3 ms·
Agreed that it's unfortunate that flash can write to your clipboard. The only place I've seen that used legitimately is on bit.ly so they can copy the shortene
by mkjones 15y ago
Agreed that it's unfortunate that flash can write to your clipboard. The only place I've seen that used legitimately is on bit.ly so they can copy the shortened link to your clipboard. Even there, I usually end up confused about what happened and manually copy it anyway.
As far as things we could do at Facebook, we definitely work to detect wall spamming. We end up blocking this kind of spam a lot the time, but there's always room for improvement.
- codejoust 15y agoHow about running the facebook javascript in a sandbox? Such as proxying the document.createElement and document.getElements* methods for the initial script while breaking it for everything else?
- mkjones 15y agoThat's a good idea, and we actually thought about that. But assuming we need those APIs, what's to keep them from calling our wrappers around them? Put another way, how do we determine if the caller of some of our js is malicious or is us?
- jQueryIsAwesome 15y agoIt just needs to be non-predictable. Give the wrapper object and ALL his methods a random name for every session.