Handshake Papers
Handshake Papers
@HandshakePapers

Is loading an image over HTTP on an HTTPS page a harmless warning?

Is loading an image over HTTP on an HTTPS page a harmless warning?

The dismissal "it's just an image over HTTP, the warning is cosmetic" misreads the threat model behind mixed content. Browsers split mixed content into two classes. Active mixed content — scripts, stylesheets, iframes, fetch/XHR — is blocked outright, because an attacker who substitutes it executes in your origin. Passive mixed content — images, audio, video — is what triggers the softer warning, and that is where the "harmless" myth lives.

Passive content is not benign. An on-path attacker (think hostile Wi-Fi) who intercepts an HTTP image can swap pixels, but more importantly the request still leaks: the HTTP fetch exposes the page context, referrer, and cookies sent in cleartext, and a manipulated image can be used for tracking or, with crafted dimensions, layout-based deception. The integrity guarantee of HTTPS is broken for that subresource.

This is why browsers now auto-upgrade passive mixed content to HTTPS where possible and warn where not. The Content Security Policy directive upgrade-insecure-requests formalizes it.

— Active mixed content: blocked, can run code
— Passive: warned, but leaks and is tamperable
— upgrade-insecure-requests rewrites the requests

Further reading: W3C Mixed Content specification; CSP upgrade-insecure-requests.
Bottom line: Passive mixed content still breaks the page's confidentiality and integrity guarantee. Fix the URLs; don't dismiss the warning.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.