From b1e8da143edfed6ba26c59d1a83a755e7a8be9a4 Mon Sep 17 00:00:00 2001 From: Bernhard Posselt Date: Mon, 18 Jan 2016 20:14:43 +0100 Subject: add explanation for mixed passive content --- README.md | 42 +++++++++++++++++++++++++++++++++--------- 1 file changed, 33 insertions(+), 9 deletions(-) (limited to 'README.md') diff --git a/README.md b/README.md index d78454aca..c15f85e3d 100644 --- a/README.md +++ b/README.md @@ -103,6 +103,35 @@ To receive notifications when a new News app version was released, simply add th ## FAQ +### My browser shows a mixed content warning (Connection is Not Secure) +If you are serving your ownCloud over HTTPS your browser will very likely warn you with a yellow warnings sign about your connection not being secure. + +Chrome will show no green HTTPS lock sign, Firefox will show you the following image +![Mixed Passive Content](https://ffp4g1ylyit3jdyti1hqcvtb-wpengine.netdna-ssl.com/security/files/2015/10/mixed-passive-click1-600x221.png) + +Note that this warning **is not red and won't block the page like the following images** which signal **a serious issue**: + +![Untrusted Cert](http://www.inmotionhosting.com/support/images/stories/website/errors/ssl/chrome-self-signed-ssl-warning.png) +![Mixed Active Content](http://www.howtogeek.com/wp-content/uploads/2014/02/650x367xchrome-mixed-content-https-problem.png.pagespeed.gp+jp+jw+pj+js+rj+rp+rw+ri+cp+md.ic.r_lQiZiq38.png) + +**What is the cause of the (yellow) error message** +This warning is caused by [mixed passive content](https://developer.mozilla.org/en/docs/Security/MixedContent) and means that your page loads resources from non HTTPS resources, such as: +* Images +* Video/Audio + +This allows a possible attacker to perform a MITM (man-in-the-middle) attack by serving you different images or audio/video. + +**Why doesn't the News app fix it** +The News app fully prevents mixed **active** content by only allowing HTTPS iframes from known locations; other possible mixed active content elements such as \