12 ms·
Websites can change content inside a selection
- ArchReaper 7y agoWhy is this being posted? This "issue" has existed for a long, long time, and it is not specific to any single browser.
- netsharc 7y agoThe bug poster is a well known German tech blogger (blog.fefe.de , in German), so maybe that's why it's gained traction. He also whined on his blog that saying "it's what expected abd that's how it works on every browser" is bullshit, Firefox was the 1st browser that e.g. implemented popup blocker, which obviously breaks the "expected" functionality of window.open; or blocking 3rd party cookie also isn't according to the spec of how cookies work.
- carapace 7y ago"Ten Thousand" https://xkcd.com/1053/ https://xkcd.com/1053/ QUOTE I try not to make fun of people for admitting they don't know things. Because for each thing "everyone knows by the time they're adults, every day there are, on average, 10,000 people in the US hearing about it for the first time. Fraction who have heard of it at birth = 0% Fraction who have heard of it by 30 ~= 100% US birth rate ~= 4,000,000 year Number hearing about it for the first time ~= 10,000 day If I make fun of people, I train them not to tell me when they have those moments. And I miss out on the fun. Person #1, about to have a messy fun time: "Diet coke and mentos thing"? What's that? Person #2, in a delightfully pro-knowledge mood: Oh man! come on, we're going to the grocery store. Person #1: Why? Person #2: You're one of today's lucky 10,000. {{Title text: Saying 'what kind of an idiot doesn't know about the Yellowstone supervolcano' is so much more boring than telling someone about the Yellowstone supervolcano for the first time.}}
- namanaggarwal 7y agoNot important though but the reporter says that they used ctrl+v to copy. Is that right or a typo ?
- grenoire 7y agoLikely a typo.
- asah 7y agoA slightly more nuanced proposal: 1. Detect the first time a site (domain? URL?) attempts to copy something that's not visible. Algorithm TBD but we can start by warning too frequently. 2. Ask the user if this is a trusted site and deny, allow once, allow always. Users presumably select allow-always for apps like Google sheets. 3. (advanced) detect if enough people over long enough time select allow-always and then allow users to go with the herd. I'm talking 10+mm users not 10k, i.e. hard to cheat. 4. (Advanced) option to see what's in the proposed copy buffer. (Obviously this all assumes that publishing sites have web security measures in place e.g. no raw HTML...)
- ArchReaper 7y ago1. As mentioned in the OP, there are numerous ways to add content to a copy event, and 'not visible' is not a 'real thing' - see discussion in the OP 2. What are we asking the user? Permission to copy from the website? 3. So we are adding a new 'permission' that users must accept to... copy from the website? And that trustworthiness is based on how many other people click 'allow' on a permissions popup? 4. You mean displaying what you just copied to the user, on copy? So the browser would give you a popup with the content of what you copied every time you copy anything? I'm failing to see how any of your proposals solve the problems mentioned and discussed in the OP.
- nine_k 7y ago(2) A permission to copy something not rendered in the selection. (4) To show a dialog showing the actual copied content if the content does not match the rendered visible content of the selection.
- ArchReaper 7y agoBoth of your answers assume there is a simple and easy way to identify what is "visible on screen" - which if you read through the OP, you will understand that is not an achievable concept.
- 7y ago
- WA 7y agoThis has been a "bug" for a long time with exactly the same behavior that is described here. Copy&paste from a news article or a blog and have something like "read more at <URL>" inserted. It's also not Firefox-specific. Same behavior happens in Safari and Chrome. But yeah, it makes total sense to point this out that hijacking the clipboard is probably not a good idea and this might be a security issue.
- osamagirl69 7y agoHasn't this been the expected behavior since the dawn of the web 2.0? Next he is going to complain that websites can have a hyperlink that says example.com but points to badexample.com! And worse yet, they can use js to hide their tracks! (ie, google search click redirects)
- rkangel 7y agoI think that protecting against this sort of thing would be helpful: identify hyperlink text that looks like a URL and compare it with the actual link. If they differ, pop up a warning.
