12 ms·
"That seems like a major security issue." Do you mean something you verified is happening or something you assumed is happening? You can go look at the site OP
by jerbearito 2mo ago
"That seems like a major security issue."
Do you mean something you verified is happening or something you assumed is happening? You can go look at the site OP linked and find out what is happening and if it's a "major security issue". In this case, after user click/intervention, it renames the current history entry to "New Tab". This is not a security issue at all.
- hyperhello 2mo agoWell, it’s right there in the headline that the website wipes itself from history, so I don’t need any realignment of my ability to discern what I’ve read from what I’ve imagined. If all the site is doing is renaming itself New Tab then that sure isn’t newsworthy. Maybe a domestic violence reporting site should just name itself something innocuous in general without the quick escape? But nonetheless, a web site replacing its own history entry with something from another domain sure doesn’t sound secure.
- xdkaplan 2mo agoNot to start an argument but in lamence terms, renaming history to "New Tab" is as close to wiping history as a website can manage. Concealing, obfuscating, hiding might have been better words but the non technucal audience would not see an issue with the language. Nuance is important, though and i agree its slightly misleading
- hyperhello 2mo agoI just tested it on both iPhone and Android and it does indeed remove itself from history and replaces with a link to a weather domain. That’s incredible that it is allowed and I can trivially think of a way to get someone to get to a fake banking site right now, or for that matter, fill the history with a series of visits to domestic violence sites or even worse!
- jerbearito 2mo agohttps://developer.mozilla.org/en-US/docs/Web/API/Location/replace https://developer.mozilla.org/en-US/docs/Web/API/Location/re... This is known and commonly used -- since 1996. What's the risk? You can't change records about other domains.
- hyperhello 2mo agoI knew about history.replace but I had no idea you could cross sites. Suppose a site, for example, leaves a trail of Amazon Shopping, and curious, you go to it to recall what you did, but it’s Amaz0n instead.
- post-it 2mo agoWell there's no need to suppose. While I think if it hasn't been exploited in 30 years, there probably isn't an attack surface, you can always demonstrate and report an exploit.
- deleted 2mo ago[deleted]
- hilariously 2mo agoI dont think its highly exploitable, but you could get people in trouble - have them visit innocuous website during a vulnerable time window, spray a bunch of adult websites into their history, report them to the boss, future visits do not inject history items.
- aaron695 2mo ago[dead]
- 100721 2mo agoWhat does “lamence” mean?
- deleted 2mo ago[deleted]
- caymanjim 2mo agoIt's an eggcorn for "layman's".
- chopin 2mo agoWhat does eggcorn mean?
- hyperhello 2mo agoThat's a typo.
- caymanjim 2mo agoIt's not a typo. Although it's really more of a routine malapropism than an eggcorn, since it's nonsensical. https://en.wikipedia.org/wiki/Eggcorn https://en.wikipedia.org/wiki/Eggcorn
- chrisjj 2mo ago> Not to start an argument but in lamence terms, renaming history to "New Tab" is as close to wiping history as a website can manage. "I did my best" is no excuse for this critical failure to deliver as advertised. This fail is a horrifying abuse facilitator.
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- jerbearito 2mo ago"so I don’t need any realignment of my ability to discern what I’ve read from what I’ve imagined" Not what I asked but I'm glad you're doing okay! I share your concerns.