Unsupported Flag unsafely-treat-insecure-origin-as-secure

12,044 views
Skip to first unread message

Muhammad Zubair

unread,
Jun 15, 2017, 4:29:27 AM6/15/17
to securi...@chromium.org
Hi


Above link says that by using flag

unsafely-treat-insecure-origin-as-secure

we can test the features over http but I am getting the following message while using it.

You are using an unsupported command-line flag: --unsafely-treat-insecure-origin-as-secure. Stability and security will suffer.

PFA

--
Muhammad Zubair

Software Engineer

Mob. +92 345 9632 108
Capture.PNG

Eric Lawrence

unread,
Jun 15, 2017, 8:04:32 AM6/15/17
to Muhammad Zubair, Security-dev
Yes, this is expected. It means the flag is in use, but it notes that using the flag reduces your security. 

Muhammad Zubair

unread,
Jun 20, 2017, 8:16:56 AM6/20/17
to securi...@chromium.org
Hi

I used this flag but still getting error while using

navigator.getUserMedia(options, successCallbac, errorCallback);

It still triggers the errorCallback with the message Only secure origins are allowed

Eric Lawrence

unread,
Jun 20, 2017, 8:37:05 AM6/20/17
to Muhammad Zubair, Security-dev
The flag has no effect unless --user-data-dir is also supplied. Example: --unsafely-treat-insecure-origin-as-secure=http://a.test,http://b.test --user-data-dir=/test/only/profile/dir

Joshua Watson

unread,
Jun 20, 2017, 9:34:01 AM6/20/17
to Security-dev
I have the same issue with embedded content linked in the webpage. I'm using the following flags on chromeos:

--unsafely-treat-insecure-origin-as-secure=http://domain1,http://domain2,http://domain4,http://ip1,http://ip2
--user-data-dir=/home/chronos
--allow-running-insecure-content
--reduce-security-for-testing

Also, using a directory other than the default chronos directory results in a restart and frozen boot (I waited 2 hours to verify it was frozen).

Emily Stark

unread,
Jun 22, 2017, 12:21:27 AM6/22/17
to Muhammad Zubair, security-dev
Hi -- can you please tell us what exact command-line options you are using when you run Chrome, and also what URL you are testing navigator.getUserMedia on?
Thanks,
Emily

Emily Stark

unread,
Jun 22, 2017, 12:22:52 AM6/22/17
to Joshua Watson, Security-dev
Can you please explain what you mean by "the same issue with embedded content linked in the webpage"? Are you trying to use getUserMedia as the previous poster was, or are you trying to load insecure scripts in a secure page? Do you have an example webpage that we could look at that illustrates the problem?
Thanks,
Emily


--
You received this message because you are subscribed to the Google Groups "Security-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email to security-dev+unsubscribe@chromium.org.

jo...@joshwatson.net

unread,
Jun 22, 2017, 11:11:42 AM6/22/17
to Security-dev, zedi...@gmail.com
Thanks for your response Emily. I am shamefully piggybacking this post; I am trying to run insecure scripts on an insecure page. No matter what combination of exceptions I use, I could not get the microphone and the camera to work via flash. Despite the unsafely-treat-insecure-origin-as-secure flag being active for the api origin, I was still receiving an error similar to "microphone and camera are no longer allowed on insecure origins".

Strangely, this issue stopped occurring about 12 hours ago with no changes on my end, and no changes to the code of the webpage. Perhaps it was just a driver issue?

> To unsubscribe from this group and stop receiving emails from it, send an email to security-dev...@chromium.org.

eka...@gmail.com

unread,
Nov 5, 2018, 6:45:59 AM11/5/18
to Security-dev, zedi...@gmail.com, jo...@joshwatson.net
Not working for me same issue.

--unsafely-treat-insecure-origin-as-secure

ศิรรักษ์ เดล

unread,
Nov 9, 2021, 9:08:04 PM11/9/21
to Security-dev, eka...@gmail.com, zedi...@gmail.com, jo...@joshwatson.net
I've faced  this, how to fix?
ในวันที่ วันจันทร์ที่ 5 พฤศจิกายน ค.ศ. 2018 เวลา 18 นาฬิกา 45 นาที 59 วินาที UTC+7 eka...@gmail.com เขียนว่า:

Derek Lafontaine

unread,
Jun 28, 2022, 5:32:18 PM6/28/22
to Security-dev, ศิรรักษ์ เดล, eka...@gmail.com, zedi...@gmail.com, jo...@joshwatson.net
I get this message everytime I use chrome and want to know how to fix it....Can someone please help me
Reply all
Reply to author
Forward
0 new messages