Small percentage of users receiving ERR_SSL_PROTOCOL_ERROR and unable to load stuff
lmvm2041
PROOP

3 months ago

Some users are experiencing issues loading certain parts of the website, such as images and other data stored in the railway buckets. It was recently discovered that their network security is blocking access to the bucket URL because it has been marked as "possibly malicious." We are unable to do much, and thought it was a good idea to open a ticket instead.

I attached the images below. I tried running the URL through different virus checkers such as VirusTotal but they returned clean.

image.png

image.png

image.png

21 Replies

lmvm2041
PROOP

3 months ago

https://railway.com/project/0a2fe4ba-fe0e-495b-a983-f5f1c3e1e8de?

The bucket URL being blocked is organized-snackbox-bgq5i.t3.storageapi.dev


lmvm2041
PROOP

3 months ago

image.png

Attachments


3 months ago

Where was this screenshot made from?


lmvm2041
PROOP

3 months ago

app: Helix Fi

isp: Videotron Ltee


lmvm2041
PROOP

3 months ago

According to the user that reported it


lmvm2041
PROOP

3 months ago

I'm not 100% sure what applications other users are using which is blocking their access to the bucket though


3 months ago

After some searching, it seems like a 'protection' layer for networks

I don't think Railway or Tigris (Railway's bucket provider) can do anything about this


lmvm2041
PROOP

3 months ago

Is there maybe a workaround I could try or is it out of my control as well?


lmvm2041
PROOP

3 months ago

If not, thats fine I guess


3 months ago

It's out of your control as far as I can tell


3 months ago

Could recommend your user to contact Videotron/Helix to get the false positive resolved


lmvm2041
PROOP

3 months ago

Will do, thank you <:salute:1137099685417451530>


3 months ago

Actually, what I think could work, is creating a CNAME record pointing to organized-snackbox-bgq5i.t3.storageapi.dev, and using that instead

May have to proxy it through Cloudflare as well


lmvm2041
PROOP

3 months ago

I could give it a try


lmvm2041
PROOP

3 months ago

Will see if that works


3 months ago

Since the domain isn't flagged by VirusTotal/URLVoid, I have a feeling that the name itself may be getting flagged


3 months ago

something prettier could then work


lmvm2041
PROOP

3 months ago

Tried it out by proxying images from that bucket URL to cdn.erlcx.com and it seems to be working, BUT, our memory usage is spiking a ton. Not sure if its the way our developer set it up but yeah

Screenshot_2026-03-05_113121.png

Attachments


lmvm2041
PROOP

3 months ago

But I mean, it works <:shrug:1408521109443449014>


lmvm2041
PROOP

3 months ago

Not sure if it was a resource template, not quite sure how he set it up

Screenshot_2026-03-05_113221.png

Attachments


3 months ago

I believe you could just replace the hostname of the signed URL to that of the CNAME pointing to that of the bucket

You could also consider going directly to Tigris and creating a bucket there, you'll be able to make it public


Welcome!

Sign in to your Railway account to join the conversation.

Loading...