3 ms·
It seems I can't reply to your post (max HN thread depth = 5?), so I'll do it here... I believe the like:impression ratio for clickjacking sites isn't differen
by mkjones 16y ago
It seems I can't reply to your post (max HN thread depth = 5?), so I'll do it here...
I believe the like:impression ratio for clickjacking sites isn't different enough from the (noisy) norm to make it a usable metric for identifying malicious sites.
We should detect clickjacking sites before you get a chance to goatse your friends. I'm pretty sure our the current state of things does that. At least in Firefox, you always have the option to disable third party cookies, which will disable the like button along with a slew of other, much sketchier, stuff that ad networks and the like tend to do.
You're right that it's possible to do the cross frame stuff without an extra ui-stalling roundtrip - that's what I meant to describe in the above post. I think the bigger issue in this case is determining in the parent page when a click is happening so you can determine if it's legitimate.
I don't believe it's possible for the parent page (or fb's javascript in the parent page) to screw with the button in the iframe - cross-domain policy forbids any access to its dom.
EDIT: Also, in case it wasn't clear, as soon as we identify a domain or url to be bad, it's impossible to reach it via any click on facebook, so even if something becomes bad after people have liked it, we still retroactively protect users. So as long as we've detected that something's bad, you can't accidentally goatse your friends with it even if you do get in a like before we identify it to be bad or before it turns bad.