- pavel_lishin 7y ago> Hasn't this been the expected behavior since the dawn of the web 2.0? Expected for cheese-brained marketers who love to slap garbage into my selections. Certainly not expected when I'm trying to discuss an article in slack and comment on excerpts.
- matheusmoreira 7y agoNo, this is not the expected behavior. When people copy a selection, they intend to paste it somewhere else. They expect to paste exactly what they copied, no more and no less. Whether they trust a website or not should not even be a factor. People should complain about it. People should complain about clipboard hijacking, hyperlink hijacking and all the other unacceptable breaches of trust that web masters perpetrate. Web developers were given powerful tools and instead of using them responsibly they chose to abuse them. So they shouldn't have access to them anymore. These issues need to be fixed client side just like ads were. We need to remind these people who owns the machine.
- IvanK_net 7y agoI am always shocked, that instead of writing the authors of a website to change it, they write to authors of a browser to prevent it. I think each website provides you a content under a certain conditions, and the browser is not here to let you "steal" every content while absolutely ignoring the conditions.
- cameronbrown 7y agoA browser is a user agent that behaves in your favour.
- inetknght 7y agoYou should remind Google's Chrome teams of that.
- loeg 7y ago> I am always shocked, that instead of writing the authors of a website to change it, they write to authors of a browser to prevent it. If it's fixed once in the browser, the solution is universal. Contacting every single website that does this (3+ orders of magnitude more than the number of browsers) is vastly higher effort and unlikely to be 100% successful (or even 50%). And anyway, it's reasonable to fix this permissions issue in the user tool, rather than on the end of the publisher, because the user tool has incentives more in line with users. E.g., for some reason, browsers today block pop-up ads, although once they were extremely popular with publishers. Do you think asking publishers with pop-up ads to just stop that practice would have worked? > I think each website provides you a content under a certain conditions, and the browser is not here to let you "steal" every content while absolutely ignoring the conditions. Pulling single sentence quotes, such as "I think each website provides you a content under a certain conditions, and the browser is not here to let you 'steal' every content while absolutely ignoring the conditions," is very much fair use, not theft.
- IvanK_net 7y agoI used many programs, called "trials", which stopped working after 30 days. So it does not let me use it, while the program itself is on my hard drive, with all resources necessary to run that program. But the computer belongs to me, and the content of a hard drive too. And the OS should do what I want it to do. Should I report it as a bug to the creators of my OS? If it's fixed once in the OS, the solution is universal. So that since I downloaded a program to my computer, the OS should make it run every time.
- codezero 7y agoAs someone who spent quite a while understanding the differences between innerText and textContent between different browsers and browser versions, I completely empathize with the POV that it's not just as simple as not letting someone copy what isn't "visible." It's really hard to define visibility of text in a simple straightforward way.
- skibz 7y agoOne of the people active in the thread concludes that: > The right approach if you're worried about these vectors is: never paste things off internet sites you don't trust directly into your terminal. I'd like to add that disabling JavaScript also seems like a sensible option, unless that prevents the site from rendering, of course.
- vbrandl 7y agoDisabling JS doesn't help in this case. This post shows that it is possible to put unwanted text in your c&p buffer without using JS: http://thejh.net/misc/website-terminal-copy-paste http://thejh.net/misc/website-terminal-copy-paste
- inetknght 7y agoLeading that page in Firefox reader mode seems harmless enough...
- danShumway 7y agoRemembering to click a button that strips the fonts/CSS out every page I read seems a lot harder to me than remembering to always paste into a blank document before my terminal. Reader mode isn't even available for every site. That being said, yes, stripping CSS, fonts, and Javascript would fix the issue.
- jwilk 7y agoYou would also have to disable images, because they could hide text in the alt attribute. (The reader mode doesn't to it for you.)
- Mathnerd314 7y agoThere are some extensions that help, e.g. https://github.com/aaronraimist/DontFuckWithPaste https://github.com/aaronraimist/DontFuckWithPaste. It just allows you to paste, IIRC, not copy, but if someone was really annoyed I guess they could make one for copying. And NoScript had some clickjacking protection, but it hasn't been ported to the WebExtension yet. Typically though these are done with third-party scripts and just blocking the script is sufficient. In this case it isn't so uBlock has a rule: https://www.reddit.com/r/uBlockOrigin/comments/7l54xr/metro_copyjacking_filter/ https://www.reddit.com/r/uBlockOrigin/comments/7l54xr/metro_...
