Pastejacking
github.com
github.com
Does it really work? Do sites actually get more traffic by hijacking your keyboard's basic functions to insert advertisements? I guess it probably does. :(
But yeah, Demand Media is terrible and their employees are not on my Christmas card list.
Which is a perfectly rational question/argument.
> Expecting people to behave against their own self interest in the short term, for the good of strangers in the long term, will always end in disappointment.
I agree. This is a systemic problem, and appeals to ethics won't work (and the advertisers won't change their metrics because of them) - one needs to attack the economic incentives underlying their current strategies.
uh. That isn't what I was doing - one party's act in self interest can benefit third parties (even if accidentally)... like electing to not set yourself on fire in a crowded Museum of Yarn and Flammables.
> ...attack the economic incentives underlying their current strategies.
That has been going on since the first ad click payment. I'm guessing that the ideal solution is one that would require a scale of economy that is outside the capabilities of the majority of the market participants, and that is why we still have catch the monkey ads.
How is that rational at all? That question is referencing the common practice of blaming rape victims rather than the rapists, by questioning what the victim was wearing.
It doesn't matter what society implies.
Note that I can say that while unequivocally condemning rape and providing zero cover to rapists. I am describing what is, not what I think ought to be.
I don't understand - how is that not victim blaming, and going against your last line? And how exactly do you take precautions against rape, especially when you factor in the fact that the perpetrators are far more likely to be people who wield some kind of authority over the victim, including family members, bosses at work, police and security forces, etc. which is true at least where I come from (West Africa), and leads to chronic under reporting / decisions by families to either blame the victim or sweep the whole thing under the rug. Or am I somehow misunderstanding your meaning?
Disagree. Thats a personal value judgment and an ethical perspective viewing efficient corporations as utilitarian bodies fulfilling the greater good.
I do. That's probably why I won't be running an effective business any time soon. Being nice and not fucking people over doesn't get you far in highly competitive markets.
I strongly second what 'nitrogen wrote[0]. This is very much about ethics.
> Is it ethical for a shop to advertise its products in the shop windows when the people running the shop know that there are higher quality products available in a competitors store?
In my opinion, no. Basically, if you know your product is shit, you are morally obliged to make it better or find something else to sell; lying to people to make them buy your stuff instead of something objectively better is fucking them over for your own gain.
Think about it the next time you find yourself on the receiving end of such businessmen.
That said, most of my peers who are objectively better than me are already employed, and it's up to employers to select from the available pool of employees. My responsibility is to truthfully present my skills during interview.
In hiring analogy, it would be as if I couldn't code at all, but could talk my way through the interviews - and so instead of actually learning to code, I'd earn money by getting employed at companies and trying to extract as many paychecks and benefits as I can and then quitting before they figure out I'm a fraud.
Me investing my time to get a job through pure charisma, without bringing any merit to the table, is like selling products on pure marketing. Pretty dishonest, and also poisons the ecosystem for everyone.
... but a warning sign that an argument is probably too broad, too absolute, too confidently stated, and has ten thousand exceptions that you didn't consider.
> lying to people to make them buy your stuff instead of something objectively better is fucking them over for your own gain
Thanks, this needed to be said. I'm in the same position. I will probably never be able to run a business either because I hold these same views.
This is why we can't have nice things. Because people adopt a FYGM attitude. Because they piss in the pool we all have to swim in.
...all that harm can be removed simply by...
...quitting smoking? Throwing away the prescription pain meds? Giving up junk food?
How about not robbing people of their valuable time and money? How about moving past negative-sum business models where the distributed costs far outweigh the concentrated gains?
That pretty much describes living in the US and even Europe to a degree compared to most of the world.
How deep should morality go? Almost all of us in the US consume an order of magnitude more than most of the world for instance.
(hey it works in the advertising industry. I attack your humanity on multiple levels and then show you garbage that... kind of, almost, but not really restores your humanity. Of course, you really need next months update, or you're just subhuman again! )
Not sure about Mad Men, but HoC doesn't "glorify" its subject. And tons of great art is about "assholes".
