Unfortunately i have just finished attempting all of the suggestions both of you suggested and the issue is still existing. for the record this is not an OS issue as i am the only one in the group running on a mac, and i tried it on a windows 10 VM... STEP 4: Web Browser: Google Chrome Browser Version: 55.0.2883.95 Operating System: Macintosh OS X 10.12.3 If Javascript is enabled: YES Your anti-virus software: None List of any browser add-ons or extensions enabled: None LOG (getting 403 from AWS): 2Navigated to <a href="https://roll20.net/" rel="nofollow">https://roll20.net/</a> (index):83 Mixed Content: The page at '<a href="https://roll20.net/" rel="nofollow">https://roll20.net/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://www.drivethrurpg.com/images/44/197746-thumb140.jpg" rel="nofollow">http://www.drivethrurpg.com/images/44/197746-thumb140.jpg</a>'. This content should also be served over HTTPS. /editor/:12 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-nI6oq7TBb0/ZMhJlZWQ21HKspjuppw/Mq2qJplY6i3I='), or a nonce ('nonce-...') is required to enable inline execution. /editor/:13 Refused to execute inline script because it violates the following Content Security Policy directive: "script-src 'self' 'unsafe-eval' https://*.googlesyndication.com https://*.doubleclick.net <a href="https://partner.googleadservices.com" rel="nofollow">https://partner.googleadservices.com</a> <a href="https://www.googletagservices.com" rel="nofollow">https://www.googletagservices.com</a> <a href="https://ssl.google-analytics.com" rel="nofollow">https://ssl.google-analytics.com</a> <a href="https://www.google-analytics.com" rel="nofollow">https://www.google-analytics.com</a> <a href="https://ajax.googleapis.com" rel="nofollow">https://ajax.googleapis.com</a> <a href="http://ajax.googleapis.com" rel="nofollow">http://ajax.googleapis.com</a> <a href="https://d3clqjduf2gvxg.cloudfront.net" rel="nofollow">https://d3clqjduf2gvxg.cloudfront.net</a> <a href="https://cdn.firebase.com" rel="nofollow">https://cdn.firebase.com</a> https://*.firebaseio.com https://*.tokbox.com https://*.opentok.com <a href="http://static.opentok.com" rel="nofollow">http://static.opentok.com</a> <a href="http://www.google-analytics.com" rel="nofollow">http://www.google-analytics.com</a> <a href="http://cdn.crowdin.com" rel="nofollow">http://cdn.crowdin.com</a> <a href="https://crowdin.com" rel="nofollow">https://crowdin.com</a> <a href="http://stun.l.google.com" rel="nofollow">http://stun.l.google.com</a>". Either the 'unsafe-inline' keyword, a hash ('sha256-npngRtQYomQz2/PGlo3OMaFWOvAvrm65p+WFyZPCRuo='), or a nonce ('nonce-...') is required to enable inline execution. Navigated to <a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a> app.js?1486144092:31 70 app.js?1486144092:31 TOUCH SUPPORTED: false app.js?1486144092:33 Custom Sheet Translation app.js?1486144092:26 select app.js?1486144092:26 Switch mode to select app.js?1486144092:42 Initializing new dice engine with randomness... app.js?1486144092:42 Using random entropy app.js?1486144092:46 Compiling sheet... app.js?1486144092:46 Found rolltemplate: simple app.js?1486144092:46 Found rolltemplate: atk app.js?1486144092:46 Found rolltemplate: dmg app.js?1486144092:46 Found rolltemplate: atkdmg app.js?1486144092:46 Found rolltemplate: desc app.js?1486144092:46 Found rolltemplate: spell app.js?1486144092:46 Found rolltemplate: npc app.js?1486144092:46 Found rolltemplate: npcatk app.js?1486144092:46 Found rolltemplate: npcdmg app.js?1486144092:46 Found rolltemplate: npcaction app.js?1486144092:46 Found webworker script app.js?1486144092:46 Finding sheet rolls... app.js?1486144092:47 window resize app.js?1486144092:32 Final set zoom! app.js?1486144092:32 Final set zoom! tutorial_tips.js:7 tuts loaded app.roll20.net/:1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png</a>'. This content should also be served over HTTPS. app.roll20.net/:1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/3OxOqmb.