Why not to whitelist operating system user agents
neelc.org
neelc.org
After lots of testing and trying to contact whoever built the website I found that it blocked only user-agents which contained this literal string:
X11; Ubuntu; Linux
Only when that string was in there verbatim would it fail all requests with a 403 Forbidden.After I saw the same error with some other websites for businesses in my town I started seeing a pattern. The company that hosts/builds this website apparently copy/pastes their basic server set up, and so every website they host works everywhere, except when using Firefox on Linux. So maybe one in a thousand users gets this.
I posted my search for the cause of this issue on StackOverflow¹, and even got a reply from (presumably) someone who works for the company that hosts these websites, but alas, the websites remain broken to this day. They suspected a hack to prevent some WordPress exploit…
It's frustrating, because a general practitioner's website should not fail like this (it is a point of contact that sits just below emergency services), but the people that work there don't understand the problem, and the company that hosts is can't be arsed to fix the issue.
1: https://stackoverflow.com/questions/66185885/some-websites-r...
Haha! Never attribute malice when a simple incompetence would explain it!
Malice might be too strong of a word, disdain could be closer to what we are seeing.
Oh, we have a WordPress exploit? Let's blacklist User Agent strings!
It would be a stretch to call this an outright violation (as they could satisfy the requirement by printing the information you want and mailing it to you...), but it's a trendy topic in healthcare right now, so it might be enough of a motivator.
Unless you’re a lawyer, don’t do this. Empty threats are more frequently sorted into the crackpot category than the kind one responds to.
EDIT: I also wouldn't characterize it as an "empty threat", as it is neither empty (I think a good faith argument could be made that this needlessly disrupts patient access to information), nor a threat (it's just making them aware of something).
Seeing this topic on HN reminded me to try to and contact the website builder again, and this time they did get their hosting party to fix the problem.
The explanation as passed on to me was:
> There was a bit in the htaccess that was there since 2019, we don't know why.
Maybe now, not really sure if there are now changes (hopefully, since Microsoft is dropping IE), but in a time where browser plugins are abound you can't place an ActiveX plugin inside Firefox (or vice versa).
At least in Spain we have online administration, even if it's not perfect. Here? Hand written forms, hankos and fax machines. Everything is at least ten times as difficult as it should be.
My advise to OP is to dump Chase, Citibank, Bank Of America, ASAP. Move your money to one of the millennial focused banks, or an ETrade checking account.
The big banks hate you, they think your stupid, offering you retail banking services is the bane of their existence. They are going to knock you over with $40 fees because you SHOULD pay them to put up with you — at least that is how they see it.
There are much better options these days, just search for zero fee checking.
(Wikipedia isn’t up to date BTW. Even before the Etrade they had over $1T in AUM)
The vendor was threatening me and using my bank account level (down to the penny) to make the threats.
Chase identified the culprit, told me who it was, then offered me lifelock identity theft protection as a courtesy for my troubles.
I haven’t had $1k in my private client account since.
What was up was that on their new site, I had to use Google Chrome and only Google Chrome. Not Firefox, not even Chromium. I wonder if Edge even works.
I'm seriously considering switching providers over it.
Unfortunately there are no decent alternatives for a PPO, where I am. If it's browser issues vs an HMO, I'll begrudgingly accept developer incompetence.
I don’t have a FreeBSD machine handy right now but I just switched user agent to FreeBSD amd64 on a Linux machine with Chromium 95 and have no issue with the front page or logging into chase.com. I have rarely encountered issues using this Linux/X11 setup on chase.com for years.
Is it possible they are using an ancient browser and incorrectly assuming it’s the OS part of the user agent?
No User-Agent switcher required.
They too mention Linux so it's possible they aren't aware of the difference.
It's possible "Linux" is allowed, but not *nix/Unix?
Everything in this article and it's supporting evidence is a stretch and should be evaluated very carefully.
It looks like Firefox but there's just so many small browsers these days. Honestly I'd need to see the offending code. If it's user agent testing, those strings should still be readable even in a compressed js unless they run it through an obfuscator
Probably using qutebrowser or something else like that.
I see this from the pretty-printed version
function a() {
return /Android|webOS|iPhone|iPad|iPod|BlackBerry|IEMobile|Opera Mini/i.test(navigator.userAgent) ? "Device" : "Desktop"
}
So let's try to just say I'm say, Opera Mini, still no dice. I tried a bunhch of these to no avail. I don't know how the OP got this.Using your bank's mobile webapp is very useful when they, for some god awful reason, decide to use SafetyNet.
