Live data from Hacker News

Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

zdnet.com

61–70 of 82 posts

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#61
post #33

The bigger problem is that a authentication dialog is a window modal, which makes the entire browser inoperative. If it wasn’t for this, you could simply close the tab with the malicious site. This broader issue is reported on the bug #123913, which is 17 years old. The bug is old enough to drive.

> The bug is old enough to drive. Where I'm from it can't drive, but it's been old enough to drink for a while now !

Denmark?

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#62
post #61
post #33

Earlier quoted context omitted.

> The bug is old enough to drive. Where I'm from it can't drive, but it's been old enough to drink for a while now !

Denmark?

France.

We have no law about age of consumption but we have a law about a minimal age of buying; it has almost no sanction though and the worst you risk in spending a few hours or a night in a "drunken" cell at the police station. On the other hand we do have strong sanction for selling to someone under the legal age.

About the age of buying it used to be 16 years old but the law was changed to put it at 18 for liquors and hard alcohol back in 2009, since then most maps you can find on the internet about drinking age often put us at 18 but in reality it's still 16 for wine/beer/cider/...

The change was to fight whisky/vodka/rhum/... binge drinking by high schoolers.

(driving age is 18, or 16 is you're accompanied by an adult and passed a specific kind of driving permit)

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#63
post #45

The bigger problem is that a authentication dialog is a window modal, which makes the entire browser inoperative. If it wasn’t for this, you could simply close the tab with the malicious site. This broader issue is reported on the bug #123913, which is 17 years old. The bug is old enough to drive.

Not to defend Mozilla's inability to prioritize , but ... Isn't that a common issue across browsers? I know on iOS, I get burned by shady sites on Safari that do redirects and pop up a browser-level modal that somehow stops me from closing the tab until I turn off Javascript and restart the browser.

Ironically, I've dropped Chrome on Windows because of the very same issue several years ago. There were more than a few sites like this; the only way to close the tab was killing the entire browser with the task manager. I've been occasionally stumbling upon sites like this for a year and a half, and the bug hasn't been fixed this entire time. Then I switched to Firefox, which has a feature to bail out from the endless loop (the 'Prevent this site from creating additional dialogs' checkbox), and never looked back.

So I guess there's more than one way to aggressively keep the tab open.

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#64

Earlier quoted context omitted.

I also saw one with an offset custom mouse cursor so you can’t trust what you’re clicking on.

Also such sites sometimes play audio instructions trying to scare or deceive a user.

I've had relatives tricked by this and called the number for "Microsoft Support."

They were using Chrome. Clicking on the browser outside of the page area resulted in the tab going full screen again somehow, and they used multiple other tricks to make the page impossible to close (e.g. looping message boxes).

I don't think browser vendors take these issues very easy. But when I tell relatives to hit the escape key and it DOESN'T work, it isn't helpful.

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#65

Earlier quoted context omitted.

> Note that currently web browser developers are implementing a fullscreen mode with keyboard lock that is much harder to leave because it blocks most of system key combinations. The only keys that will still work are Ctrl + Alt + Del or holding an Esc for two seconds. And as I assume you cannot leave it using mouse or touchpad. What possible justification is there for this? Looks like this can become an ideal way to…

> What possible justification is there for this? If I had to guess, I'd say games. Browser games just refuse to die. I thought they'd die with Java applets, then with Flash, but they just keep coming back...

There is no good reason for any website to be able to block Esc key from exiting fullscreen mode, games or no games.

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#66
post #55

Earlier quoted context omitted.

Why the language of refuse? Are you inferring there is inherently something bad about games on the web?

No, that's just my opinion. One of the main reasons wouldn't like to see browser games come back is that they are usually basically 100% tied to a server. They're not like standard games, where even if the servers go down, you still have the files and can either keep playing offline or even hack together a server implementation. Once the server goes down, that game is gone[1]. Not to mention, that if an industry were…

This is no longer true for even locally installed games. If Ubisoft's uPlay disappears tomorrow, your locally installed games are just useless bits.

Many very nice web based games exist, and many can be saved to disk and launched from a local html file just fine. Many games target the web browser because it's easily cross platform, requires no install, and is easy to convince new players to give it a try.

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#68
post #57
post #50

Earlier quoted context omitted.

That must be on an older iOS version? Pretty sure that on recent versions the modal dialogs are actually not modal anymore and are rendered 'in content'. So you can always close the tab.

11.2.1. But I guess in tech, that's the wild-west stone age where you couldn't expect a browser not to be taken over by a site ...

Why the negativity? Software is fluid and never perfect. And specially the fight between browsers and malicious sites won't stop at any time ... At least they recognized the problem and acted on it.
Post reply on HN