Copy & paste some text from this article. Notice anything funny?
techvibes.com
techvibes.com
What if I don’t want this behavior? We are currently working on a global opt out for users who would rather not have Tynt monitor their actions when they visit a site. In the interim you can opt out on a site by site basis (i.e. the opt out for the SF Gate is here: http://www.sfgate.com/chronicle/faq.shtml#faq1.5#ixzz0bxLIAb...
More info on Tynt is available in our FAQs here: http://www1.tynt.com/faq-technical-topics#ixzz0bxGzIgPZ
Tynt (http://www.tynt.com/) was the "culprit" in that case and looks so here.
I haven't pored through their code, but I already know that my initial suspicion (binding CTRL+C with JS) isn't accurate, as right-clicking -> copy also appends it.
It's interesting at the very least, and I don't know how they're doing it. Anybody have an idea?
In this case, the site works fine without the clipboard-hacking JavaScript running, so it just stays disabled and the OP doesn't get random data from a website written to his clipboard. If he wants that functionality, though, it's one click away.
What's quaint is trusting websites to run arbitrary code on your machine, as your regular user.
Edit: To put it better perhaps, are you worried that they can execute arbitrary code on your CPU as your user on your OS? Or are you just worried that they might paste a link into your clipboard?
(No, any experience you may have shutting it off entirely does not count. NoScript is smarter than that and does not work that way.)
I do use it. It is two to three times less common for me to be surprised by secret JavaScript functionality on a site than for me to be surprised going into the comment sections of HN or reddit and seeing people complain about some bad thing that I didn't experience. That is a serious estimate. And the thing I missed out on is rarely important. (The most common exception to that is when you need JS to go to the next page. Frequently I decide I don't care enough anyhow.)
Malicious Javascript can do some weird and nasty things, but mostly I run it because it makes the web less annoying. That it tends to prevent exploits from working is just gravy. (Exploits often fail against a 64 bit gentoo-based Firefox anyhow, but still, careful is good.)
Doesn't NoScript / using no .js break many web 2.0 ajax sites?
For example, on the Hacker News main page, i allow js from ycombinator.com and forbid js from co2stats.com
Carbon preacher hypocrites! They probably heat their homes with coal-fired Franklin stoves, too.
Personally, I block Google Analytics, because fuck Google tracking me on every site I go to.
http://www.jwz.org/doc/x-cut-and-paste.html
is an interesting article about the different avenues that text can take under X.
Possibilities are already popping into my head. This could in the future make citations and references really easy, for starters! Tick an option, or copy with a certain key set, and bam you have the quote and an IEEE-style citations entry in the paste buffer.
Now it makes me double check every time I copy and paste. At first thought this might not seem too bad but modifying basic user behavior should be frowned upon.
Although, these comments did serve as a remindeer for me to give NoScript a chance again.
It's very very annoying.
No?
(Thanks, http://www.ghostery.com/ !)
FYI, works in Chrome/Mac for me.