2 ms·
> The real question here is why is facebook embedding an untrusted widget. 1. That's not really the question, at all. The attack works fine w/o flash. Flash ju
by lbrandy 15y ago
> The real question here is why is facebook embedding an untrusted widget.
1. That's not really the question, at all. The attack works fine w/o flash. Flash just helps reduce friction. I'm pretty certain we've seen versions of the attack that don't use flash.
2. Given #1, it doesn't solve the problem, and it creates a new one. See the other response you received.
- rsoto 15y agoI'm not sure it might work without flash, there's no way to copy and paste, at least aside from IE[1]. What I'm arguing is the fact that the widget is embedded. Without it, at least one crucial step will be added (switch back to the previous tab), making the scam way less effective. 1: http://stackoverflow.com/questions/400212/how-to-copy-to-clipboard-in-javascript http://stackoverflow.com/questions/400212/how-to-copy-to-cli... (yeah, it's kinda old, but just check google docs--even in chrome, there's no way to copy something with the menu)
- mkjones 15y agoWe've seen the same attack on a 3rd party site that pops up a facebook window that's minimized such that all you can see is the address bar, and has you paste into there. Perhaps a lower conversion rate, but still effective.