Anti-phishing measure has incorrect prompts on dialog box

Bug #274992 reported by Kevin McCormick
4
Affects Status Importance Assigned to Milestone
firefox-3.0 (Ubuntu)
Incomplete
Undecided
Unassigned

Bug Description

Go to URL: http://test:<email address hidden>

The dialog box says:

'You are about to log in to the site "example.com" with the username "test", but the website
does not require authentication. This may be an attempt to trick you.

Is "test" the site you want to visit?'

By clicking "Yes", I am taken to example.com, not "test".

I don't believe this requires any changes to the functions of the box, simply the text. The box should ask if "example.com" is the site you want to visit. The Windows version behaves this way.

Revision history for this message
Parthan SR (parth-technofreak) wrote :

Thank you for taking your time to report this bug and help make Ubuntu better. Can you please specify the release version of Ubuntu you are using and the full version of Firefox installed?

I have verified this in Firefox-3.0.3 in Intrepid beta and the bug doesn't exist. It correctly asks me,
Is "example.com" the site you want to visit?
and hence the bug is invalid for Firefox-3.0.3.

Changed in firefox-3.0:
status: New → Incomplete
Revision history for this message
Kevin McCormick (kmccormick) wrote :

This is in 8.04.1 release, with Firefox 3.0.3. I just confirmed that it still occurs as well.

$ apt-cache policy firefox
firefox:
  Installed: 3.0.3+build1+nobinonly-0ubuntu0.8.04.1

$ apt-cache policy firefox-3.0
firefox-3.0:
  Installed: 3.0.3+build1+nobinonly-0ubuntu0.8.04.1

Revision history for this message
Jonathan Wakely (jwakely) wrote :

this is bug 271933
and https://bugzilla.redhat.com/show_bug.cgi?id=462392
so it isn't ubuntu-specific

all reported occurrences are with x86_64.

noone seems to be looking into it, even though the anti-phishing check is completely backwards and therefore does more harm than good.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.