Looks like you are typing while in full screen
imgur.com
imgur.com
This gets into sandboxes needing to have "sacred pixels" as a border to prevent the sandbox tricking the user into thinking they exited from the browser
This issues goes way back: imagine if after executing a program on CLI instead of closing it gave you a fake shell, where you eventually went about your day until you had to type your password into sudo..
Of course, your point about the app store is good motivation to address this, whereas consoles don't go about offering much protection there
Is this even the case anymore? On Android, all my URL bars peel up into the top of the screen as I browse, and I'm pretty sure a website can capture the vertical swipe/arrange an inner-scrolling element to make it very difficult to quickly get the URL bar visible again.
I think that would be enough to trick most users. This seems like an unnecessary limitation
As a fun fact, even worse might be a program maliciously aliasing sudo in ~/.profile
But then again how, how someone know if that happened!
For background, there is a convenience feature in sudo: It only requires your password prompt if you have not had a successful sudo invocation in the same terminal in the last X minutes (5 minutes, I think? not sure on the exact value). "sudo -v" is a special invocation which does not actually execute any command, but it renews your 5-minute lease. ("sudo true" is effectively equivalent, though not idiomatic.)
So if you're executing a short script that needs sudo, run "sudo -v" before running the actual script. Then you know that if a root password prompt pops up again, it's not really sudo who's asking.
The bigger problem is that even without sudo or your root password, malicious scripts can do a lot of damage. ie. they can add a fake sudo to your .profile, so you next time you try to do "sudo -v" your password still gets stolen.
Every "security" feature on Safari points into harming web apps so you are on the right tracks...
It doesn't if you have dual monitors and are typing on the other, which I do rather often.
I'm not particularly inclined to reconfigure to see if that's still the case when switching desktops on a single-monitor setup, since OSX mangles the desktop layouts if you unplug a monitor and reboot.
What version are you running, I'm running catalina.
Maybe, instead, there ought to not be 'sacred pixels' on the screen, but a secret image to be displayed to the user (which only they recognize and can perhaps even change over time), and only the user, alongside every prompt for user input.
Admittedly, this could engender a false sense of trust if the secret image is ever compromised. I think there is an architecture around this, though.
The daemon providing the secret image service could simply stop screen sharing applications from reading those pixels. Why not expose the screen as a virtual filesystem, where every pixel has mutable unix permissions? Then, in any secure system, the screen sharing services would merely need to be served its pixels by the secret image server. The secret image server then just has to preserve the condition that programs aren't served secret pixels if they aren't run by a user in the 'secret pixel' entry in /etc/group. Then it would just be a matter of (secret) pixel files remaining unreadable for untrusted programs.
This could require some deep hooks into the display system, though, considering that a lot of graphical programs are going to be running on the video driver (well, technically, all of them). I suppose another reason to care about open source and graphics.
I wonder as well if Rio from Plan 9 can accomplish this with a minimal amount of code, since Rio already serves windows through a file server!
I think it’s not a bad idea in terms of security, and likely its a response to an actual attack vector. But maybe there should be a way to disable it for specific sites or just have a warning bar.
"youtube.com" could show you a fake keyboard anyways and why can't it trick you with a real keyboard.
1. The username/password form of your bank, as shown in your browser.
2. A pixel-perfect fake of your bank as it would look if you were to go there directly in your browser, including the browser UI, except you’re actually looking at a full-screen image displayed on a random scammer website, and you already were in the fake when you typed the bank domain name into the fake address bar on the fake UI.
I am not arguing your point strictly. But the problem in general can only really be solved with education. Users should always know who they’re giving credentials to. A technical measure like not allowing keyboard input in a full screen browser is a leaky stop gap. The full screen app could just as well show its own pixel perfect full screen keyboard and trick users to tap it.
You should’ve led with that, it’s a much better question than your others on this thread.
[1] ie. you're on site A, which wants access to your account details on bank X. when you're entering your details, the address bar shows site A's domain, not plaid.com or bank X.
If a user trusts plaid to handle their credentials, so be it.