4 ms·
It seems the new Clipboard API requires explicit permission (video on [0]), that's not going to increase adoption I suppose. [0]: https://developers.google.com
by Promarged 8y ago
It seems the new Clipboard API requires explicit permission (video on [0]), that's not going to increase adoption I suppose.
[0]: https://developers.google.com/web/updates/2018/03/clipboardapi https://developers.google.com/web/updates/2018/03/clipboarda...
- frgewut 8y agoReading from clipboard without explicit permissions would be a severe security issue.
- Cthulhu_ 8y agoYup, I have passwords and such in there.
- therealmarv 8y agotell that Android users... https://www.xda-developers.com/stop-apps-reading-android-clipboard/ https://www.xda-developers.com/stop-apps-reading-android-cli...
- Lx1oG-AWb6h_ZG0 8y agoWriting to a clipboard when you’re the active tab doesn’t require the prompt, I’d imagine that covers the vast majority of use cases. I can’t think of any good reason why a site should be able to read from the clipboard silently, or write to it in the background.
- catach 8y agoA clipboard history web app isn't the craziest idea in the world, though it's at least moderately crazy.
- reificator 8y agoIt might not win but it's a serious contender.
- catach 8y agoAnd yet, I bet there's at least a few dozen people in the world that would fall in love with such a thing, and get viciously angry if you tried to mess with their workflow.
- bad_user 8y agoPrioritizing the use case of the clipboard history web app would ruin the day for many 1Password / LastPass / KeePass etc users. Automatic password filling isn't great, isn't universal, KeePass's keyboard emulation never worked reliably for me, so users of such apps rely on the clipboard a lot. And consider that you don't have to give out a password frequently via the clipboard, you only have to do it once with a malicious app nearby. What I'd like the OS itself to do is to block by default copy/pasting between apps, with the user agreeing to each combination, with "only once" option available. But sadly, for historical purposes I guess, or maybe because normal users would get annoyed, the OS doesn't do that.
- catach 8y ago> What I'd like the OS itself to do is to block by default copy/pasting between apps, with the user agreeing to each combination, with "only once" option available. This made me think. At the cost of learning new key combinations, a clipboard manager browser extension could isolate in-browser copy/pastes from the system clipboard, unless explicitly asked.
- michaelmrose 8y ago"What I'd like the OS itself to do is to block by default copy/pasting between apps, with the user agreeing to each combination, with "only once" option available." Please no. At present any application which could compromise you by stealing passwords could probably just as easily pwn your entire system thus you will have saved zero people from harm. Meanwhile 99.9% of people will be frustrated by such an ill thought out security measure. 50% will have to google how to fix clipboard permissions to disable this. 25% will ask their computer literate friends how to do this. 20% will click once every single time and just think the new release of their OS sucks slightly. 10% will accidentally click deny at some point and think cut and paste is broken. Some percentage will probably reinstall their entire OS to fix cut and paste or just hate their life every time they hit this application combination. Random web pages should probably just never have access to your clipboard because people will just click accept when the malicious site askes. Its sufficient that your browser which you either trust or are already laughably pwned to have access to the clipboard so that you can paste stuff into websites. Said sites don't even need to know the difference between user typed foo and user pasted foo.
- jonny_eh 8y agoAnd it's not crazy for the user to grant it permission.