Something
Emporium

Clippy, the bush paperclip.

Still using Microsoft Internet Explorer? Want to see something scary? IE allows web developers full read access to your clipboard while you're surfing the net. Have you ever copied and pasted user account details between two windows? Have you ever used a password manager such as Password Safe to keep track of your user accounts on websites? Well, check this sucker out:

If you're seeing this, you're not using IE. Good job!


If you're using IE and you've got something in the clipboard you should be able to see the contents printed in that box. Hit refresh to update it. It's a single line of Javascript code that does that:
var text = clipboardData.getData("Text");
So what? It's not as if this data is going anywhere, right? Well, wrong. Thanks to XMLHttpRequest (the basis of AJAX) your clipboard contents could have been sitting in my email inbox by the time you started reading this news item. Luckily for you it's not ('View', 'Source' if you want to check), but not all websites will be that nice. So, what can you do? Well, you could make the change to Firefox, Opera or Safari. I have, and haven't looked back. Or you could disable Javascript - it'll break some sites, but it's pretty much the safest way to use IE. Or you could follow these steps to disable this particular 'feature':
  1. Open up Tools, Internet Options
  2. Go to the 'Security' tab
  3. Click the 'Custom Level' button
  4. Scroll to 'Scripting'
  5. Set 'Allow paste operations via script' to 'Disable'
Dominic

Comments

That is f--king freaky.

Good thing the only time I use IE is for development testing. In other words, never, since I don't do development testing.
robbie
Too true. s--t no wonder people are getting screwed over. Screw you too Microsoft!! Makes you wonder how Bill Gates got so rich......
sven
f--k you.
Alyx
Everyone - excuse Alyx.

She's mad because she thinks I've posted one of her MSN conversations in this news item. Obviously she was copy-pasting it somewhere.
Dominic
Yeah, what he said. Sorry.
Alyx
Haha I think it's pretty awesome. Just for kicks though
aymar
Keep tapping it. It goes away eventually. Trav and I have just been to see 'Plot to blow up the Eiffel Tower' at the King's Arms. Gay set. Too short. Waaay overrated. Trav and I are pretty drunk right now. Of course it's the best time to make use of $2/hr korean internet cafés. We're gonna miss the night rider and swim home. Beat that.
canuckboy
I swear I wrote a damn good submission for S.E.
Too bad I lost it to vanity and computational ineptitude.

It was full of things which really needed to be said then and to repeat now seems like blasphemy.

t.
aymar
Yeah i thought it was good. Something about the coca-cola ribbon device. I'm sure you can think up something just as compelling.
canuckboy
Yeah, I'll just have to get drunk again and convince the 'net cafe guy that it's okay to give us the Korean only computers 'cause I know Korean.

t.