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/3OxOqmb.png</a>'. This content should also be served over HTTPS. 3app.roll20.net/:1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/ZgULBCp.png</a>'. This content should also be served over HTTPS. app.roll20.net/:1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/py5B0cm.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/py5B0cm.png</a>'. This content should also be served over HTTPS. app.roll20.net/:1 Mixed Content: The page at '<a href="https://app.roll20.net/editor/" rel="nofollow">https://app.roll20.net/editor/</a>' was loaded over HTTPS, but requested an insecure image '<a href="http://imgsrv.roll20.net/?src=i.imgur.com/LoT21n1.png" rel="nofollow">http://imgsrv.roll20.net/?src=i.imgur.com/LoT21n1.png</a>'. This content should also be served over HTTPS. sheetsandboxworker.js?20160926:250Starting up WEB WORKER app.js?1486144092:38 Final page load. app.js?1486144092:37 Auth'ed. app.js?1486144092:37 Go post auth! app.js?1486144092:37 initial setup app.js?1486144092:38 Heard playingplaylist change to -K_RTN9RL8H49DZ22P2G app.js?1486144092:38 -K_Xtp2ECpoeNO8N3jjs app.js?1486144092:38 PLAYING TRACK app.js?1486144092:35 T.r {attributes: Object, _escapedAttributes: Object, cid: "c0", changed: Object, _silent: Object…} app.js?1486144092:37 Got players value... app.js?1486144092:37 joining game... 3app.js?1486144092:35 Full load page! app.js?1486144092:37 We have 5 pages app.js?1486144092:35 Player -K_L7pTYa6rI9k3ZhYHu is offline... app.js?1486144092:35 Player -K_LB29IIqyHgISBTjJn is offline... app.js?1486144092:36 Global Volume: 0=0 app.js?1486144092:35 Player -K_XY4rB1uXw-uOuQCVV is offline... app.js?1486144092:35 Player -K_XYEM_B9jx5fXkchmY is offline... app.js?1486144092:35 Player -K_XZFuq3Nx528IHmCOz is offline... app.js?1486144092:35 Player -Kb2zXs9czwuv6w2d208 is offline... app.js?1486144092:37 Deferred finish joining... app.js?1486144092:31 Firebase Online app.js?1486144092:44 Loading Roll20 Chat Event Handlers app.js?1486144092:37 handle page changes app.js?1486144092:37 false app.js?1486144092:33 139 app.js?1486144092:45 Refresh Journal List! app.js?1486144092:45 Search took 6ms app.js?1486144092:37 init active page! app.js?1486144092:35 activate page! app.js?1486144092:35 FULLY ACTIVATE VIEWS FOR PAGE. app.js?1486144092:38 Scan for new plays! app.js?1486144092:33 Do refresh link cache! app.js?1486144092:35 Graphics: 18 app.js?1486144092:35 Paths: 4 app.js?1486144092:35 Reorder by ZORDER app.js?1486144092:35 Reorder by ZORDER app.js?1486144092:45 Refresh Journal List! app.js?1486144092:45 Search took 4ms app.js?1486144092:34 Swapping <a href="https://s3.amazonaws.com/files.d20.io/images/26830922/l2H95rcj5Xcv0He905uBtQ/thumb.jpg?14832143055" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26830922/l2H95rcj5Xcv0He905uBtQ/thumb.jpg?14832143055</a> to <a href="https://s3.amazonaws.com/files.d20.io/images/26830922/l2H95rcj5Xcv0He905uBtQ/original.jpg?14832143055" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26830922/l2H95rcj5Xcv0He905uBtQ/original.jpg?14832143055</a> thumb.png:1 GET <a href="https://s3.amazonaws.com/files.d20.io/images/26910362/8xhCxVAAD7CevMhoXSygyQ/thumb.png?14834146445" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26910362/8xhCxVAAD7CevMhoXSygyQ/thumb.png?14834146445</a> 