5 ms·
That's clever. It was pretty obvious to me, since I run Chrome in presentation mode (no UI elements visible) and Chrome popped up a dialog box telling me about
by AngryParsley 14y ago
That's clever. It was pretty obvious to me, since I run Chrome in presentation mode (no UI elements visible) and Chrome popped up a dialog box telling me about the switch to full-screen mode. Still, I can see how a lot of people could be tricked by this. I can't think of a better solution than extant phishing site blacklists.
Full-screen mode can be useful, but it and other HTML5 features can be used for phishing or to generally annoy users. I'm wondering how soon it will be before someone makes the HTML5-equivalent of ClickToFlash.
- skeletonjelly 14y agoBy presentation mode you mean fullscreen (F11)? I had a quick search and couldn't find anything conclusive. It's an OSX specific thing?
- AngryParsley 14y agoI don't have a Windows machine or VM, but it looks like full-screen mode on Linux is the same as presentation mode on OS X: the UI is completely hidden unless you move the mouse to the top of the screen. In addition to presentation mode, Chrome for OS X has a separate full-screen mode that always shows the tabs and buttons.
- skeletonjelly 14y agoThanks! Looks like Chrome doesn't do this on Windows but it's similar to how Firefox has always done fullscreen.
- FooBarWidget 14y agoIn OS X, "Full screen" triggers the Lion native full screen mechanism. In this mode Chrome is full-screen but you still see the toolbar. "Presentation mode" is more like what "Full screen" did before Lion, or how full screen behaves on other OSes: no toolbar.
- wtallis 14y agoNoScript already inherently blocks this, and even if you allow the domain that provides the script that tries to go full-screen, and allow the full-screen transition, the web page pretending to be a desktop doesn't cover the NoScript toolbar that's still prompting for permissions on the other domains. I suspect the anti-clickjacking measures would kick in if the phishing site tried to incorporate the real site as a base layer. NoScript does not seem to have any features targeted directly at HTML5 fullscreen, though.
- tymekpavel 14y agoI don't think the average user knows what NoScript is.
- nikcub 14y agoThis is why I want to fork Chrome and create a secure and privacy-aware browser. * Take out everything Google-related, including safebrowsing * Rip out Flash and Java * Integrate NoScript * Integrate an alternate html5/canvas based video player * Integrate third-party request blocking * No cookies by default * Strip out all the tracking id's in URLs (eg. Google search results pages, back to just plain old ?s=search+query) * Automatically clear cookies such as the __ut* cookies from analytics * Incognito by default * Introduce a concept of 'installing' trusted sites that would be allowed to run scripts, etc. not too dissimilar to how desktop computing works I have had this idea for over a year now, but haven't gone far in implementing it other than doing a test build of chromium with incognito by default and some default extensions. It came about because my dad and other family members have each had spyware or rootkits installed on their machines. 99.99% of drive-by exploits can be stopped by simply not running IE and switching off Flash and Java. It would be a browser where you don't have to explain everything, just marketed/renown as being a browser focused on privacy and security features for everyday users. When I get a chance, I am contemplating putting a team together and forking this as an open source project. If such a project is of interest to anybody else, get in touch (via email in profile).
- adrinavarro 14y ago