[whatwg] Dealing with UI redress vulnerabilities inherent to the current web

Toby A Inkster mail at tobyinkster.co.uk
Thu Sep 25 12:33:45 PDT 2008


Michal Zalewski wrote:

> 3) Add an on-by-default mechanism that prevents UI actions to be taken
>     when a document tries to obstruct portions of a non-same-origin  
> frame.

Something like focus-follows-mouse plus autoraise for IFRAMEs might  
work.

-- 
Toby A Inkster
<mailto:mail at tobyinkster.co.uk>
<http://tobyinkster.co.uk>




More information about the whatwg mailing list