Skip to main content

For what are probably very sound productivuty reasons, my empolyers network blocks traffic from TikTok and Snapchat but that is no issue to me becasue I don’t use them.  (it also blocks Deezer, but perversely not Spotify - go figure!).  However,  when I move around these Community pages, as well as those on the Sonos main site, when a new page opens I get alerts telling me that content from Tiktok and content from Snapchat is not permitted.  Are there “hidden” linke to those sites somwhere in the code of these sites or is there some other, more acceptable reason?

Hi ​@essenby 

Thanks for your post!

We do not have links to TikTok or to Snapchat on our pages - certainly not our main pages, but I think we’d also remove any that users posted on the Community. Certainly so if they were not relevant to Sonos.

Could you please post some links here to which pages you saw these reports come up? Thanks.

I think it also might be a good idea to check your browser’s extensions to see if there is anything suspicious there - it could be that links are being injected onto our pages by your browser.

 


Hi ​@Corry P 
You may have something there with the Browser suggestion, although I can’t think what.

Using Firefox I see alerts an almost every page.   So much so that I think that if I don’t see an alert then it is an error of some kind.

Same experience when using Chrome.

However when I use Edge - I don’t see the alerts at all so I think that might point to the way the browser renders the code in the page?


Hi ​@essenby 

Do you only see these reports on our websites though? If it were due to a browser extension, I would have thought it would behave like this for all websites.

I am not sure about Firefox, but I believe Edge is now Chrome with a disguise on, to an extent.

Can you please post a screenshot or two? Thanks.


@Corry P 

These are the  warnng alerts that are displayed and yes they only happen on this site.  I have seen them very sprodically from the Sonos main site (https://www.sonos.com/en-gb/home) but his is by no means reproduceable.  I have not seen them from any other site.

 


Hi ​@essenby 

@Corry P 

I have not seen them from any other site.

Well, that’s strange.

Sorry - I should have specified - could you please screenshot again, but clearly show in it that the reports are coming from the fact that you have our webpage open? I’m going to have to try to convince our web team to look into this, and I may need some encouragement for them.

The weird thing is that my work PC has similar safety filters on it, and I see no such reports (though I guess it is possible the filter is disabled for our own domains). More tellingly, I have not heard any reports from anyone else, and this is exactly the kind of thing that gets flagged by our superusers pretty much instantly. They won’t be behind work-safe filters, however, so perhaps not. 

I am not sure what to make of this at all.

I may at some point request that you click that Feedback button, but let’s see what our team can make of this first.

 


As requested<.  Although I suspect the “Feedback” button it to enable feedback to  “IT admin” who will mearely ignore it 😀

 


Press F12 and go to the Network tab. In there you should be able to see which urls are offending your IT department.


Just pulled up my DNS logs for the last 7 days and looked for either source in them. Found these from 5 days ago. That is the Linux desktop I browse here from but that time looks to be more when I was doing some social media stuff.

No hits at all from my tablet that I use for these forums several times a day.

I was hoping to see more, something that I could use to track down the problem posts but I don’t think I will see anything to dig into.

DNS Filter log:

2024-11-30 13:28:09 HTTPS analytics.tiktok.com Hp-800.home.arpa Blocked (gravity) NODATA (0.3ms)  Whitelist
2024-11-30 13:28:09 A analytics.tiktok.com Hp-800.home.arpa Blocked (gravity) IP (0.5ms)

Press F12 and go to the Network tab. In there you should be able to see which urls are offending your IT department.

@controlav - Many thanks for this.

 

@Corry P - Fpllowing the above advice I have identified the following which may help in the investigation: -

Method

Domain

Initiated by

Error

Post

tr.snapchat.com

seven.min.js.js2(beacon)

SSL_ERROR_NO_CYPHER_OVERLAP

Get

Analytics.tiktok.com

recent_line_803 . injected Script:2(script)

SSL_ERROR_NO_CYPHER_OVERLAP

 

By repeating this on several pages I note that the “Initiated by” and “Error” values can vary but the “Domain” is constant

 


Hi ​@essenby ​@controlav & ​@Stanley_4 

Thank you all - we have forwarded all this to the web team for further investigation.


Reply