Single post

jump to replies

21 visible replies; 8 more replies hidden or not public

back to top
Avatar for leeloo
Leeloo , @leeloo@c.im
(open profile)

@sunny
Hey browser makers, weren't you supposed to be running in a sandbox? You realize that the clipboard is outside the sandbox, right?

And that everyone who cares about security was warning you that allowing Javascript to access the clipboard was a security hole decades ago?

So, how many of you still haven't fixed this glaring hole?

Avatar for dat
Cegorach , @dat@social.g33ky.de
(open profile)
@sunny yes I can

But only because I work in IT and do such shit for a living.

more relevant question: can you formulate a single sentence criterion on how stupid users should tell those apart?

And I'd say that's impossible.

Worse: any that I came up with would rather recognize the wrong one as malicious.
Avatar for number6
Number6 :syncthing: , @number6@fosstodon.org
(open profile)

@dat @sunny

The hacker left off a step.

The one on the left will give you a serious sounding warning that what you are about to do could hurt your system.

So a sentence about, "If you receive a message saying you might be hurting your system, stop, and contact IT immediately." might help.

The one on the right could be malware, but either the Stores have to be compromised, or you will need to side-load an app, which is non-trivial for most users.

Avatar for sco_tty
ScoTTY , @sco_tty@mastodon.social
(open profile)

@sunny One gives RCE, all my data and likely my identity to some botnet or ransomware group, the other gives the same to a surveillance tech monopolist corp that abandoned even pretending to "not be evil"

At this point i would definitely put more trust in the first one. Ransomware gangs at least give you customer support after locking you out of your digital life 💀