If there's active blocking based on OS (from replies in this thread, evidence seems to be slim) then that's not great, but this seems to be pretty one-sided so far.
User-Agent may be determined on a webserver/proxy level and request redirected silently to a page with JS just showing the banner. It does not have to be based on JS checking anything.
Nevertheless, I left banking for good and chose a company where I have real IT engineers as colleagues.
I wonder if/when banks will extend this idea to banking to prevent fraud?
Perhaps it'll be merely an optional thing at first, like 2FA.
Later it could become something that while optional, does get you a better price of some kind, much like the driving trackers that some auto insurance companies offer.
Before long, it could even become mandatory or there could be a penalty or higher price or fee to pay if you don't do it.
Just a random idea or conspiracy theory of what's possible I suppose, but it feels like something that could be possible in the not too distant future.
Of course using the bank website with the phone's browser still works...
(I say this because you're dealing with actual money, so incompatibilities from your browser might cause major problems if you're not careful)
Is it to reduce amount of testing, and only have a few "blessed" browsers with guaranteed happy experience? Any other reasons?
[0] https://github.com/amilajack/eslint-plugin-compat
[1] https://github.com/ismay/stylelint-no-unsupported-browser-fe...
Not saying this is the way it should be, just saying that “doing your best” to allow unsupported platforms often leads to a terrible and confusing user experience.
If you click through to the link, you will see that this claim is totally made up.
Google Maps work perfectly on Lion if you fake the user agent, because of course it does, it's a web app and the underlying OS is irrelevant.
They still prevent you from running their app on a rooted Android, which is nice considering I can do much more dangerous things with my money from the web site.
I have updated my article. It seems Chase is whitelisting OSes, but they seem to allow Linux and not FreeBSD based on comments and using a Linux user agent.
Chase may not block Linux because does Chase exactly want to deal with angry Linux users on the phone, or see Linux die-hards switch to competitors. Even if 1% of customers leave and don't come back, it could anger Chase's investors.
They may not officially support Linux but the web developers allow it anyways since it's too big of a minority.
They still block FreeBSD. Whether Chase's web developers don't know about BSD or they're willing to let BSD users switch to Citi Bank, I don't know.
I mean, they shouldn't whitelist by OS, but I don't know what the reasoning of blacklisting FreeBSD is.
I never even thought about the accessibility requirements. I am sure that relying on PDF features that only the latest Acrobat supports hurts a lot of people on that front too (unless Acrobat happens to be the most accessible of readers?)
Chase does not have to implement a specific solution to a users problem, they have to make a reasonable adjustment - I.e. you can install a small ramp if someone asked for a lift.
Depending on the issue raised, chase may feel they have a reasonable way of providing the services - for instance if the user is blind and uses some specific Linux screen reader then telephone banking may also be a reasonable adjustment rather than Linux support.
Chase may see supporting Linux for all users because of one persons disability as an ‘unreasonable’ adjustment (I don’t see the issue, but this is approximately how the claim would work). To be open I’m not exactly sure how ADA works as I’m more familiar with UK legislation.
There are people who only use Linux in textmode.
Both Firefox and Google Chrome support powerful screen readers and other accessibility features based on an open standard. A site using these would surely be ADA-compliant
A business is going to have a hard time arguing that providing text is unreasonable.
"You are using a non-free Operation System and thus signing away you fundamental rightsas a user. Please use a free Operationsystem like GNU/Linux to access this website."
At that point we'll need a user-agent switcher that is website aware to know which sites need which user-agents. Like secret hand signals to get into your secret clubs.
I'll just pass and not use any of it at that point.
Microsoft Edge already has something like this built in to get around Google's user agent checks.
I mean worst case scenario I can always open dedicated Windows VM, but I will admit that the trend is troubling.. especially with Win11 push towards 'trusted computing'.
As an aside, one issue Chase did have, 10 years ago, was that their DNS servers would return “query refused” if you sent them an AAAA (i.e. IPv6 IP) query. This actually caused issues with my recursive DNS server; I had to make AAAA (IPv6) queries handle errors differently than A (IPv4) queries. I just checked, and Chase finally fixed their DNS and IPv6 issues.