3 ms·
> Windows could certainly tighten the security by optionally only allowing foreground/focused apps to access, or notifying the user when apps read the clipboard
by dethos 5y ago
> Windows could certainly tighten the security by optionally only allowing foreground/focused apps to access, or notifying the user when apps read the clipboard without being in focus or sent any input first.
Author here, yes, this is indeed the point of the article. Desktop operating systems could/should have implemented such a feature a long time ago, it is clearly a security "blind spot" at the moment.
- IshKebab 5y agoNot really though. It makes sense for mobile OSes because they have proper isolation of apps, but desktop OSes don't have that. Apps can pretty much do anything. What's the point of copy notification if apps can just read all your emails and steal all your files anyway. Android and iOS both have this feature already. That's the best we can do for now.
- dethos 5y ago> What's the point of copy notification if apps can just read all your emails and steal all your files anyway. We are discussing "paste" notifications. Knowing that an "app" is constantly pasting(fetching) the contents of the clipboard seems suspicious behavior and I as a user would like to be made aware of it.
- nitrogen 5y agoDesktop OSes all have some form of optional sandboxing now, so it makes sense to keep chipping away at the edges of the attack surface.
- IshKebab 5y agoDo people use them though? Both Mac and Windows have pretty much tied app sandboxing to 30% app store fees, which means the proposition is "rewrite your app to use incomplete APIs and then you can put it in our store where we'll take a big cut!" Not very appealing. It only works on mobile because there wasn't an existing industry used to 2% fees and unrestricted APIs. Unsurprisingly Microsoft has abandoned app store fees and mandatory sandboxing so their app store has any chance of being used. Not sure about Apple.