4 ms·
> I don't think it's possible to remotely steal the encryption key as JavaScript doesn't have access to browser's bookmarks. I think a trusted site might be ab
by spokey 16y ago
> I don't think it's possible to remotely steal the encryption key as JavaScript doesn't have access to browser's bookmarks.
I think a trusted site might be able to read the bookmark URL from the history object, but that seems to be sandboxed in general and might not contain javascript: links in the first place. If you were more clever with JavaScript than I am you might be able to do something like (1) pop open the current page in a new window to hide what you're about to do from the user, (2) invoke history.back() in the "parent" window, and (3) read the URL from window.location