4 ms·
Didn't target="_blank" originate in that era you were talking about? I know the target attribute was part of HTML4 (1999). I'm not sure when _blank became a spe
by XaspR8d 9y ago
Didn't target="_blank" originate in that era you were talking about? I know the target attribute was part of HTML4 (1999). I'm not sure when _blank became a special value, but I imagine it was before the spec acknowledged it.
I agree window.opener was a fairly dangerous addition, but it is subject to CORS restrictions. You can't access it from just anywhere.
- username223 9y agoI think you're right about target=_blank. Still, it has very little potential to benefit the user, who can option-click or similar if he/she wants a new tab or window, but has to copy-and-paste to prevent one. It should never have been added. I would rather that web browsers simply not implement things with significant potential to do harm; at the least, those things should be disabled by default. Unfortunately we aren't headed that way: WebUSB is coming[1]. Anyone who could write that "[t]he composablity of the web allows a new ecosystem of hardware support to be built entirely from web technology" without feeling a chill run down their spine and imagining a years-long security nightmare is truly blind. [1] https://wicg.github.io/webusb/ https://wicg.github.io/webusb/
- eponeponepon 9y agoStrewth, I can't even read that without wanting to go and uninstall every browser from every device I own. Are people really considering this? People that, y'know... matter? edit: good lord, I read further and saw this: 3. Security and Privacy Considerations This section is non-normative. ...I mean... surely, surely that's the one bit that should be most gigantically normative? Right?
- pmoriarty 9y ago"This specification recommends device manufacturers practice defense in depth by designing their devices to only accept signed firmware updates and/or require physical access to the device in order to apply some configuration changes." Yes, let's put the burden of protecting users from browser-transmitted malware on to the hardware manufacturers, who've had a such a wonderful track record of caring about and protecting their users' security in the past. What could possibly go wrong?
- username223 9y agoAagh! "Let's take hardware designed to be connected to a machine by its owner, connect it to the whole internet, and blame the hardware when it gets hacked." Does anyone remember how long it took for single-user operating systems to harden themselves against remote attacks? Yeah, they're still working on it. Now imagine something like that, but for hardware that either never gets firmware updates, or is connected to the internet so it can have them pushed.
- duskwuff 9y ago> ...I mean... surely, surely that's the one bit that should be most gigantically normative? Right? No. "Security and privacy considerations" sections of standards documents are typically used for a analysis or discussion of the security/privacy posture of the standard. The security features are "baked into" other portions of the document.
- hdhzy 9y ago> I agree window.opener was a fairly dangerous addition, but it is subject to CORS restrictions. You can't access it from just anywhere. You can't access things via opener but you can change the location of opener, that's an easy target for phishing.