The thing is, and this is a very christian message, assholes are people too.
Ethically, self-interest is fine. Failing to help others isn't a huge deal either. It's the part where you're actively and deliberately harming others (by polluting search results - impairing both search engines, as a company, and their users) that we're objecting to.
Demand Media has strong brands. They aren't anonymous/fly by night operators. If they were promising content and not delivering with any sort of regularity they'd lose viewers. They're not doing that though. The content when you click on an ehow or livestrong article is exactly what you'd expect from an ehow or livestrong article. That you find this content undesirable is very much subjective. Plenty of people seem to enjoy it.
http://blog.cleancoder.com/uncle-bob/2015/11/18/TheProgramme...
Oh, darn … /s
Then I realized that the reason I was doing that instead of ctrl-c is all the times that web sites break ctrl-c. I literally have gotten used to highlighting, right-clicking, and clicking copy, for a "clean" copy :) I wasn't even aware I was doing this.
Of course, web sites can hook right-clicks. It would be funny if they threw up a fake context menu matching the default context menu of the browser and operating you're using, but with evil versions of commands :)
I don't disable or modify javascript, so with that addition it would have tricked me.
I will say that the people who generate event hooks in browsers need to pull their heads out of their asses before this kind of thing becomes necessary.
But then, I've seen sites that break highlighting. Either intentionally, or accidentally, thinking people will share their every highlight on Twitter (I am looking at you, Medium).
Most people who use terminals know how to protect themselves, and they can recognize questionable content.
This whole problem shouldn't even exist.
https://msdn.microsoft.com/en-us/library/bb250473(v=vs.85).a...
http://i.stack.imgur.com/jvDUh.png
https://developer.mozilla.org/en-US/docs/Mozilla/Preferences...
But the same quick search shows that it does not appear possible to control this in Chrome. If anyone knows how, please correct me.
What browsers really should have are a standard "Ask & Whitelist" dialog for all of these security critical features[1]. It seems Firefox even used to have this feature, but it and the corresponding addon have long since crumbled to dust[2].
Unfortunately browsers are no longer controlled by hackers who think about all the implications of a feature, but by corporations who think about money, and us hackers have to spend inordinate amounts of time trying to play security whack-a-mole, or be forced to give up and use our browsers like sheep, the way the corporations want us to.
[1] There's many more, including utterly ridiculous stuff such as telling websites the battery charge status of your device (and if your charger is plugged in): https://gist.github.com/haasn/69e19fc2fe0e25f3cff5
[2] http://kb.mozillazine.org/Granting_JavaScript_access_to_the_...
https://bugzilla.mozilla.org/show_bug.cgi?id=38966
They had a pretty useful per-site configuration mechanism that wasn't UI-configurable so someone started to make a UI for it, but then some higher-up decided they should remove the whole thing completely! The screenshots they have there look so awesome:
https://bug38966.bmoattachments.org/attachment.cgi?id=63187
It's ironic that, meanwhile, IE gets this right.
FWIW, the features that this uses have their origins in proprietary IE5 features (maybe 5.5?). Whether this attack works in IE5 I leave as an exercise to someone else.
Note that the tradeoffs are more complex than what one might naïvely assume: people weren't using the feature as it existed in Firefox before because it required explicit user interaction, but doing the same thing through Flash didn't… so everyone just used Flash. In effect, this is a security bug the platform has long had (because, like it or not, de-facto the web platform for the longest time included Flash). Now, should we blindly copy everything Flash can do? Of course not. But if something is making people hold on to Flash, we really should consider the tradeoffs. Are we just gaining theoretical superiority but practical irrelevance (on desktop at least; mobile where Flash is gone is a different story)?
How is this method different?
This method is more sophisticated; it monitors the whole page for copy commands, and has an event listener watching to see when this 'copy' command is executed.
Of course a better solution wouldve been a program which doesnt so easily let you lose data in the first place, but this software was long past that.
If it's intentional, you don't want to pull the data back up (people want a "fresh copy")
If it's not intentional, you do want to pull the data back up.
