3 ms·
I think your suggestion would actually make things worse, because it would cause more people to have a false sense of security when copying from a web browser,
by ArchReaper 7y ago
I think your suggestion would actually make things worse, because it would cause more people to have a false sense of security when copying from a web browser, which is exactly the problem in the first place.
The issue is not that the clipboard can be modified. The issue is that users expect a clean copy when they copy from a website.
There are many valid uses for this, and there is not a strong enough argument that this presents a real security issue that would necessitate disabling such a widely-used feature.
- rhn_mk1 7y agoI don't think security is the only factor here. Security is only achieved when 100% of the holes are plugged, which is indeed not achievable outright. But what is achievable immediately is being closer to user's expectations of what will be pasted in general, and a step-by-step approach gives benefits in this regard at every step, without making false promises.
- ArchReaper 7y agoOk. So you're editing a sheet on google docs, you highlight part of it to copy into another doc. You hit ctrl+c. What happens? Do we not let Google modify what you just copied to inject the actual rich-text version of what you highlighted, as opposed to the presentation-formatted version you're seeing as a user in the editor UI? What can actually be done if we allow the 'good actors' to continue working as needed?
- pavel_lishin 7y agoLet's handle this like we handle things like location tracking, notifications, etc: ask the user. Except I don't think we should ask the user, because everyone will blindly click yes. I think we should disable this by default, and let Google Docs, etc., remind the user via some in-app modal with step-by-step instructions. If someone actually needs this functionality, let them do the work to unlock it for a given website. 99.99999% of the web has no good reason to be modifying a user's clipboard.
- ArchReaper 7y agoI encourage you to read through the OP first on why your suggestion (remove copy-modification entirely) is not reasonable.
- pavel_lishin 7y agoAh: > The metro.co.uk code inserts an off-screen-positioned element with the disclaimer into the selection range, and you could just listen for selectionchange and/or mouse drag and/or keypress events to detect selection changes, and add/remove such an element based on those events. Well, shit.
- roywiggins 7y agoMy favorite scummy thing done to mess with browsers is to insert a noscript meta refresh redirect just to catch anyone who refuses to run the JavaScript adware embedded in their crappy local news website CMS. It must be standard in some local newspaper CMS and I've only ever seen it used on that sort of site. Never underestimate newspaper publishers' CMS vendors' ingenuity.
- weaksauce 7y ago> Do we not let Google modify what you just copied to inject the actual rich-text version of what you highlighted, as opposed to the presentation-formatted version you're seeing as a user in the editor UI? could you not have a two tiered clipboard that is exposed via javascript for the webpage interactions(to solve the copy and paste issue with rich text inside google docs) but have the main paste system be synced with the system clipboard and that restricts the copy and paste to visible text/non-javascript hijackable(stops the manipulation of the clipboard to inject malicious code for terminals or even the annoying injection of "this snippet was copied from example.com/xyz") I haven't thought too hard about the downsides to this or how hard it would be to implement but i'd be curious to see any discussion on some kind of approach like this.
- rhn_mk1 7y agoIdon't know what the "correct" solution for that could be. I can come up with some half-baked ideas, like whitelisting, web-app bifurcation (we have reader mode, why not app mode?), or allowing for some amount of modification if clipboard events are enabled. What's clear to me is that the situation we have now is suboptimal, that coming up with a better solution will take up some time, and that incrementally fixing the current situaton completely will take enough time to find a better solution in the meantime.
- deleted 7y ago[deleted]
- komali2 7y agoIsn't this just a rehash of the "people ride their bicycle more dangerously when they're wearing helmets" argument? The solution is all of the above, and also don't paste stuff into your terminal from the internet.
- deleted 7y ago[deleted]
- uneekname 7y agoI respect and share your goal to educate users about what they should expect from their browser/computer security-wise. As someone with a (healthy?) distrust of the content I copy/paste, and would never run code I copy/pasted without checking it first (one of the examples given in the linked bug report thread), I would still rather my browser only copy the text that I visibly highlighted. It is annoying to edit content out that I have carefully selected.
- ArchReaper 7y ago>I would still rather my browser only copy the text that I visibly highlighted. It is annoying to edit content out that I have carefully selected. Absolutely. But how do we solve that problem and still allow proper usage of it? Removing this feature would break the copy ability of nearly every rich-text-like web-based UI in existence, such as Google Sheets. Personally, this feels more like something for an adblock-like addon.
- NoodleIncident 7y agoThe 10 sites that have a genuine reason to listen to selection events and force you to copy invisible text can ask permission to do so, as suggested in the thread.
- ArchReaper 7y agoThat still does not answer the question of "what are we asking permission for?" Why that is a hard question can be understood by reading through the discussions in the OP.
- Marsymars 7y ago> Removing this feature would break the copy ability of nearly every rich-text-like web-based UI in existence, such as Google Sheets. Skipping over the technical implementation issues, I'd rather copying rich-text-like be relegated to a "Copy Rich Content" context menu action, and the default copy command be plain text only. I very seldom want to copy rich content. I very frequently am copy/pasting content to notepad, selecting it, and then copying it again in order to strip out the rich content I don't want.