W3C home > Mailing lists > Public > public-web-security@w3.org > June 2011

Re: Req for feedback? Add attribute to elements to defeat clickjacking

From: Michal Zalewski <lcamtuf@coredump.cx>
Date: Tue, 7 Jun 2011 12:07:44 -0700
Message-ID: <BANLkTikYD6dfj-nK3UzM2jh4LcxGfLKmJg@mail.gmail.com>
To: "sird@rckc.at" <sird@rckc.at>
Cc: public-web-security@w3.org
> I think leaving that to the developer might be better, since he knows
> his product better.. since I'm sure scrolling/moving and clicking soon
> after (<1 second) might be common enough on some cases but very
> uncommon on other.

Yes, but there are no APIs to do it well right now. Monitoring
onmouseover etc fails in a number of scenarios (IIRC, including
closing, opening, and repositioning windows in certain ways), and
again, is problematic with many accessibility features :-(

/mz
Received on Tuesday, 7 June 2011 19:08:32 UTC

This archive was generated by hypermail 2.3.1 : Tuesday, 6 January 2015 20:26:19 UTC