Though of course you can make something like a "New Copy" button, but then that presents its own challenges.
*insanely large is anything that takes up 75% of whatever computer bottlenecks first at the time of reading this comment(Memory, processor)
All this was introduced to prevent abuse. Apparently it still wasn't enough though...
However, sometimes I want to share a qoute I found online. I don't want a promo for the website inserted into my clipboard. For them, it must be a fine line that realization: user-hostility can be short term profitable but long term fatal.
The problem I see with this scenario is that not everyone is copy-pasting from the browser into a terminal. I for example copy things to my VM's text editor first, then run the command. Other could be copy-pasting to an email for example. In those instances it would be obvious that the site is doing something not so kosher and it would be notices pretty soon I guess, depending on the site's popularit
Try to copy one from this site for example.
http://www.brainyquote.com/quotes/authors/a/albert_einstein....
"Please enable Javascript This site requires Javascript be enabled to provide you the best experience [for us]. Some features [like shoving crap into your clipboard] may not be available with Javascript disabled!"
It's not uncommon to find sites whose definition of "good UX" is exactly the opposite of what I want.
Twitter does this on every single tweeted link. For example copy the link in this tweet: https://twitter.com/twitter/status/727507892283142145
You don't see a https:// on the page, but it gets put on your clipboard because it is actually there with 0 font size. In this case it's actually pointless though because they cut off the end of the url.
It defangs this vulnerability nicely.
echo hacked > hacked.txt; echo -ne '\033[1F\033[2K'
echo innocent --preserve-root
do not remove '/' (default) sudo rm -rf /sys/firmware/efi/efivars/
(no, don't run that at home)While we are on the topic of copying and pasting. If the command downloads a script, make sure you download the script out-of-step via curl first, review its contents, and only then execute it. This avoids sites maliciously changing the script based on the User Agent.
To solve this, browsers should probably disallow modifying the clipboard .
curl -sL http://example.com/install.sh | less -eK && \
curl -sL http://example.com/install.sh | bashOn the Mac, applications downloaded from the Internet are quarantined; they stay that way until you accept a warning message displayed at first launch (even if you wait days to launch it for the first time). The OS helpfully remembers where the file came from, e.g. “This was downloaded from www.notmalware.com on July 6, 2000.”.
If a web browser insists on allowing web-controlled Copy behavior, the resulting pasteboard should be given a big, black TAINTED mark that cannot be cleared without a very explicit action. If I go to another application and try to Paste, the other application should not be able to access the data without clearing the quarantine (e.g. OS provides standard dialog that shows the entire text and web site of origin, free of any white text-coloring or Unicode invisibility tricks).
Edit: Sorry, I didn't read close enough.
"not evil"
without a line break as expected. Chrome and Safari.edit: doesn't seem to have unexpected behavior in terminal either. Am I missing something, or does uBlock default deny the scripts that can do this?
edit 2: console log: Copying text command was unsuccessful. uBlock disabled.
This particular attack doesn't work when not using keyboard to copy (think select to copy (traditional X behavior) or using a context menu), it causes text to unselect after busy loop ends, causes fans in my laptop to start working (because of busy new Date loop), causes cursor to cease changing for a certain period of time, requires me to enable JavaScript, requires support for "copy" command (which isn't universal), and requires the user to press CTRL+C either way (otherwise the webpage won't be able to copy into a clipboard).
I guess you could paste an output after a certain time, but because of hijacking on Ctrl key, nothing can be copied before busy loop ends, and as a result, it doesn't prevent "pasting the command into Notepad" just to ensure it's safe - as either what previously was in pastebin or malicious command will be pasted.
https://xfix.github.io/mystery-zone/command.html (disclaimer: I made this page) doesn't have any of those problems (other than requiring the user to copy text in any way (CTRL+C, text selection, context menu, whatever odd interface do you have)), and it still can break vim (and for that matter, bash, zsh (including zsh with paste protection), fish, and emacs).
