https://msdn.microsoft.com/en-us/library/bb250473(v=vs.85).a...
http://i.stack.imgur.com/jvDUh.png
https://developer.mozilla.org/en-US/docs/Mozilla/Preferences...
But the same quick search shows that it does not appear possible to control this in Chrome. If anyone knows how, please correct me.
How is this method different?
This method is more sophisticated; it monitors the whole page for copy commands, and has an event listener watching to see when this 'copy' command is executed.
What browsers really should have are a standard "Ask & Whitelist" dialog for all of these security critical features[1]. It seems Firefox even used to have this feature, but it and the corresponding addon have long since crumbled to dust[2].
Unfortunately browsers are no longer controlled by hackers who think about all the implications of a feature, but by corporations who think about money, and us hackers have to spend inordinate amounts of time trying to play security whack-a-mole, or be forced to give up and use our browsers like sheep, the way the corporations want us to.
[1] There's many more, including utterly ridiculous stuff such as telling websites the battery charge status of your device (and if your charger is plugged in): https://gist.github.com/haasn/69e19fc2fe0e25f3cff5
[2] http://kb.mozillazine.org/Granting_JavaScript_access_to_the_...
https://bugzilla.mozilla.org/show_bug.cgi?id=38966
They had a pretty useful per-site configuration mechanism that wasn't UI-configurable so someone started to make a UI for it, but then some higher-up decided they should remove the whole thing completely! The screenshots they have there look so awesome:
https://bug38966.bmoattachments.org/attachment.cgi?id=63187
It's ironic that, meanwhile, IE gets this right.
FWIW, the features that this uses have their origins in proprietary IE5 features (maybe 5.5?). Whether this attack works in IE5 I leave as an exercise to someone else.
Note that the tradeoffs are more complex than what one might naïvely assume: people weren't using the feature as it existed in Firefox before because it required explicit user interaction, but doing the same thing through Flash didn't… so everyone just used Flash. In effect, this is a security bug the platform has long had (because, like it or not, de-facto the web platform for the longest time included Flash). Now, should we blindly copy everything Flash can do? Of course not. But if something is making people hold on to Flash, we really should consider the tradeoffs. Are we just gaining theoretical superiority but practical irrelevance (on desktop at least; mobile where Flash is gone is a different story)?
Of course a better solution wouldve been a program which doesnt so easily let you lose data in the first place, but this software was long past that.
*insanely large is anything that takes up 75% of whatever computer bottlenecks first at the time of reading this comment(Memory, processor)
If it's intentional, you don't want to pull the data back up (people want a "fresh copy")
If it's not intentional, you do want to pull the data back up.
Though of course you can make something like a "New Copy" button, but then that presents its own challenges.
All this was introduced to prevent abuse. Apparently it still wasn't enough though...
However, sometimes I want to share a qoute I found online. I don't want a promo for the website inserted into my clipboard. For them, it must be a fine line that realization: user-hostility can be short term profitable but long term fatal.