8000 Cannot access Zen-Browser website on Zen Browser · Issue #551 · zen-browser/www · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Cannot access Zen-Browser website on Zen Browser #551

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
5 tasks done
eyesoffsin opened this issue Apr 10, 2025 · 18 comments
Open
5 tasks done

Cannot access Zen-Browser website on Zen Browser #551

eyesoffsin opened this issue Apr 10, 2025 · 18 comments

Comments

@eyesoffsin
Copy link
eyesoffsin commented Apr 10, 2025

Captchas

  • I have read the instructions.
  • I have searched existing issues and avoided creating duplicates.
  • I am not filing an enhancement request.
  • I have checked that this issue cannot be reproduced on Mozilla Firefox.
  • I have checked that this issue can be reproduced once I removed all my Mods and Custom CSS.

What happened?

Ever since installing the zen browser i have not been able to open any of the zen websites ive tested on my other browser opera gx and it loads just fine on it, tried searching for a reasoning or another bug report and have found nothing, i was in the last version of the browser and since updated and the issue is still here, im new to all this but love the browser so hope anyone can help me fix this

Image

Version

1.11.1b

What platform are you seeing the problem on?

Windows - x64

What component is this issue related to?

Other

Relevant log output if applicable

@Propheticus
Copy link
Propheticus commented Apr 10, 2025

Looks like you use a TIM Safe Web service that does some HTTPS decrypting and resigning (in order to malware/virusscan the content of the traffic?).
This means your browser is presented with a certificate for the domain of safeweb-service.tim.it which does not match with the website's domain zen-browser.app
Due to the strict(er) certificate settings in Zen (HSTS) the connection gets blocked.

@eyesoffsin
Copy link
Author
eyesoffsin commented Apr 10, 2025

Looks like you use a TIM Safe Web service that does some HTTPS decrypting and resigning (in able to malware/virusscan the content of the traffic?). This means your browser is presented with a certificate for the domain of safeweb-service.tim.it which does not match with the website's domain zen-browser.app Due to the strict(er) certificate settings in Zen (HSTS) the connection gets blocked.

how could i fix it then? when i open it on other browsers it goes through without a problem. if its the TIM Safe Web service wouldnt it affect the other browser?

@SirOMGitsYOU
Copy link

Also having the same issue, not affecting the Zen website but is affecting a lot of other websites including ones that I own which at the time I reported it were unaffected and last night all stopped working but work completely fine on other browsers, definitely a Zen issue - as no issue on any other browser or base firefox with the same settings.

zen-browser/desktop#7389, have also tried with no AV or zen mods on and same issue only started a few versions ago

@Propheticus
Copy link

how could i fix it then? when i open it on other browsers it goes through without a problem. if its the TIM Safe Web service wouldnt it affect the other browser?

You could try clearing the sites preferences (see step 2.2 in this how-to) for sites that give you this error.

If a site explicitly sets HSTS, this protects against HTTPS downgrade or man-in-the-middle (mitm) attacks. The service you're using effectively operates as a mitm , so when a site has set HSTS, Firefox (or Zen) is rightfully rejecting the connection.

However, I just checked and zen-browser.app does not even set HSTS in the header. So it's strange that this error is thrown.

@SirOMGitsYOU I think we need to differentiate between cases where Zen is correctly following the HSTS standard (IETF RFC 6797) protecting again mitm attacks and cases where the connection is rejected even though the expiry date and domain of the certificate are correct.... or cases where the site did not specify HSTS in its headers at all.

Here it looks like the error is thrown even on sites that don't set HSTS in their header at all:

Image

Can you help rule out this is an issue with the default profile by creating a new/clean one in about:profiles ? (nota bene: it sets the new profile as the default upon creation.)

@Propheticus Propheticus moved this from Triage to Verification in Zen Browser - public roadmap Apr 11, 2025
@eyesoffsin
Copy link
Author

how could i fix it then? when i open it on other browsers it goes through without a problem. if its the TIM Safe Web service wouldnt it affect the other browser?

You could try clearing the sites preferences (see step 2.2 in this how-to) for sites that give you this error.

If a site explicitly sets HSTS, this protects against HTTPS downgrade or man-in-the-middle (mitm) attacks. The service you're using effectively operates as a mitm , so when a site has set HSTS, Firefox (or Zen) is rightfully rejecting the connection.

However, I just checked and zen-browser.app does not even set HSTS in the header. So it's strange that this error is thrown.

@SirOMGitsYOU I think we need to differentiate between cases where Zen is correctly following the HSTS standard (IETF RFC 6797) protecting again mitm attacks and cases where the connection is rejected even though the expiry date and domain of the certificate are correct.... or cases where the site did not specify HSTS in its headers at all.

Here it looks like the error is thrown even on sites that don't set HSTS in their header at all:

Image

Can you help rule out this is an issue with the default profile by creating a new/clean one in about:profiles ? (nota bene: it sets the new profile as the default upon creation.)

ive cleared out the sites preferences and restarted the browser and the issue still remains

@eyesoffsin
Copy link
Author

and i think it also seem that its creating a conflict with the updating system? (im not sure) since i cant load any of the zen browser websites i have to update it through here, but the browser although being on the latest version seems to think it has a new available update and continues to pop up on my screen

Image

@SirOMGitsYOU
Copy link

how could i fix it then? when i open it on other browsers it goes through without a problem. if its the TIM Safe Web service wouldnt it affect the other browser?

You could try clearing the sites preferences (see step 2.2 in this how-to) for sites that give you this error.