It is time to rein in all the things that web browsers are complicit in doing at the request of random web sites. There needs to be a lot more thought put into these “APIs” that sites have access to, and a lot more scrutiny of the data.
This clipboard thing remembers me of the webrtc functionality that enable browsers to scan my network without asking me.
At the same time, it's better than those times when you had flash buttons to copy link. So I think it should be allowed to change clipboard on user's action (can it be detected?). But there certainly shouldn't be an event to change clipboard that is fired after the user copies something (selection copy, keyboard shortcut, browser ui, ..).
As others have already pointed out, an API for interacting with the clipboard is a terrible idea that should be removed from the browser.
However, this particular problem of pasting multi-line strings into the terminal is already a solved problem if you use rxvt-unicode. The standard package includes the perl plugin "confirm-paste"[1][2]. Enable it in ~/.Xresources
URxvt.perl-ext-common: default,confirm-paste
confirm-paste passes single line pastes normally, but asks for a y/n confirmation before sending a multi-line paste to the shell.[1] urxvt-confirm-paste(1)
[2] http://cvs.schmorp.de/rxvt-unicode/src/perl/confirm-paste?vi...
in it's feature creep it added clipboard access.
then web site developers thought it's a crucial feature. even github used a flash element to allow easy copy of repo url. as if anyone using git can't copy. then some moron added that to the browser, and every other moron followed.
morons. copying flash...
The solution is definitely to avoid pasting commands with newlines in them into your terminal. With Vim, you can use the + register to paste (e.g. "+p). Using iTerm on OS X, I've added a custom keymap for Cmd+V, bound to Run coprocess:
pbpaste | tr -d "\n"
which filters out the newlines.It isn't perfect because people could try to obscure the command but in general it makes me a lot happier to paste commands into my terminal.
- Paul Vixie, vixie-cron INSTALL file (https://github.com/rhuitl/uClinux/blob/master/user/vixie-cro...)
As it happens, this particular attack doesn't work in gngr [0]. The example uses an absolute positioned div to put extra text out of viewport, which is not picked up by gngr when selecting text.
gngr also doesn't enable Javascript by default, so attacks such as that described in OP are not possible from random site visits. (I recommend uBlock / uMatrix for other browsers).
However, the attack surface is really quite large here. CSS directives such as `opacity: 0.001` could be easily used to mask extra text.
[0]: https://gngr.info/
and https://github.com/UprootLabs/gngr
[1]: https://thejh.net/misc/website-terminal-copy-pasteThen I remembered I had no script enabled, and then I remembered I don't trust JS and browsers by default, they are like OS in my OS that are way complex to be audited and they have access to way too much sensitive things (files, display, keyboard, network).
Weirdly enough, I don't think noScript is the solution (it is heavy, unpractical and I dare not look the code).
I am pretty awry of the evolution of the DOM + JS interaction and the new features brought in browsers that looks like both a cancer and instabilities to come.
So am I immune (Unix style is all I ever use) or is there a way for my browser to mess with that buffer as well?
It is far easier to execute on the desktop (by watching for the control key press, then creating a hidden div that contains the text to be copied + malicious code if necessary).
> document.addEventListener('keydown', function(event) { ... })
Basically, press any key on your keyboard on the website, and it'll work.
It may also be because you have no support for execCommand if it didn't work for CTRL+C.
Just wrote https://github.com/awalGarg/realcopy to "counter" this. Plan to add for FF as well.
The proper way of pasting into vim, which doesn't have this problem, is "+p (as mentioned in the article).
:set pasteThis also includes the awful popular installation commands in the form of "curl -s ... | sh" - which means you are basically giving your computer in the hands of a third party.
As opposed to any other installation method? Do you regularly vet the entire source code of software you install?
Always review the script first.
But I agree with your greater point; hashes are better used as a guard against file corruption than fuckery.
I am already using a terminal emulator that warns me when I paste multiple lines (ConEmu).
fu9ar@traveler ~ % ^[[200~echo "evil"
It works, but it also doesn't work.Usually I use the middle-click-to-paste feature, which just doesn't work at all.