403 (Forbidden) thumb.png:1 GET <a href="https://s3.amazonaws.com/files.d20.io/images/26908978/X__f3goovD-ZMsryWExOQQ/thumb.png?14834119605" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26908978/X__f3goovD-ZMsryWExOQQ/thumb.png?14834119605</a> 403 (Forbidden) 4app.js?1486144092:30 Error loading image, probably due to cors. Trying once without CORS for <a href="https://s3.amazonaws.com/files.d20.io/images/26910362/8xhCxVAAD7CevMhoXSygyQ/thumb.png?1483414644" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26910362/8xhCxVAAD7CevMhoXSygyQ/thumb.png?1483414644</a> app.js?1486144092:30 Error loading image, probably due to cors. Trying once without CORS for <a href="https://s3.amazonaws.com/files.d20.io/images/26908978/X__f3goovD-ZMsryWExOQQ/thumb.png?1483411960" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26908978/X__f3goovD-ZMsryWExOQQ/thumb.png?1483411960</a> app.js?1486144092:35 Reorder by ZORDER thumb.png:1 GET <a href="https://s3.amazonaws.com/files.d20.io/images/26910602/Q2CJ2eacxUHwCBld_7Lo9g/thumb.png?14834149655" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26910602/Q2CJ2eacxUHwCBld_7Lo9g/thumb.png?14834149655</a> 403 (Forbidden) mini.jpg:1 GET <a href="https://s3.amazonaws.com/files.d20.io/images/26931214/3dxBVb9Xw5b2AdWXWj7J3g/mini.jpg?1483477811" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26931214/3dxBVb9Xw5b2AdWXWj7J3g/mini.jpg?1483477811</a> 403 (Forbidden) app.js?1486144092:30 Error loading image, probably due to cors. Trying once without CORS for <a href="https://s3.amazonaws.com/files.d20.io/images/26910602/Q2CJ2eacxUHwCBld_7Lo9g/thumb.png?1483414965" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26910602/Q2CJ2eacxUHwCBld_7Lo9g/thumb.png?1483414965</a> thumb.png:1 GET <a href="https://s3.amazonaws.com/files.d20.io/images/26910339/6kcbFRR-OvGsIawdIJTJPA/thumb.png?14834146345" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26910339/6kcbFRR-OvGsIawdIJTJPA/thumb.png?14834146345</a> 403 (Forbidden) mini.png:1 GET <a href="https://s3.amazonaws.com/files.d20.io/images/26910362/8xhCxVAAD7CevMhoXSygyQ/mini.png?1483414644" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26910362/8xhCxVAAD7CevMhoXSygyQ/mini.png?1483414644</a> 403 (Forbidden) 2app.js?1486144092:30 Error loading image, probably due to cors. Trying once without CORS for <a href="https://s3.amazonaws.com/files.d20.io/images/26910339/6kcbFRR-OvGsIawdIJTJPA/thumb.png?1483414634" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26910339/6kcbFRR-OvGsIawdIJTJPA/thumb.png?1483414634</a> thumb.png:1 GET <a href="https://s3.amazonaws.com/files.d20.io/images/26908978/X__f3goovD-ZMsryWExOQQ/thumb.png?1483411960" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26908978/X__f3goovD-ZMsryWExOQQ/thumb.png?1483411960</a> 403 (Forbidden) thumb.png:1 GET <a href="https://s3.amazonaws.com/files.d20.io/images/26910362/8xhCxVAAD7CevMhoXSygyQ/thumb.png?1483414644" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26910362/8xhCxVAAD7CevMhoXSygyQ/thumb.png?1483414644</a> 403 (Forbidden) thumb.png:1 GET <a href="https://s3.amazonaws.com/files.d20.io/images/26910602/Q2CJ2eacxUHwCBld_7Lo9g/thumb.png?1483414965" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26910602/Q2CJ2eacxUHwCBld_7Lo9g/thumb.png?1483414965</a> 403 (Forbidden) thumb.png:1 GET <a href="https://s3.amazonaws.com/files.d20.io/images/26910339/6kcbFRR-OvGsIawdIJTJPA/thumb.png?1483414634" rel="nofollow">https://s3.amazonaws.com/files.d20.io/images/26910339/6kcbFRR-OvGsIawdIJTJPA/thumb.png?1483414634</a> 403 (Forbidden) app.js?1486144092:34 setting src app.js?1486144092:30 Cols: 3 Rows: 2 app.js?1486144092:30 Took 1ms to generate cache.