Live data from Hacker News

Using the HTML5 Fullscreen API for Phishing Attacks

feross.org

131–133 of 133 posts

Re: Using the HTML5 Fullscreen API for Phishing Attacks

#132

Earlier quoted context omitted.

Entirely? So no way to use fullscreen mode for keyboard-driven games in saf'?

That's correct, this is why the Facebook full-screen photo viewer is not enabled in Safari even though the API is supported.

That stinks.

Re: Using the HTML5 Fullscreen API for Phishing Attacks

#133
post #29
post #22

When the standard was being ratified, this came up on the mailing list (I can't find the link right now, I am on my cell). The solution was that to recommend vendors print warning labels across the top or add a layer of permissions around the feature - which Chrome and Safari have done. for eg. when I open it I get a message saying 'Chrome is currently in fullscreen mode'. They will likely both also add permission bo…

which Chrome and Safari have done Firefox does it too, and in a much more obvious way than either Chrome or Safari. Here are all the latest browsers on Mac compared: http://imgur.com/a/jdcI7 (Sorry Opera; I haven't re-installed you yet.) I actually didn't get any permissions dialog or warning label in Safari 6; maybe I ok'd it for another site at some point in the past, but I definitely didn't whitelist this domain.

These messages do not show any warnings about possible malicious activity. This is enough to get a few not so computer-savvy people to get robbed.
Post reply on HN