If a site explicitly sets HSTS, this protects against HTTPS downgrade or man-in-the-middle (mitm) attacks. The service you're using effectively operates as a mitm , so when a site has set HSTS, Firefox (or Zen) is rightfully rejecting the connection.

However, I just checked and zen-browser.app does not even set HSTS in the header. So it's strange that this error is thrown.

@SirOMGitsYOU I think we need to differentiate between cases where Zen is correctly following the HSTS standard (IETF RFC 6797) protecting again mitm attacks and cases where the connection is rejected even though the expiry date and domain of the certificate are correct.... or cases where the site did not specify HSTS in its headers at all.

Here it looks like the error is thrown even on sites that don't set HSTS in their header at all:

Image

Can you help rule out this is an issue with the default profile by creating a new/clean one in about:profiles ? (nota bene: it sets the new profile as the default upon creation.)

So for some reason creating a new profile seems to do the job,

Hard to test without all my settings and bookmarks etc, Is there an easy way to migrate my current settings, extensions + data, cookies, mods & pinned tabs to put that theory to full force testing?

@Propheticus
Copy link

You could either only clear all site preferences (menu > history > clear recent history > check only the bottom option and timeframe Everything

Image

You could also backup your original profiles folders somewhere (just in case) and from the folder listed under 'root directory' in the profile manager delete the SiteSecurityServiceState.bin file.

@eyesoffsin
Copy link
Author

You could either only clear all site preferences (menu > history > clear recent history > check only the bottom option and timeframe Everything

Image

You could also backup your original profiles folders somewhere (just in case) and from the folder listed under 'root directory' in the profile manager delete the SiteSecurityServiceState.bin file.

if done both steps and the issue still remains

@Propheticus
Copy link
Propheticus commented Apr 11, 2025

Bah!
If clearing 'cookies and site data' & 'caches' also does not help there's a little more cumbersome route:
Create a new profile and copy over some of the old profiles data and configs into it.
See https://docs.zen-browser.app/guides/manage-profiles
From that instruction I guess the last file mentioned (prefs.js) has the highest risk of copying over the issue.

@mauro-balades mauro-balades transferred this issue from zen-browser/desktop Apr 12, 2025
@KyleDL101
Copy link
Contributor

Please try restarting the browser in troubleshoot mode over at 'about:support'. Troubleshoot mode automatically disables extensions and any other modifications to the profile (it's basically like using vanilla Zen). It's best to try it on the problematic profile. The Zen website loads fine for me (even after clearing the cache).

Simply copying over all your data, extensions, modifications, etc. to a new profile could cause the issue on the new profile if the problem lies within that data. It's entirely possible that this is an extension issue or similar. @eyesoffsin

@SirOMGitsYOU
Copy link

Please try restarting the browser in troubleshoot mode over at 'about:support'. Troubleshoot mode automatically disables extensions and any other modifications to the profile (it's basically like using vanilla Zen). It's best to try it on the problematic profile. The Zen website loads fine for me (even after clearing the cache).

Simply copying over all your data, extensions, modifications, etc. to a new profile could cause the issue on the new profile if the problem lies within that data. It's entirely possible that this is an extension issue or similar. @eyesoffsin

Still happens in troubleshooting mode too.

@eyesoffsin
Copy link
Author

Please try restarting the browser in troubleshoot mode over at 'about:support'. Troubleshoot mode automatically disables extensions and any other modifications to the profile (it's basically like using vanilla Zen). It's best to try it on the problematic profile. The Zen website loads fine for me (even after clearing the cache).

Simply copying over all your data, extensions, modifications, etc. to a new profile could cause the issue on the new profile if the problem lies within that data. It's entirely possible that this is an extension issue or similar. @eyesoffsin

ive done the following steps sorry for the late reply, but the issue still happens, my browser is currently unmodded aswell since i have never been able to enter zens website on it, and even without my extensions which r only ad blockers off it still didnt go through, i cleared the entire cache aswell just to be 100% sure and it still didnt load.

@eyesoffsin
Copy l 8000 ink
Author

Bah! If clearing 'cookies and site data' & 'caches' also does not help there's a little more cumbersome route: Create a new profile and copy over some of the old profiles data and configs into it. See https://docs.zen-browser.app/guides/manage-profiles From that instruction I guess the last file mentioned (prefs.js) has the highest risk of copying over the issue.

i am currently also unable to enter that website i get the same error.

Image

@eyesoffsin
Copy link
Author

just updated the browser to the latest version and the issue still remains.

Image

@SirOMGitsYOU
Copy link

Bah! If clearing 'cookies and site data' & 'caches' also does not help there's a little more cumbersome route: Create a new profile and copy over some of the old profiles data and configs into it. See https://docs.zen-browser.app/guides/manage-profiles From that instruction I guess the last file mentioned (prefs.js) has the highest risk of copying over the issue.

Been trying a few days now with just my bookmarks on a new profile and the issue has just come back again,

Not installed any Zen Mods or Extensions just plain zen with bookmarks.

Definitely seems to be an issue somewhere with Zen as never had such an issue before with FF, Edge, Chrome or Opera GX

@wangwq7
Copy link
wangwq7 commented Apr 26, 2025

就是zen的bug太多了,证书这个问题老早就有了,一直不解决,影响很多人使用

@taroj1205
Copy link
Member

Hi guys we've updated the homepage slightly, can anyone confirm if the issue has been resolved?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Verification
Development

No branches or pull requests

6 participants
0