- rhn_mk1 7y agoI find the reasons not to mitigate this in any way short-sighted. Disabling the copying of invisible text will not mitigate all the instances. Disabling the modification via clipboard events won't either. Nor will disabling the ability to see user's selection. But each of them would cut off a lot of offenders already (defense in depth-like), and each change in this direction would give credibility to the idea that the expected behaviour is to copy what's visible. With all of them implemented, it would become politically much more palatable to plug the last holes and let copy-paste behave 100% as users expect.
- ArchReaper 7y agoI think your suggestion would actually make things worse, because it would cause more people to have a false sense of security when copying from a web browser, which is exactly the problem in the first place. The issue is not that the clipboard can be modified. The issue is that users expect a clean copy when they copy from a website. There are many valid uses for this, and there is not a strong enough argument that this presents a real security issue that would necessitate disabling such a widely-used feature.
- rhn_mk1 7y agoI don't think security is the only factor here. Security is only achieved when 100% of the holes are plugged, which is indeed not achievable outright. But what is achievable immediately is being closer to user's expectations of what will be pasted in general, and a step-by-step approach gives benefits in this regard at every step, without making false promises.
- ArchReaper 7y agoOk. So you're editing a sheet on google docs, you highlight part of it to copy into another doc. You hit ctrl+c. What happens? Do we not let Google modify what you just copied to inject the actual rich-text version of what you highlighted, as opposed to the presentation-formatted version you're seeing as a user in the editor UI? What can actually be done if we allow the 'good actors' to continue working as needed?
- mikl 7y agoThis is one of those cases where useful features for web applications (ie. custom copy & paste logic) enables dark UI patterns for the web in general. Neigh impossible to solve without breaking existing apps.
- jawns 7y agoIf there really are technical reasons not to change this behavior, then shaming sites that employ it to do bad things seems like a next-best solution. Perhaps a browser extension that maintains a list of offenders and alerts the user that the site injects bad things (including marketing and promotional stuff) into copied text?
- banger180 7y agoAn alert that you did not copy what you think you copied would not be out of place in my opinion.
- netsharc 7y agoAn OS window that flashes to show you what you just put in the clipboard would make life easier. Or a keyboard shortcut to show that content. Besides, it seems like the clipboard could use a redesign, the OS default has always been a stack of 1, unless you install a 3rd party tool to manage it.
- InsomniacL 7y ago1) Remember the selection when the selection is made, if content changes ignore until a re-selection is made or un-select when it changes. 2) for hidden content, when selected display a permission box 2.1) permission box states, "hidden content was selected but Chrome removed it, to allow hidden content to be selected for this website click allow " [Allow] [Ignore] obviously it needs finessing but it seems possible?
- vezycash 7y agoOff topic: I've been wanting a: 'Exclude on this site,' 'Run on this site only' option for Firefox addons. A site Whitelist / Blacklist menu for all Firefox addons. It should be accessible from the toolbar, so I can click to restrict / allow the current domain without needing to type (that's for the extension details page). This will be massive privacy help.
- greggman2 7y agochanging this behavior will break many sites. slack, discourse, Gmail chat/Hangouts , Facebook messenger, and I'm guessing discord etc. Most chat sites seem to want their own emoji. Gmail replaces emoji with Google's. Discourse claims to do it to make it consistent across devices and they got angry when I asked for an option to disable the conversion and just leave things plain text. In order for all of these to work they have to let you select your chat messages with their embedded images and then convert that back to utf8 if you copy
- pavel_lishin 7y ago> changing this behavior will break many sites. slack, discourse, Gmail chat/Hangouts , Facebook messenger, and I'm guessing discord etc. How will it break any of those sites? If you mean that it won't copy-and-paste formatting, which is encoded in a mark-down like syntax, then that's true - but most of the time when I copy something on a website, the formatting there rarely makes it through to another application (like any of the ones you mentioned) anyway, and most of the time when it _does_ survive the journey, I silently curse and try to remember what the "paste without formatting" hotkey is.
