stereo: /devices/pci0000:00/0000:00:05.0/sound/card0

Important Modified Preferences

accessibility.typeaheadfind.flashBar: 0 browser.cache.disk.capacity: 542720 browser.cache.disk.filesystem_reported: 1 browser.cache.disk.hashstats_reported: 1 browser.cache.disk.smart_size.first_run: false browser.cache.frecency_experiment: 3 browser.link.open_newwindow.override.external: 3 browser.places.smartBookmarksVersion: 8 browser.search.openintab: true browser.sessionstore.upgradeBackup.latestBuildID: 20180815100249 browser.startup.homepage: https://support.toshiba.com/support/viewContentDetail?contentId=4015952 browser.startup.homepage_override.buildID: 20180815100249 browser.startup.homepage_override.mstone: 63.0a1 browser.tabs.closeWindowWithLastTab: false browser.tabs.tabMinWidth: 100 browser.urlbar.placeholderName: DuckDuckGo browser.urlbar.timesBeforeHidingSuggestionsHint: 0 browser.urlbar.trimURLs: false dom.forms.autocomplete.formautofill: true dom.push.userAgentID: bbe4b98526094a15a77e8890c69003ff extensions.formautofill.creditCards.enabled: false extensions.formautofill.firstTimeUse: false extensions.lastAppVersion: 63.0a1 media.gmp-gmpopenh264.abi: x86_64-gcc3 media.gmp-gmpopenh264.lastUpdate: 1508516487 media.gmp-gmpopenh264.version: 1.7.1 media.gmp-manager.buildID: 20180815100249 media.gmp-manager.lastCheck: 1534353911 media.gmp.storage.version.observed: 1 media.peerconnection.ice.proxy_only: true media.webrtc.debug.log_file: /tmp/WebRTC.log network.cookie.prefsMigrated: true network.dns.disablePrefetch: true network.http.speculative-parallel-limit: 0 network.predictor.cleaned-up: true network.predictor.enabled: false network.prefetch-next: false places.database.lastMaintenance: 1531772863 places.history.expiration.transient_current_max_pages: 134204 plugin.disable_full_page_plugin_for_types: application/pdf plugins.flashBlock.enabled: false print.print_bgcolor: false print.print_bgimages: false print.print_duplex: 0 print.print_evenpages: true print.print_margin_bottom: 0.5 print.print_margin_left: 0.5 print.print_margin_right: 0.5 print.print_margin_top: 0.5 print.print_oddpages: true print.print_orientation: 0 print.print_page_delay: 50 print.print_paper_data: 0 print.print_paper_height: 11.00 print.print_paper_name: na_letter print.print_paper_size_unit: 0 print.print_paper_width: 8.50 print.print_scaling: 1.00 print.print_shrink_to_fit: true print.print_to_file: false print.print_unwriteable_margin_bottom: 56 print.print_unwriteable_margin_left: 25 print.print_unwriteable_margin_right: 25 print.print_unwriteable_margin_top: 25 privacy.cpd.cookies: false privacy.cpd.offlineApps: true privacy.cpd.sessions: false privacy.firstparty.isolate: true privacy.sanitize.pending: [{"id":"newtab-container","itemsToClear":[],"options":{}}] privacy.sanitize.timeSpan: 4 privacy.userContext.extension: treestyletab@piro.sakura.ne.jp security.sandbox.content.tempDirSuffix: aeabe93d-8c33-4ed5-9c80-823ec0344668 services.sync.declinedEngines: services.sync.engine.addresses: true services.sync.engine.addresses.available: true services.sync.engine.bookmarks.validation.lastTime: 1534353764 services.sync.engine.creditcards.available: true services.sync.engine.passwords.validation.lastTime: 1534353764 services.sync.engine.prefs.modified: false services.sync.lastPing: 1534353753 services.sync.lastSync: Wed Aug 15 2018 13:38:45 GMT-0400 (EDT) signon.importedFromSqlite: true storage.vacuum.last.index: 0 storage.vacuum.last.places.sqlite: 1531772862

Important Locked Preferences

Places Database

JavaScript

Incremental GC: true

Accessibility

Activated: false Prevent Accessibility: 0

Library Versions

NSPR Expected minimum version: 4.20 Beta Version in use: 4.20 Beta

NSS Expected minimum version: 3.39 Beta Version in use: 3.39 Beta

NSSSMIME Expected minimum version: 3.39 Beta Version in use: 3.39 Beta

NSSSSL Expected minimum version: 3.39 Beta Version in use: 3.39 Beta

NSSUTIL Expected minimum version: 3.39 Beta Version in use: 3.39 Beta

Sandbox

Seccomp-BPF (System Call Filtering): true Seccomp Thread Synchronization: true User Namespaces: true Content Process Sandboxing: true Media Plugin Sandboxing: true Content Process Sandbox Level: 4 Effective Content Process Sandbox Level: 4

Rejected System Calls

Internationalization & Localization

Application Settings Requested Locales: ["en-US"] Available Locales: ["en-US"] App Locales: ["en-US"] Regional Preferences: ["en-US"] Default Locale: "en-US" Operating System System Locales: ["en-US"] Regional Preferences: ["en-US"]

Screenshot Description

adamopenweb commented 6 years ago

Hi @eDave56. Thanks for the feedback.

This should be failing in all versions of Firefox Nightly that are up to date. Can you try doing a hard refresh of each?

Since this is also failing in Chrome Canary it's likely related to be a Symantec distrust issue. See: https://blog.nightly.mozilla.org/2018/08/14/symantec-distrust-in-firefox-nightly-63/

There's also a preference you can change in about:config security.pki.distrust_ca_policy change from 2 to 1. I just tested and the site works as expected with this pref flipped.

Windows:

screen shot 2018-08-15 at 2 46 18 pm

Linux:

screen shot 2018-08-15 at 2 47 43 pm

MacOS:

screen shot 2018-08-15 at 2 48 25 pm
eDave56 commented 6 years ago

Indeed, doing a hard refresh in the Linux and Mac versions resulted in failure to load/render as in the Windows version, but then setting the policy variable value you cited to 1 resulted in success in all three. Thanks so much.

Question: Is there a significant security risk in leaving the policy set to 1?

adamopenweb commented 6 years ago

Question: Is there a significant security risk in leaving the policy set to 1?

@eDave56 This will give you the same experience as Firefox release (61 currently) and in my opinion is not a big risk, but others may disagree with me on that.

eDave56 commented 6 years ago

Thank you, @adamopenweb, that is reassuring even after actually reading the article from the link you included and clicking through to some of its source material to get more of a clue. Maybe especially after reading it. Anyway, thank you for the help and opinion.

softvision-oana-arbuzov commented 6 years ago

Closing the issue as a duplicate of #1409257