Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
zdnet.com
zdnet.com
This broader issue is reported on the bug #123913, which is 17 years old. The bug is old enough to drive.
Where I'm from it can't drive, but it's been old enough to drink for a while now !
We have no law about age of consumption but we have a law about a minimal age of buying; it has almost no sanction though and the worst you risk in spending a few hours or a night in a "drunken" cell at the police station. On the other hand we do have strong sanction for selling to someone under the legal age.
About the age of buying it used to be 16 years old but the law was changed to put it at 18 for liquors and hard alcohol back in 2009, since then most maps you can find on the internet about drinking age often put us at 18 but in reality it's still 16 for wine/beer/cider/...
The change was to fight whisky/vodka/rhum/... binge drinking by high schoolers.
(driving age is 18, or 16 is you're accompanied by an adult and passed a specific kind of driving permit)
Isn't that a common issue across browsers? I know on iOS, I get burned by shady sites on Safari that do redirects and pop up a browser-level modal that somehow stops me from closing the tab until I turn off Javascript and restart the browser.
So I guess there's more than one way to aggressively keep the tab open.
Another problem is that browsers are tol complicated. Building Firefox from source requires you to have a powerful machine with multicore CPU and lot of memory and comilation would take a lot of time. This could stop people from contributing fixes.
What possible justification is there for this? Looks like this can become an ideal way to 'force' unsuspecting users to interact with a malicious site...
If I had to guess, I'd say games. Browser games just refuse to die. I thought they'd die with Java applets, then with Flash, but they just keep coming back...
One of the main reasons wouldn't like to see browser games come back is that they are usually basically 100% tied to a server. They're not like standard games, where even if the servers go down, you still have the files and can either keep playing offline or even hack together a server implementation. Once the server goes down, that game is gone[1].
Not to mention, that if an industry were to arise around web-based games, most would probably either be the "free but pay-to-win and with ads" kind, or on Netflix-style subscription platforms where you don't actually own anything and you're just paying for the access.
[1] - not saying it's impossible to preserve it, just that it's not preserved by default, like a locally-installed game is
Many very nice web based games exist, and many can be saved to disk and launched from a local html file just fine. Many games target the web browser because it's easily cross platform, requires no install, and is easy to convince new players to give it a try.
> Richly interactive web sites, games and remote desktop/application streaming experiences want to provide an immersive, full screen experience. To accomplish this, sites need access to special keys and keyboard shortcuts while they are in full screen mode so that they can be used for navigation, menus or gaming functionality.
But I guess it will be used by scammers as well.
It's being championed by the Chromium team, and just because Chromium has turned something on doesn't mean it's a standard. It just means that Chromium doesn't know how to properly launch experimental browser settings behind user flags, <rant>because apparently we've all learned literally nothing from the early days of browser-specific CSS tags and the botched release of flexbox</rant>.
Remember HTML imports, Observable, etc... there's still plenty of time to file issues[0] and participate in conversation about the feature[1]. And I encourage you to do so, because speaking as a game developer on the web, this is a bad feature that shouldn't be built.
[0]: https://github.com/w3c/keyboard-lock/issues
[1]: https://discourse.wicg.io/t/proposal-system-keyboard-lock-ap...
They were using Chrome. Clicking on the browser outside of the page area resulted in the tab going full screen again somehow, and they used multiple other tricks to make the page impossible to close (e.g. looping message boxes).
I don't think browser vendors take these issues very easy. But when I tell relatives to hit the escape key and it DOESN'T work, it isn't helpful.
I (an experienced user) couldn't quickly figure out that it was actually a fullscreen mode, couldn't understand why the browser doesn't launch and thought it was some kind of virus in the system. I figured it out only when I tried to move mouse upwards and a browser UI appeared.
The reason is just that no-one has thought it important enough to fix, and/or no-one has been able to get sufficient agreement on what the correct fix is. Let's not pretend there's a mystery.
AFAIK, there are still no usable built-in date pickers or upload controls.
As far as uploads, no large website ever uses the default ones. All of them roll their own using JavaScript APIs. The most popular example is probably Gmail attachments.
The user can't leave the malicious domain, but they also can't interact with the page, because the dialog is in the way. And even if they could, are they really more likely to trust the site after it's made a bunch of random popups appear in a row?
Is it just malice? What does the malicious site gain?
https://www.youtube.com/channel/UCm22FAXZMw1BaWeFszZxUKw/vid...
But in some cases, Chrome has modal dialog popups that Firefox does not. I made a previous comment about this and you can test that behavior on a safe site like regex101.com:
The possibility to show popups and popovers in browsers should be removed completely. There are little to no legit uses for them. Even reputable websites use them only to nag and annoy their users.
And don't get me started about Javascript. This is a plague, that causes more problems than it solves.
Popovers are CSS. Just a positioned element. And both up-and-overs are "legitimately" used as modals in apps.
Modals have a place, but like everything, they get abused by people with no idea about how things should work. But that isn't a good standalone argument for going back to pre-1997 CSS.
For all the time browsers have been providing this, no one's ever come even close to a good alternative.
That's why the JS-powered browsing experience will never go away, there's nothing like it for how people actually use computers now.
And if you're setting a computer up for a non-poweruser, you can't deploy uMatrix because you really can't expect the user to do said debugging.
A very good thing is that most websites use external javascript to implement the most annoying "features" like asking for consent, tracking, autoplay and diverse pop-up junk.
Also it includes the "cosmetic filtering" that allows me to block html elements by name, very useful for subscription requests.
Only when I browse in other people's computer, I'm reminded how screwed the web really is.
Seriously, though, you're right — and every time I'm forced to enable a new JavaScript source in uMatrix, I'm angered at the site which requires it. In some cases, I just don't even bother using such sites — why buy something from someone who respects neither me nor the Web enough to provide a usable site without tons of JavaScript?
The impact on amount of traffic and load speed is considerable IMO and well worth the pain at start.
One of the funny discoveries was supported platforms and setup bugs are filtered very fast and just flagged as such.
The only monitoring was the up or down trends for that kind of complaints. It includes people on IE6, those using their fridge browser to open the site, or apps that showed the site under some broken in app browser. So people blocking javascript are just a drop in that global number, and if the number is mostly constant it just won’t matter what happens in it and reports won’t even get to the devs.
I've registered my fair share of complaints about javascript problems, nobody does anything ever. Except once when I complained a bug triggered epilepsy, that got their attention real quick.
Also, websites should not be able to block browser UI unless I explicitly allow them to. In any way.
for(a=0;a<9001;a++){
prompt('','');
}One, among many, of the reasons I use Chromium is that I see reports taken absolutely seriously, especially any report with any potential security outcome. Even seemingly minor issues or feature requests I've filed with Chromium get thoughtful and prompt responses.
I wish Mozilla the best, but the quality of Firefox is low in a way that I notice every time I use it; I'd appreciate it if they go back to basics and actually try to address at least the known issues with the software.