Bug#807143: Iceweasel user-agent prevents usage with chase.com; works with Firefox user-agent

Josh Triplett josh at joshtriplett.org
Sat Dec 5 22:49:53 UTC 2015


Package: iceweasel
Version: 42.0-1
Severity: important

Some time ago, Chase Bank (https://www.chase.com/) started generating
warnings about using an out-of-date browser, despite using a version of
Iceweasel based on the latest upstream Firefox.  As of recently, they
now completely reject logins from a browser using the Iceweasel
User-Agent.  Changing the User-Agent to the corresponding Firefox
User-Agent (dropping the Iceweasel/42.0 token) allows logging in.

Yes, this is a stupid thing for Chase to do.  However, a quick check on
Alexa confirms that Chase is the 116th most popular site on the web.

Between this and the privacy concerns about browser fingerprinting (e.g.
Panopticlick), versus the little-to-no value provided by including this
token, is there any reason *not* to remove the Iceweasel token from the
User-Agent string and match the upstream Firefox User-Agent?

-- Addons package information
ii  gnome-shell    3.18.3-2     amd64        graphical shell for the GNOME des
ii  iceweasel      42.0-1       amd64        Web browser based on Firefox
ii  rhythmbox-plug 3.2.1-1      amd64        plugins for rhythmbox music playe
ii  xul-ext-adbloc 2.6.10+dfsg- all          advertisement blocking extension 
ii  xul-ext-https- 5.1.1-2      all          extension to force the use of HTT
ii  xul-ext-itsall 1.9.2-1      all          extension to edit textareas using

-- System Information:
Debian Release: stretch/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 4.3.0-trunk-amd64 (SMP w/4 CPU cores)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages iceweasel depends on:
ii  debianutils               4.5.1
ii  fontconfig                2.11.0-6.3
ii  libasound2                1.0.29-1
ii  libatk1.0-0               2.18.0-1
ii  libc6                     2.21-3
ii  libcairo2                 1.14.4-1
ii  libdbus-1-3               1.10.6-1
ii  libdbus-glib-1-2          0.102-1
ii  libevent-2.0-5            2.0.21-stable-2+b1
ii  libffi6                   3.2.1-3
ii  libfontconfig1            2.11.0-6.3
ii  libfreetype6              2.6.1-0.1
ii  libgcc1                   1:5.3.0-3
ii  libgdk-pixbuf2.0-0        2.32.2-1
ii  libglib2.0-0              2.46.2-1
ii  libgtk2.0-0               2.24.28-1
ii  libhunspell-1.3-0         1.3.3-3+b2
ii  libnspr4                  2:4.11-1
ii  libnss3                   2:3.21-1
ii  libpango-1.0-0            1.38.1-1
ii  libsqlite3-0              3.9.2-1
ii  libstartup-notification0  0.12-4
ii  libstdc++6                5.3.0-3
ii  libvpx2                   1.4.0-4
ii  libx11-6                  2:1.6.3-1
ii  libxcomposite1            1:0.4.4-1
ii  libxdamage1               1:1.1.4-2+b1
ii  libxext6                  2:1.3.3-1
ii  libxfixes3                1:5.0.1-2+b2
ii  libxrender1               1:0.9.9-2
ii  libxt6                    1:1.1.5-1
ii  procps                    2:3.3.10-4+b1
ii  zlib1g                    1:1.2.8.dfsg-2+b1

Versions of packages iceweasel recommends:
ii  gstreamer1.0-libav         1.6.1-1
ii  gstreamer1.0-plugins-good  1.6.1-1

Versions of packages iceweasel suggests:
pn  fonts-lmodern          <none>
pn  fonts-stix | otf-stix  <none>
ii  libcanberra0           0.30-2.1
ii  libgnomeui-0           2.24.5-3
ii  libgssapi-krb5-2       1.13.2+dfsg-4
pn  mozplugger             <none>

-- no debconf information



More information about the pkg-mozilla-maintainers mailing list