4 ms·
Ohh right, so your plan would be to essentially check for third-party javascript things running on the same page? This would be a really easy "security" measur
by tom-lord 11y ago
Ohh right, so your plan would be to essentially check for third-party javascript things running on the same page?
This would be a really easy "security" measure to circumvent, though - I could literally just delete your monkey patch, for a start!
- aidos 11y agoIt wasn't my idea so, no, that was never my plan :) Though, you do raise a valid point, so let's see how it plays out. setTimeout = function(){...} delete setTimeout // true - you've removed the patch window.setTimeout = function(){...} delete window.setTimeout // true - you've removed the patch window.constructor.prototype.setTimeout = function(){...} delete window.constructor.prototype.setTimeout // false - the patch is still there! I don't know about the hierarchy of the prototype chain up at this level but it seems to work. Maybe there's some other way of getting to the built-in setTimeout so you can create your own version to mask the one I added? EDIT you can embed an iframe and rip the native setTimeout from there.
- zedadex 11y agoreddit stops you from embedding it iirc
- aidos 11y agoI tried that too - you can just use any old page that has CORs headers allowing it.
- towelguy 11y agoThey could listen to the DOMSubtreeModified event in the 10s div.
- aidos 11y agoNice! There are probably clocks all over the place when you start looking around :)