W3C home > Mailing lists > Public > public-html-bugzilla@w3.org > August 2010

[Bug 9602] Autofocus attribute.

From: <bugzilla@jessica.w3.org>
Date: Wed, 04 Aug 2010 22:16:47 +0000
To: public-html-bugzilla@w3.org
Message-Id: <E1OgmGV-000235-1P@jessica.w3.org>

--- Comment #10 from Skyphire <sasha@scarletred.nl>  2010-08-04 22:16:46 ---
(In reply to comment #9)
> Is anyone seriously going to go out of their way to attack the tiny percentage
> of users who have script disabled?  Normal attackers will just use script,
> something as convoluted as this is not worth the effort to them -- simple XSS
> would be much easier to write and much more effective.  If some users don't
> want autofocus, they can turn off autofocus as well as script (if their browser
> permits).

I think that argument goes both ways. Who needs to autofocus something? Google?
I mean; what is it use, if the same can be accomplished by JavaScript too? 

Besides, there is a great percentage of user that have the NoScript extension
for FireFox installed. Another considerate amount of users have disabled
JavaScript altogether for obvious security purposes.

I like the idea of the option to turn if off. In FireFox this doesn't seem
possible yet? at least not in the configuration screen. But as Anne suggested,
if JavaScript is disabled, such attribute routines could be turned off as well.
The latter would be great in my opinion.

Configure bugmail: http://www.w3.org/Bugs/Public/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the QA contact for the bug.
Received on Wednesday, 4 August 2010 22:16:48 UTC

This archive was generated by hypermail 2.4.0 : Friday, 17 January 2020 20:01:21 UTC