- greggman2 7y agosince HN doesn't allow emoji I can't post an example. without this feature what you copy in slack would be text <img src="happy.png"> text instead of text (@) text where (@) is actual utf8 emoji same for vscode/Monaco where the editor adds a clickable color box for css colors.
- pavel_lishin 7y agoIt'd be nice if browsers would copy an image's alt-attribute if you tried to copy some text that included an image; that would solve the problem. In any case, I would gladly give up the ability to copy-and-paste an emoji if it meant never again seeing a long line trying to link me to some website just because I had the audacity to copy three words from a news article.
- 7y ago
- hamandcheese 7y agoThe people most likely to be actually harmed by this are developers, right (i.e. pasting in to a terminal)? And shouldn’t we of all people understand that there isn’t much practical difference between opening a shady website, and running a shady executable binary? And if pasting straight into your terminal then there literally is no difference whatsoever. Aside from shady websites, the other main attack vector would be, e.g., a XSS vulnerability on Stack Overflow. And browser vendors do seem to take XSS very seriously, and there are a number of ways to mitigate those. Scummy news site injecting social links in to copied text? That to me sounds like a people problem, not a software problem.
- pjc50 7y ago> And shouldn’t we of all people understand that there isn’t much practical difference between opening a shady website, and running a shady executable binary? But there is a big difference. This is almost the entire point of a browser, a secure way of viewing data from outside our control?
- phn 7y agoIt is still vastly different to paste a command you can inspect visually when copying than an unknown command injected imperceptibly.
- shujito 7y agoI'd disable javascript on the offending website (not web apps, but blogs, news sites, or the likes) for anything JS related that causes annoyances, like popups or unsolicited modals or alerts.
- Someone1234 7y agoThis can be done entirely with CSS or even HTML. Disabling JS only mitigates this, it isn't a solution.
- jakeogh 7y agoHow can a page modify the selection without JS?
- danShumway 7y agoHow exactly would you block this behavior without getting rid of a substantial portion of web functionality, even around simple document styling? It's not a Javascript problem. To make it impossible, we'd need to get rid of invisible spans. Text overflow can't be hidden. This means you can't display extra text to screen readers, since that's invisible text. Also, non-system fonts are right out, because they can contain invisible characters, or even be remapped so that the wrong characters display. The 'solutions' I'm seeing proposed on this issue are hacks. If this is a real problem, the real answer is to just make the clipboard visible when you copy, preferably on an OS level (since literally every format/platform that allows bundling custom fonts is vulnerable to this, including PDFs). Prefer security solutions that are simple and universally understandable, rather than solutions that rely on adding a bunch of code to plug part of a hole. Doing real-time analysis to figure out whether text is visible doesn't fix the whole problem, and is highly error prone. I think Mozilla is right to reject this. If you're coming up with hacks about per-domain character recognition that will end up behind some kind of permission prompt that users will click through without reading anyway... that's a sign you haven't thought hard enough about what the problem is. When something is written to the clipboard, just bring up a notification on-screen and show the user what they copied, and give them the option to inspect/edit it in more detail. The best thing is that's an OS-level mitigation, and not another weird, buggy implementation detail that makes it harder to build or inspect a web browser.
- tobr 7y agoThere’s a lot of steps that are failing to produce this problem: - The browser could do a better job of making sure a text selection only includes the expected content (this is not just a security issue - I often find that text copied from websites include unexpected words or whitespace). - The browser could do a better job showing you what it is putting on your clipboard. For example, they could briefly overlay the text they copy on the selection, in a way that would be virtually unnoticeable when you copied the expected text, but reveals the difference if the content somehow changed. - The system could do a better job showing users what the clipboard contains. The fact that clipboards are completely invisible in most OSes is kind of weird, and also has privacy implications, for example if you copy something sensitive on a public machine and forget to clear it. - The system could implement a way to flag clipboard items as “untrusted”, and require apps to implement adequate checks if you paste something that can have security implications. - When you paste into a terminal, it should probably give you a chance to see what you’re pasting before it tries to execute. After all, this is the place where the actual security problem happens.
