Opened 7 months ago

Closed 7 weeks ago

#29904 closed defect (fixed)

NoScript blocks MP4 videos on "Safer" and "Safest" without click-to-play option

Reported by: gk Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: noscript, tbb-8.0-issues, tbb-8.0-regression
Cc: ma1, adrelanos@… Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

In #28720 a regression in NoScript for click-to-play videos got investigated and fixed. However, there seem to be more cases that are unresolved so far. Examples are:

https://justi.cz/security/2018/11/14/gvisor-lpe.html
https://www.destroyallsoftware.com/talks/wat
http://www.html5videoplayer.net/html5video/mp4-h-264-video-test/
https://camendesign.com/code/video_for_everybody/test.html

It seems to be related to MP4. I did not find an older NoScript WebExtensions version where this did work, so no regression range.

That's again easily reproducible in a vanilla Firefox 60 ESR, by making sure everything in NoScript is allowed but media and then visiting the above mentioned URLs.

Child Tickets

Change History (11)

comment:1 Changed 7 months ago by cypherpunks

Unless you copy the video link and visit directly, click-to-play then shows up.

comment:2 Changed 7 months ago by adrelanos

Cc: adrelanos@… added

comment:3 Changed 6 months ago by gk

FWIW: on Ctrl+I (page Info) > Media Tab one is able to play the video (found on https://blog.torproject.org/comment/280654#comment-280654).

comment:4 Changed 4 months ago by ma1

Most if not all the given examples should show click-to-play placeholder in NoScript 10.6.3, thanks.
https://github.com/hackademix/noscript/releases/tag/10.6.3

comment:5 Changed 4 months ago by cypherpunks

All candidate resources failed to load. Media load paused.  watch
TypeError: this.video.error is null videocontrols.xml:1277:1

http://axqzx4s6s54s32yentfqojs3x5i7faxza6xo3ehd4bzzsg2ii4fv2iid.onion/watch?v=LpOPpBUQqcc
https://ww1.movies24.top/ray-donovan-season-6-episode-7-watch-online-free/
don't work.

comment:6 in reply to:  4 Changed 4 months ago by gk

Replying to ma1:

Most if not all the given examples should show click-to-play placeholder in NoScript 10.6.3, thanks.
https://github.com/hackademix/noscript/releases/tag/10.6.3

Indeed! Thanks, this is working for me now.

comment:7 in reply to:  5 Changed 4 months ago by gk

Replying to cypherpunks:

All candidate resources failed to load. Media load paused.  watch
TypeError: this.video.error is null videocontrols.xml:1277:1

Not sure when you get that error message. Could you open a new ticket with steps to reproduce?

http://axqzx4s6s54s32yentfqojs3x5i7faxza6xo3ehd4bzzsg2ii4fv2iid.onion/watch?v=LpOPpBUQqcc

Works for me with 10.6.3 on a Linux box.

https://ww1.movies24.top/ray-donovan-season-6-episode-7-watch-online-free/
don't work.

What is supposed to happen here? This does not work for me even on the default security level. So, this is a different issue. Could you open a new ticket with steps to reproduce (and what is supposed to happen)?

comment:8 Changed 4 months ago by gk

Resolution: fixed
Status: newclosed

Fixed in tor-browser-build with commit 07961f94a1d956c33c1d0448b6e5f69df6b03ea4 (on master) and 26a5d9739b7e0d30f03da46b316ac15546e79eef (on maint-8.5).

comment:9 Changed 7 weeks ago by echaskaris

I am experiencing this issue. I have Tor 8.5.4. I use this page to test. I have to click the link and press allow in the noscript dialog to get the click-to-play media. Thanks.

comment:10 Changed 7 weeks ago by echaskaris

Resolution: fixed
Status: closedreopened

comment:11 Changed 7 weeks ago by gk

Resolution: fixed
Status: reopenedclosed

This got fixed (and actually works for me on my Linux box). Please open a new ticket and give us a bit more information that could help figuring out what is going on, like operating system you are on, NoScript version (you'll find that in about:addons) additional customizations you made to your Tor Browser etc.

Note: See TracTickets for help on using tickets.