5 ms·
This isn't new, and it's not as simple as not letting the browser change the URL during the click event. This swapping of addresses is more complicated that it
by timothya 14y ago
This isn't new, and it's not as simple as not letting the browser change the URL during the click event. This swapping of addresses is more complicated that it even needs to be, all we need is:
<a href="http://google.com" id="link">Google</a>
and some JavaScript running like this:
document.querySelector("#link").addEventListener('click', function(e) {
e.preventDefault();
document.location = 'http://evil.com';
}, false);
And this is a valid use case - perhaps we're in a web app and if the user clicks the link, we want to perform an AJAX call for the data instead of the normal link action - unless they're opening the link in a new tab, in which case it should load as usual (from the URL given in the link). So this isn't really a easily fixable problem.
- jarrett 14y agoAgreed. The ability to do something other than what the href implies is a small part of JavaScript's bigger purpose: To extend the capabilities of web pages beyond the basic functionality of a browser. It's what makes the browser more than just a dumb document reader, and it's a big part of what makes the web attractive as a platform for app development. We shouldn't chip away at it. Rather than crippling JavaScript, we should focus on implementing a different security principle: Merely visiting a web page should never be dangerous or harmful. This has always been a goal of browser developers. Browsers run in a sandbox for this reason. Although they will execute arbitrary, untrusted code (i.e. JavaScript), by design that code has no access to your hard drive, other web pages you visit, etc.. Were this principle implemented perfectly, the OP's concerns would mostly be alleviated. Sure, some people will still download and run malware EXEs, or enter their private data on a phishing site. But those who do will probably not benefit much from hovering over a URL anyway. If you don't know better than to hand the keys to the castle to random web pages, you probably don't know how to spot a suspicious URL.
- bjourne 14y agoAs a Linux user, malicious exe-files doesnt concern me much, but random joksters trying to get me to click on goatse-links does. It especially sucks when you're at work and you thought it was a link to a page describing matrix multiplication. I think that a modern browser should protect you against that. After all, my economic loss is likely to be larger if my boss sees me staring at a bleeding anus than if I catch a malware infection. Just like browser these days detect malware sites they should also detect shock sites.
- dllthomas 14y agoAs a Linux user I am more worried about malicious elfs and dwarfs than malicious exes. Seriously, though; while Linux seems to typically be less of a target, and thus a malicious executable is less likely, the level of security that things like running as a non-root user buy me aren't that huge on a desktop machine. Most of the interesting things are things that my non-root user can read and write, by necessity and design. With a proper SELinux setup, this might change a bit, but that's not "simply" a matter of running Linux.
- jarrett 14y agoGranted, but does the hover URL do much to protect you from offensive content? It sounds like you're a technically sophisticated person who's worried about being pranked by other technically sophisticated people. Therefore, I assume they are capable of using a URL shortener or a misleading file name to trick you. Seeing the URL ahead of time doesn't help in these situations, unless you simply refuse to click on links whose destinations you can't identify with certainty.
- Karunamon 14y agoThe main shock sites are all clones of each other, so if you filter out hello.jpg and whatever the .js scripts of a typical Last Measure instance are called, you've killed most of them :)
- cmccabe 14y agoWho cares if your boss sees you click on a goatse link? He's probably been pranked before; he knows how it works. Are you afraid that he thinks you're a goatse afficionado? If so, you've got bigger, wider problems.
- bjourne 14y agoActually my boss has goatse man beaten when it comes to being a huge asshole. But the picture would just make him jealous.
- romaniv 14y agoLinking is the foundation of the Web. The fact that you can no longer build a website without subverting even the most basic of browser functions via custom code is a sign that something somewhere is broken. The sad part is that a lot of web developers cannot even imagine a different architecture that wouldn't have these problems. The discussions are mostly about more of the same. More permissions. More low-level APIs.
- jarrett 14y agoWhile linking is the foundation of the web, I would say that the web has grown far beyond its foundations. Nowadays, web technologies are not just a way to share a set of linked documents. They're a platform for app development. The browser is starting to resemble a miniature operating system. Thus the demands for "more permissions, more low-level APIs." You may feel philosophically that this is the wrong direction for the web, but many folks (myself included) are excited about it.
- deleted 14y ago[deleted]
- romaniv 14y agoYou haven't posted any information I wasn't aware beforehand. Yes, things change, the way we use the web changes too. That's exactly the problem. Instead of just "going beyond" foundation, it would be much more sensible approach to expand it, i.e. change what's possible with core HTML/HTTP.
- chii 14y ago> Linking is the foundation of the Web. The fact that you can no longer build a website without subverting even the most basic of browser functions ... i don't believe that's a fair assessment. A bit of javascript that "subverts" the href of an anchor tag to perform some _other_ task other than loading the page at that href, is functionally indistinguishable from having that same task performed _after_ the said href page is loaded. Sure, the technical side of this is indeed very different. One is an ajax call plus some DOM manipulation. The other is loading a different page, in an entirely different execution context. But to an end user, a link is something that you click on, and somethign happens. What happens is also quite predictable (provided the site/web app is designed with usability in mind). I dont think somethign is fundamentally broken at all.
- dutchbrit 14y agoIs it just me, or can't you just leave the ", false" part away? And to the people that use "return false;" in their JS to prevent default actions from happening, i.e. a click on a link or submitting a form, don't, stop using it, e.preventDefault(); is the way to go, as posted by timothya.
- hobonumber1 14y agoYes, you can. The boolean just denotes whether the event is listened for during the event capture phase or the event bubbling phase. Makes no difference in this case.
- pharrington 14y agoAs of FF6, Firefox defaults to listening during the bubbling phase; before that though, the parameter was required in FF.
- artursapek 14y agoI work for a startup that uses an HTML5 music player on its site, and we use this trick to load all of our pages with AJAX so the player doesn't get interrupted by refreshes.
- jervisfm 14y agoWhen you say refresh, are referring to a full browser reload ?
- artursapek 14y agoYes.
- jervisfm 14y agoInteresting. Would you mind sharing the name of your startup? I'd love to check it out.
- pud 14y agoA good example of this being used is Facebook. Click a picture in your newsfeed, get a popup. Even though the hover shows a URL. Command-click it to open in new tab, as expected.
- SquareWheel 14y agoYou can even refresh the page when you have a popup to get the URL page.