- psykus 7y agoA grantable permission would be nice. "This site would like to modify your clipboard"
- Sohcahtoa82 7y agoAs mentioned in many other comments, both here and in the link, sites don't need to modify your clipboard to exploit this behavior. They can insert invisible text inside the highlighted area when you select text, before you've even hit Copy, and this hidden text will be copied.
- deleted 7y ago[deleted]
- lilyball 7y ago> Note that this is a horrible security issue. The newlines cause the text to be immediately executed if I pasted it into a command line window. Modern terminals & shells guard against this. Modern *nix terminals emit special "paste bracketing" codes around the pasted text, which the shell can use to turn off handling of newline (such that you just get a multiline input instead of executing text). I don't know about Windows but I would hope Windows terminals have similar capabilities.
- ByThyGrace 7y agoHmm I'm concerned that zsh doesn't seem to do this by default.
- lilyball 7y ago/bin/zsh (version 5.3) in Terminal.app on macOS 10.14.6 does.
- _bxg1 7y agoThe challenge around issues like this, is that the informal separation between "trusted" and "untrusted" software used to be formalized (by coincidence) as a technical distinction: software you installed to your computer could do whatever it wanted, but you put more thought into whether or not to use it in the first place than you do when you click a link. Now that those cases are combined into a single technical platform, it's difficult to tease them back apart when it comes to level of trust.
- scarygliders 7y agoOkay, I've read all the responses so far at time of writing. Lots of technical solutions which would break the browser/site/web/whatever. What I haven't seen is; Why not, on highlighting text to copy, a small window pops up in one of the corners of the browser, and whatever text would be copied to the clipboard, is instead bunged into this window? A sort of intermediate step as it were. Then if you're satisfied that the content is what you want, hit some 'really copy to clipboard' button. The window goes away, the text is copied to clipboard. A built-in text window. Because most people who use browsers aren;t going to go to the bother of copying and pasting into a text editor (Notepad, Kwrite, whatever) to vet the contents before pasting it wherever. So make the intermediate step mandatory.
- atoav 7y agoOr just display the copied text. If it isn’t the thing you want, don’t paste it or paste it into a text editor to edit it.
- chatmasta 7y agoI would love this. Similarly, I often use the URL bar as a sort of pivot point before pasting some bash command into my shell. It would be nice to have some kind of intermediate scratch pad that is a temporary-unless-touched kind of element, like what happens when you take a screenshot on macOS.
- DrAwdeOccarim 7y agoSame! I always wondered if I was the only one. It's a great way to sanitize text, especially when pasting into Powerpoint or Excel. Especially Excel because once you paste something, that formatting does not go away with Ctrl-Z (relevant comic https://i.imgur.com/pwXryVe.png https://i.imgur.com/pwXryVe.png)
- wasdfff 7y agoOnly don't make them dissapear after 3 seconds...
- roca 7y ago
- uptown 7y agoWait till people find out what Facebook does with the device clipboard.
- shmerl 7y agoWhen such fooling around happens, you can select, then do "view selection source", then when source opens, already copy with Ctrl+C.
- adrr 7y agoAttacking shell seems to be an exploit that could maybe affect 1 out 50 people. Attack the url bar with "javascript:" and you can have XSS attack on any site.
- staeke2 7y agoI think a sensible ”solution” might be for OS vendors (usually not that different from browser vendors) to continuously monitor the clipboard just like anti-virus software is monitoring the file system for viruses. And block access (or condition it with hard warning modal) on pasting flagged text. Possibly allow pasting to same site without check.
- btschaegg 7y agoI'd just like to point out that I find the reflex of "I don't like the comments here, so I lock the bug report down" rather misfortunate. On the same note, I like to see how the discussions here look like a good distributed brainstorming session instead (ignoring a couple of naysayers).
- boomlinde 7y agoI am glad to see this raised as a bug, even if the fix would be a huge breaking change. It highlights one of many ways that growth of complexity and API surface of the browser has become a serious security issue. Maybe merging the concepts of a hypertext document layout system and an application platform wasn't a good idea.