Was bound to happen, was just wondering when it would
http://www.tomshardware.com/news/HTML5- ... or=RSS-181
HTML5 Exploit
- Jackolantern
- Posts: 10891
- Joined: Wed Jul 01, 2009 11:00 pm
- hallsofvallhalla
- Site Admin
- Posts: 12026
- Joined: Wed Apr 22, 2009 11:29 pm
Re: HTML5 Exploit
That's not really an xploit. The miss was on purpose by what I understand. It is no different than a download doing the exact same thing. I can write a program to do the exact and make it downloadable. I think it is just a kid trying to get famous.
- a_bertrand
- Posts: 1536
- Joined: Mon Feb 25, 2013 1:46 pm
Re: HTML5 Exploit
Well not really, if the page fills the disk without notice (while download you know you download) it's still somewhat annoying. Also, I doubt many joe sixpack will know where the files are stored and therefore will have issues to cleanup.
Creator of Dot World Maker
Mad programmer and annoying composer
Mad programmer and annoying composer
- hallsofvallhalla
- Site Admin
- Posts: 12026
- Joined: Wed Apr 22, 2009 11:29 pm
Re: HTML5 Exploit
I did not mean the download doing it but downloading a program to do it. The only way the above is going to happen is on purpose. Maliciously. So you could do the same with the program.
- a_bertrand
- Posts: 1536
- Joined: Mon Feb 25, 2013 1:46 pm
Re: HTML5 Exploit
Well you expect that a software you run on your PC could basically do anything. Yet when you browse the net you would expect to be safe and not think on each and every url you visit. That's why I find it personally disturbing that we find more and more issues. Sure holes are plugged as found (usually), and sure as the technology evolves and offers more opportunities it offers also more risks. Yet I'm somewhat scared by how the things are.
Creator of Dot World Maker
Mad programmer and annoying composer
Mad programmer and annoying composer
- hallsofvallhalla
- Site Admin
- Posts: 12026
- Joined: Wed Apr 22, 2009 11:29 pm
Re: HTML5 Exploit
I agree, but also think back to the real boom of computers. We had the same issues. That's where Virus's were truly virus's and you always had to worry about what disk you were putting in your PC or what you were installing. With every new technology there are risks no doubt. And yes the internet as we see it today is new as there has only recently been a massive rush to it and demand for more and more. We are building this ship faster than we can plug the holes 
- Jackolantern
- Posts: 10891
- Joined: Wed Jul 01, 2009 11:00 pm
Re: HTML5 Exploit
This is definitely an issue with the affected browsers, since this is a failure to properly implement the W3C specs. The specs clearly place a limit on the data storage per origin, but if the browsers are simply ignoring the "x space per origin" rule, there is no limit on how much a site could fill. Now add in the gaping XSS holes in many sites combined with the fact that your average Internet layuser has no idea how to clear localstorage, this could be a problem. Of course, this is only in the "annoy random people you will never meet" category, so it isn't a huge issue. There is really nothing to gain behind it for the person writing the script, so hopefully we won't see it exploited much while browsers are patching-up.
The indelible lord of tl;dr