3 ms·
The use of the word "trick" here is well-warranted. This is really more of a UI thing (i.e. it's a little too easy for a user to accidentally click "Ok"). Appli
by Derek_MK 8y ago
The use of the word "trick" here is well-warranted. This is really more of a UI thing (i.e. it's a little too easy for a user to accidentally click "Ok"). Applications have responded to concerns like this by just having the "Ok" button be non-clickable for a full second after appearing.
- abrowne 8y agoAh, so that must be why there's sometimes a delay to click to accept a download in Firefox!
- sp332 8y agoYup, you can change it in about:config under security.dialog_enable_delay. But here's a blog post from 2004 showing how easy it is to exploit a user if you turn it off. http://www.squarefree.com/2004/07/01/race-conditions-in-security-dialogs/ http://www.squarefree.com/2004/07/01/race-conditions-in-secu...
- Sylos 8y agoSo, this was a known exploit before Chrome even existed...
- feikname 8y agoI tested the demo and it seems the associated javascript function to prompt someone to install a software is no longer present in Firefox (netscape.security.PrivilegeManager.enablePrivilege). I question the utility of having this delay behaviour by default, worst that can happen is you accidentally start a download AFAIK, which you can just quickly delete/cancel afterwards. And, there's browser.download.manager.alertOnEXEOpen too. I much prefer Chrome's behaviour of starting the download and you instantly can see the filename and size in the bottom as soon as it starts and can then choose to either open it or show it in the file manager.
- mappu 8y ago> worst that can happen is you accidentally start a download There's a potential DLL hijacking attack: 1. Accidental download of kernel32.dll 2. Ignore, who cares, do something else 3. Download actually_wanted_installer.exe, which finds malicious kernel32.dll in current directory instead of SYSTEM32 There are a few DLLs whitelisted for protection for this, but drive-by downloads are a real attack vector. Also in the past, exploitable bugs in the thumbnailer if you browse to your Downloads directory (e.g. CVE-2017-11421 and others on Linux).
- marcosdumay 8y agoOpening documents is still dangerous, even if there is no option to ask for installations. Alert on exe is not nearly enough. Almost any file type is dangerous on Windows, and there is a long list for unixes. Making it possible for users to open a document without knowing what they are doing first is a huge vulnerability. That said, starting the download and immediately getting it out of the user's face, requiring interaction to open them is a very good solution. It leads to some problems on Windows, but then, what doesn't?
- captn3m0 8y agoSO it _isn't_ a bug after all. I've been perplexed by this behavior for quite some time.
- Sylos 8y agoThat delay should always be there, even when the window regains focus after being out of focus. You just usually don't notice it, because it's usually already done until you have your mouse on the button.