Another thing that Facebook can do, is detect Wall-spamming and require the user to confirm that (s)he really wants to spam all his/her friends.
Another thing that Facebook can do, is detect Wall-spamming and require the user to confirm that (s)he really wants to spam all his/her friends.
The XSS code could just be modified to automatically confirm its actions.
The only real way to eradicate this problem is what he is already trying to do: educate the users.
I think the blame lies with the address bar. If you think about it, it's a bit like having a magic key sequence on your car radio that drops you into the engine management system debugger.
Why flaw you ask? It can edit your clipboard content on "copy" and "paste" action. So you just select text, press ctrl+c and end up with some malicious link in your clipboard.
The second thing is modifying the selection through JavaScript which is indeed possible. However, removing that ability doesn't really solve your problem because you could imagine having white small text embedded wherever you select which would end up in your clipboard without your knowledge.
As far as things we could do at Facebook, we definitely work to detect wall spamming. We end up blocking this kind of spam a lot the time, but there's always room for improvement.
Put another way, how do we determine if the caller of some of our js is malicious or is us?
Disabling javascript: urls in the address bar seems like a much better way to mitigate this problem.
1. Drag this icon to your favorites bar. 2. Click it.
Might not have the same turnover as the paste-trick but will definitely catch at least 50% of those the other method does. Though IE will warn the user that this is dangerous in step 1 but other browsers doesn't.
Bookmarklets are good but the security model is very fragile. A new concept of widgets has to be introduced in browsers. Kindof like IE8's "web-snippets" but with more power and some sandboxed interface between the widget and the current website. For power users and trusted widgets you should be able to disable the barriers completely to get the same functionality as today, but as opposed to today, this should require a user warning at least on bookmarklet install.