Insecure content (CC license badge) on secure sites help.launchpad.net and dev.launchpad.net

Bug #488241 reported by Nico R.
290
This bug affects 6 people
Affects Status Importance Assigned to Milestone
Launchpad Development Wiki Moin theme
Fix Released
Low
William Grant
Launchpad Help Wiki Moin theme
Fix Released
Low
William Grant

Bug Description

Pages on the domains help.launchpad.net and dev.launchpad.net (for example the main pages <URL:https://help.launchpad.net/> and <URL:https://dev.launchpad.net/>) include a reference to the image <URL:http://i.creativecommons.org/l/by/2.0/uk/80x15.png> each. This image is served via HTTP, as you can see from the URI, so this results in insecure content (sometimes this combination is called „mixed content“) being served to the User Agent.

Either the image needs to be copied to the launchpad servers, and served from there via HTTPS, or a HTTPS reference to a Creative Commons host needs to be used. In the latter case, make sure to get in touch with the people at creativecommons.org, because i.creativecommons.org uses the certificate issued for api.creativecommons.org, and accessing creativecommons.org via TLS (port 443, HTTPS) results in a security warning for me. In the former case, I am not sure about the copyright status of the CC badge (but it *should* be at least CC-licensed, shouldn’t it? :-) ).

The problem may appear on other domains than help.launchpad.net and dev.launchpad.net as well, but as I do not have a list of all launchpad domains, I could not check. Someone should verify that please.
It does not appear on <URL:https://launchpad.net/> or <URL:https://edge.launchpad.net/>, though.

Nico R. (n-roeser)
visibility: private → public
Curtis Hovey (sinzui)
affects: launchpad → launchpad-documentation
Changed in launchpad-documentation:
importance: Undecided → Low
status: New → Triaged
affects: launchpad-documentation → launchpad-help-moin-theme
Changed in launchpad-dev-moin-theme:
status: New → Triaged
importance: Undecided → Low
Revision history for this message
painkiller6of6the6wired (painkiller6of6the6wired) wrote :

I consider the best way of solving the problem is to copy CC logo, not to correct reference to it.
I believe that it is not a good practice to provide links to other sites by means of tags other than <a> tag.

William Grant (wgrant)
Changed in launchpad-dev-moin-theme:
assignee: nobody → William Grant (wgrant)
status: Triaged → In Progress
Changed in launchpad-help-moin-theme:
assignee: nobody → William Grant (wgrant)
status: Triaged → In Progress
William Grant (wgrant)
Changed in launchpad-dev-moin-theme:
status: In Progress → Fix Released
Changed in launchpad-help-moin-theme:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.