Live data from Hacker News

Malicious Use of the HTML5 Vibrate API

shkspr.mobi

11–20 of 67 posts

Re: Malicious Use of the HTML5 Vibrate API

#11
I can't wait to see this being exploited by advertisements.

I'm already seeing this really bad trend of ads redirecting to the app store which makes the page that did it completely unreadable (going back to safari shows an empty page) and now there's the prospect of the phone vibrating to the blinking of the various ads wanting my attention?

If this goes on like this, I'll really need an adblocker on my phone.

Re: Malicious Use of the HTML5 Vibrate API

#12

Are any of those examples really only convincing if they can vibrate the phone? Surely a scam that just involved that fake call screen while playing a fake ringtone would be more or less just as effective? I can't imagine it's a lot of people who wouldn't be fooled because they think "oh, it's fake, it's not vibrating" who would suddenly be fooled by this.

I think the vibrate would catch people who aren't really looking at their phone and the x% of people who don't know how to really use their phone.

Re: Malicious Use of the HTML5 Vibrate API

#13
post #7
post #5

I'm surprised to learn that a web site doesn't need to ask for your permission to access the Vibrate API. I think there must be a warning screen with the list of permissions the web site wants, like the ones we're getting when installing apps from app stores but with a twist so you can disable individual permissions for a web site.

In Firefox right-click a page -> Page Info -> Permissions. Some APIs are allowed by default and some aren't. For the discussion about Vibration, see: https://wiki.mozilla.org/WebAPI/Security/Vibration

You can't do this on a phone however as far as I know. The vibrate API is build for mobile devices.

Re: Malicious Use of the HTML5 Vibrate API

#15
post #12

Are any of those examples really only convincing if they can vibrate the phone? Surely a scam that just involved that fake call screen while playing a fake ringtone would be more or less just as effective? I can't imagine it's a lot of people who wouldn't be fooled because they think "oh, it's fake, it's not vibrating" who would suddenly be fooled by this.

I think the vibrate would catch people who aren't really looking at their phone and the x% of people who don't know how to really use their phone.

I think the percentage of people browsing the Web while not looking at their phone is pretty low. I'm also not sure how the vibration would convince people who don't know how to use their phone. I would suspect this group would require less effort to manipulate.

Re: Malicious Use of the HTML5 Vibrate API

#16
post #13
post #7

Earlier quoted context omitted.

In Firefox right-click a page -> Page Info -> Permissions. Some APIs are allowed by default and some aren't. For the discussion about Vibration, see: https://wiki.mozilla.org/WebAPI/Security/Vibration

You can't do this on a phone however as far as I know. The vibrate API is build for mobile devices.

I don't understand this statement. A phone is a mobile device.

Re: Malicious Use of the HTML5 Vibrate API

#17
post #13

Earlier quoted context omitted.

You can't do this on a phone however as far as I know. The vibrate API is build for mobile devices.

I don't understand this statement. A phone is a mobile device.

And, on mobile Firefox, there's no way to see the permissions of a page. Certainly no that I can see of FF for Android.

Re: Malicious Use of the HTML5 Vibrate API

#18
Can't wait for Adblock for IOS.

[However we get less annoying ads because safari don't play flash. Advertisers are obviously moving to different kind of ads adapted to mobile. Anyway it's reasonable to dread for the time that they'll catch up with the desktop ones.]

Re: Malicious Use of the HTML5 Vibrate API

#19
post #12

Earlier quoted context omitted.

I think the vibrate would catch people who aren't really looking at their phone and the x% of people who don't know how to really use their phone.

I think the percentage of people browsing the Web while not looking at their phone is pretty low. I'm also not sure how the vibration would convince people who don't know how to use their phone. I would suspect this group would require less effort to manipulate.

not many people click legitimate ads. but a low enough percentage do, to make marginal gains in their effectiveness highly sought after

I suspect malware works the same. It costs little to deploy, so even if 1 in 10,000 people are fooled, it can be lucrative.

Re: Malicious Use of the HTML5 Vibrate API

#20
post #17

Earlier quoted context omitted.

I don't understand this statement. A phone is a mobile device.

And, on mobile Firefox, there's no way to see the permissions of a page. Certainly no that I can see of FF for Android.

Firefox for Android developer here, you can long-tap on the location bar while on the page and select 'Edit Site Settings'. Is that what you're looking for?
Post reply on HN