5 ms·
> I can't think of a single time when I want a site to react to my attempt to copy text off if it. I think it is needed for some complex web app to handle copy
by maple3142 7y ago
> I can't think of a single time when I want a site to react to my attempt to copy text off if it.
I think it is needed for some complex web app to handle copying non-text content. Such as images in wysiwyg editor, Google Sheets/Slides...
- na85 7y agoSo trade those apps not working for immunity from JavaScript clipboard hijacking? I'd be 110% fine with that trade and nothing of value to me would be lost. Is it possible in Firefox? Anyone know?
- bzbarsky 7y agoIt's possible. See https://news.ycombinator.com/item?id=22356697 https://news.ycombinator.com/item?id=22356697
- maple3142 7y agoIf you really don't mind it will break some websites, then you really can disable it in Firefox. https://news.ycombinator.com/item?id=22352929 https://news.ycombinator.com/item?id=22352929
- epse 7y agoMind you that this breaks a LOT of things. Even stupid stuff like any textbox on Facebook will be broken.
- TuringTest 7y agoThat sounds like a net positive, allowing you to tell apart proper websites from privacy nightmares :-P
- dwaltrip 7y agoMillions of people use applications with these kinds of features. A few more examples: the Scratch educational programming tool, website builders such as Webflow, diagram editors, image editors, etc. The list goes on and on. The browser is no longer just a document viewer... That ship has sailed, and overall it is a good thing. We can mitigate the risk of clipboard hijacking without burning down the house. By the way, I would guess that this is a minor risk in the grand scheme of things, as it seems that the worst risks are for technical individuals people copying programmatic commands (e.g. software engineers). For others, it is a real yet minor annoyance. Perhaps there could be an opt-in setting for allowing a site to modify the default content that is copied from a selection?
- Polylactic_acid 7y agoA decent workaround would be to have 2 clipboards. The regular untouched one and the special one. Then when you paste, apps which only take plain text will grab the regular one and apps which accept formatted copying will grab the special clipboard but also provide a "paste as plain text" so the user gets what they want every time.
- ken 7y agoIt sounds like you're conflating two orthogonal concepts: multiple named clipboard locations, and multiple data types on one clipboard. Both already exist, and are how clipboards on major platforms have worked for decades. The Javascript interface isn't aware of these distinctions, though I'm not sure I want it to. Web apps like this that abuse one plain text clipboard will abuse multiple richly typed clipboards, too.
- Freak_NL 7y agoYou don't have two clipboards? It's been the default on *nix OSes for ages. Ctrl+C/Ctrl+V works, but there is also the select/middle-mouse clipboard. Great for crap websites that hijack one.
- oneeyedpigeon 7y agoThose apps are surely already doing that - I don't think there's a way of copying arbitrary structured data to the web's abstraction of the clipboard. It doesn't address the problem the op raised - that browsers can sniff the copy event.
- dredmorbius 7y agoThere are already (at least) two clipboards in many platforms. X11/Xorg has the primary and secondary selections. MacOS has ... whatever it's got. A key problem with this is that the feature is covert, latent, poorly discoverable, and causes unexpected behaviours. Even presumably advanced users (myself, you, other HN readers) are poorly aware of this. Imagine trying to explain to your nontechnical Aunt Tilly or Uncle Kamlesh about these "different clipboards which treat what you've copied differently and access through this funky interface"?
- triceratops 7y agoMaybe let users grant clipboard permissions, as they currently do for location, microphone, webcam or notifications?