Security issues with custom domain name

scwalterscwalter Registered Users Posts: 417 Major grins
edited July 3, 2007 in SmugMug Pro Sales Support
I hardly ever use IE anymore, but I went to my site today using my custom domain and discovered a bunch of things that really bother me. I don't know if these are Smugmug issues, if my IE6 settings are hosed or if these issues can be fixed.

Issue #1: When I go to my site via my smugmug url, http://scwalter.smugmug.com/ all is well, no security warnings. If I go to http://www.scottwalterphoto.com/ I see the little privacy report thing pop up and it shows this:

168566471-O.jpg

So I highlight the first error: cookiemonster.mg and click on summary and see this:

168566514-O.jpg

No privacy report available, so IE does not appear to accept some/all cookies from smugmug.com. I check my security settings for IE and they are set to medium. I think this is the default, but I'm not sure.

168566542-O.jpg

Issue #2: So in light of the above issues, I attempt to add some photos to the cart and see what happens. Everything seems okay because once I go to the cart, I'm on www.smugmug.com, but when I hit the "continue browsing" button I see this error.

168566442-O.jpg

I think that last one might scare off some legitimate customers.

I've just recently upgraded to a pro account and these things seem broken. If I were a customer looking to buy prints, these errors would leave me doubting whether to actually make the purchase.

Am I doing something wrong or is this really how it's supposed to work?

Thanks,
Scott
Scott Walter Photography
scwalter.smugmug.com

Comments

  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited July 1, 2007
    Hi, what version of IE is this, and on what OS are you running please?
  • scwalterscwalter Registered Users Posts: 417 Major grins
    edited July 1, 2007
    Andy wrote:
    Hi, what version of IE is this, and on what OS are you running please?

    IE6 on WinXP SP2
    Scott Walter Photography
    scwalter.smugmug.com
  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited July 1, 2007
    In IE7, I navigated your site, back / forth, added stuff to the cart, no security warnings, or anything.

    I'm using default security in IE7.

    Do you have an special addons, or software modules that govern your surfing?

    I'll check IE6 in a sec.
  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited July 1, 2007
    Andy wrote:

    I'll check IE6 in a sec.
    Sorry, no trouble here, buying from your site, IE6, Win XP.

    But you do have IE6 errors on your site. Something in your custom code you made is not IE6-friendly - line 449, object expected....
  • scwalterscwalter Registered Users Posts: 417 Major grins
    edited July 1, 2007
    Andy wrote:
    In IE7, I navigated your site, back / forth, added stuff to the cart, no security warnings, or anything.

    I'm using default security in IE7.

    Do you have an special addons, or software modules that govern your surfing?

    I'll check IE6 in a sec.

    No additional software, no firewall, norton, etc. I also just tried from my work PC (VPN and then via remote desktop ) and I get the same security warnings. My work PC is only about two weeks old and the default security on it was also set to medium.

    -Scott
    Scott Walter Photography
    scwalter.smugmug.com
  • scwalterscwalter Registered Users Posts: 417 Major grins
    edited July 1, 2007
    Andy wrote:
    Something in your custom code you made is not IE6-friendly - line 449, object expected....

    How did you see that error? Is it a scripting error (Java)?

    Also, I checked out your site (moonriverphotography) from home and work and I get exactly the same behavior as shown above, everything from the security warnings about no privacy policy all the way to the security warning when I go from the cart back to browsing.

    Thanks,
    Scott
    Scott Walter Photography
    scwalter.smugmug.com
  • AndyAndy Registered Users Posts: 50,016 Major grins
    edited July 1, 2007
    scwalter wrote:
    How did you see that error? Is it a scripting error (Java)?

    Also, I checked out your site (moonriverphotography) from home and work and I get exactly the same behavior as shown above, everything from the security warnings about no privacy policy all the way to the security warning when I go from the cart back to browsing.

    Thanks,
    Scott
    You've got something set in IE6 that isn't "default" security...
  • scwalterscwalter Registered Users Posts: 417 Major grins
    edited July 1, 2007
    Andy wrote:
    You've got something set in IE6 that isn't "default" security...

    Thanks for all the quick respones Andy!!

