4 ms·
Both of your answers assume there is a simple and easy way to identify what is "visible on screen" - which if you read through the OP, you will understand that
by ArchReaper 7y ago
Both of your answers assume there is a simple and easy way to identify what is "visible on screen" - which if you read through the OP, you will understand that is not an achievable concept.
- nine_k 7y agoWithin a browser, which basically knows where each pixel is rendered? I suspect that for the great majority of practical cases, it is possible. Where a definite answer is too hard to achieve, it's safe to err on the side of "not visible".
- recursive 7y ago> I suspect that for the great majority of practical cases, it is possible. The bad guys aren't going to be using the great majority of practical cases.
- nine_k 7y agoMy idea is that the minority will be false negatives. The key principle of security is to deny all, allow a closed subset. Same here: allow what is obviously clear and has no hidden parts, and ask a confirmation for all the rest, legitimate or not.
- wvenable 7y agoThe browser literally highlights the selection so that seems like a solved problem. I'm in favor of two-tier system where rich applications require permission for enhanced clipboard events but the average site will just copy what is selected without modification.
- ArchReaper 7y ago>The browser literally highlights the selection so that seems like a solved problem. It's nowhere close to a solved problem, and is much more complex than this. Give a read through the comments in the OP for a taste of why.
- nine_k 7y agoI did; it sounded mostly hand-wavy. Maybe there are deep reasons why it's impossible, but they are not well presented in the OP, unfortunately.