I think chrome is intentionally providing shitty user experience for the blocking of HTTP downloads on HTTPS pages, in order to push developers to fix it faster.

you click a HTTP download link on an HTTPS page and what happens? NOTHING. No error page, no pop-up saying "BLOCKED BECAUSE SECURITY", the browser is just like "did you click? I didn't notice"
it just sticks an error in the JS console.

which I'm sure everyone notices
BTW, this is probably going to get fixed soon, but as of Version 87.0.4280.141 (which seems to be latest) there's a bug which lets you bypass the block, most of the time.

Incognito mode.
Basically chrome won't let you download it because it has the context of you clicking it from a HTTPS page.
But it loses the context if you use the "open link in incognito window" option.
The only reason this wouldn't work is if you're in incognito mode already.
Annoyingly there's only one incognito mode, you can't have incognito mode from other incognito modes.
I demand internal security between my browser windows. none of them should know about each other!
anyway it turns out this trick isn't needed after all.
You can do "save link as", it'll let you select where to save it, then it'll fail.
but it fails in a bypassable way
so you should probably do it this way, as it's less likely to be patched out soon by an angry google dev
I understand that google wants to build a more secure web but a side effect of the everything they're doing is that the web is bitrotting faster
dev1: if we change X to Y, the web will be 2% more secure
dev2: won't that break pages not made in the last 2 years?
dev1: yes. legacy pages will stop working
dev2: how will we support the old pages?
dev1: let me say this as clearly as I can
*puts mouth on the mic* FUCK THEM
chrome.exe

More from foone

More from Tech

Recently, the @CNIL issued a decision regarding the GDPR compliance of an unknown French adtech company named "Vectaury". It may seem like small fry, but the decision has potential wide-ranging impacts for Google, the IAB framework, and today's adtech. It's thread time! 👇

It's all in French, but if you're up for it you can read:
• Their blog post (lacks the most interesting details):
https://t.co/PHkDcOT1hy
• Their high-level legal decision: https://t.co/hwpiEvjodt
• The full notification: https://t.co/QQB7rfynha

I've read it so you needn't!

Vectaury was collecting geolocation data in order to create profiles (eg. people who often go to this or that type of shop) so as to power ad targeting. They operate through embedded SDKs and ad bidding, making them invisible to users.

The @CNIL notes that profiling based off of geolocation presents particular risks since it reveals people's movements and habits. As risky, the processing requires consent — this will be the heart of their assessment.

Interesting point: they justify the decision in part because of how many people COULD be targeted in this way (rather than how many have — though they note that too). Because it's on a phone, and many have phones, it is considered large-scale processing no matter what.

You May Also Like