    That's what I thought too, so i just went to Tools/Internet Options.../Security and it said "Custom Level". I hit the button to reset to "default level", cleared my cache, restarted IE6 and the same errors appear.

    Is there another way besides this to reset the security settings? Is anyone else seeing this problem? Keep an eye out for the little red icon in the status bar, towards the right side just to the left of the <icon> Internet sign.

    Thanks,
    Scott
    Scott Walter Photography
    scwalter.smugmug.com
  • DnaDna Registered Users Posts: 435 Major grins
    edited July 2, 2007
    scwalter wrote:
    Thanks for all the quick respones Andy!!

    That's what I thought too, so i just went to Tools/Internet Options.../Security and it said "Custom Level". I hit the button to reset to "default level", cleared my cache, restarted IE6 and the same errors appear.

    Is there another way besides this to reset the security settings? Is anyone else seeing this problem? Keep an eye out for the little red icon in the status bar, towards the right side just to the left of the <icon> Internet sign.

    Thanks,
    Scott
    Yep, I get the same. Looks like it might be something to do with the slideshow ?!? <img src="https://us.v-cdn.net/6029383/emoji/headscratch.gif&quot; border="0" alt="" >
    Same error with continuing browsing from the cart, although that's not a bad thing that the cart is secure and your website isn't.

    Andrew
  • AllenAllen Registered Users Posts: 10,013 Major grins
    edited July 2, 2007
    Scott, you have version 57 of the slideshow js, might put in the latest version
    58 and see if it helps, can't hurt.
    Al - Just a volunteer here having fun
    My Website index | My Blog
  • BeachBillBeachBill Registered Users Posts: 1,311 Major grins
    edited July 2, 2007
    IE6 is the first browser (that I know about) that requires a "compact privacy policy". More information at the following sites:

    http://support.microsoft.com/kb/283185
    http://www.p3pprivacy.com/

    So with medium security as you have set (which I believe is the default in IE6), IE will block cookies from any third-party code running on your site (anything that is access from outside your domain). I don't know if any other web browsers current support p3p or even if they have support planned as I have heard VERY little about it and only in an IE context.

    The dialog where it says you are exiting a secure site is perfectly valid and correct. Smugmug cannot provide SSL security for your custom domain name and it is not necessary as your domain is just used to browse photos, not to make any purchases.
    Bill Gerrard Photography - Facebook - Interview - SmugRoom: Useful Tools for SmugMug
  • scwalterscwalter Registered Users Posts: 417 Major grins
    edited July 2, 2007
    Andy wrote:
    You've got something set in IE6 that isn't "default" security...

    Andy,

    I believe this statement is not correct. Based on other people replies and my own testing on a two-week old machine, when using a custom URL, Smugmug gives security warnings using the default settings in IE6. If this is really true, I am extremely disappointed. If this is not true, please correct me.

    thanks,
    Scott
    Scott Walter Photography
    scwalter.smugmug.com
  • {JT}{JT} Registered Users Posts: 1,016 Major grins
    edited July 3, 2007
    Yes, the cookiemonster.js is blocked by IE - SmugMug does not have a site wide P3P policy - so behaves as it was designed to. That file does not provide an absolutely necessary function for the site to operate. As for the cart error, I can understand how that is jarring, I will look in to changing that in our future cart revision.

    JT



    scwalter wrote:
    Andy,

    I believe this statement is not correct. Based on other people replies and my own testing on a two-week old machine, when using a custom URL, Smugmug gives security warnings using the default settings in IE6. If this is really true, I am extremely disappointed. If this is not true, please correct me.

    thanks,
    Scott
  • scwalterscwalter Registered Users Posts: 417 Major grins
    edited July 3, 2007
    {JT} wrote:
    Yes, the cookiemonster.js is blocked by IE - SmugMug does not have a site wide P3P policy - so behaves as it was designed to. That file does not provide an absolutely necessary function for the site to operate. As for the cart error, I can understand how that is jarring, I will look in to changing that in our future cart revision.

    JT

    JT,

    Thanks for the response. I understand the cookie blocking doesn't affect the functionality, it just surprised me to see that there were warnings.

    Fixing the cart warning would be nice, but I understand why it's there for now.

    Thanks,
    Scott
    Scott Walter Photography
    scwalter.smugmug.com
Sign In or Register to comment.