HTML5 hole in major browsers... well, except for Firefox


Recommended Posts

"Flaws"

You mean ignoring the large, red-backgrounded section of the localStorage spec that specifically warns about this "flaw"? Hah!

Like Microsoft and Opera also did? I'm really not sure why you're so bent on arguing me and turning this into another opportunity to bitch about Google when almost every browser on the market has the flaw :/ It's a flaw they ALL need to fix (except Mozilla)

Like Microsoft and Opera also did? I'm really not sure why you're so bent on arguing me and turning this into another opportunity to bitch about Google when almost every browser on the market has the flaw :/ It's a flaw they ALL need to fix (except Mozilla)

Sorry to burst your ego-bubble, but you're the one who responded to me in the first place.

And honestly, not only is "they did it too!!!11" a playground-level response, but it's also completely irrelevant. Presto and Trident aren't open source, they aren't locking down the web with proprietary vendor prefixes and they haven't had people arguing in their favour purely because of silly corporate allegiances. (in this context)

Sorry to burst your ego-bubble, but you're the one who responded to me in the first place.

And honestly, not only is "they did it too!!!11" a playground-level response, but it's also completely irrelevant. Presto and Trident aren't open source, they aren't locking down the web with proprietary vendor prefixes and they haven't had people arguing in their favour purely because of silly corporate allegiances. (in this context)

Did you forget that ALL 4 of the major engines do those stupid vendor prefixes? -o (for opera), -ms (for MSFT), -moz (for Mozilla) and -webkit (everyone else) ?

Don't get why you're bashing Webkit for something EVERYONE is doing. Why not bash them all for doing it?

Because Mozilla and Opera deprecate their prefixes, WebKit (and IE) never do, which leads to people relying on non-standard behavior. At least Google and Mozilla are working on removing them entirely (for new properties)

Also, people have found another vector for this, IPv6. Each IPv6 host is considered separate (so gets their own localStorage block), yet a single person can have 18,446,744,073,709,551,616 v6 addresses (Assuming they get a /64 route, even more if they get a /48)

Edit: The best way to fix this for any situation is to put a global limit on local storage of all types, the reason this attack isn't possible with plain HTTP stuff is because browsers already limit the amount of data they store there on a global basis. Saying a single site can only store 50MB or whatever isn't enough, the browser also needs to limit the total amount to 1GB or so for all sites.

Because Mozilla and Opera deprecate their prefixes, WebKit (and IE) never do, which leads to people relying on non-standard behavior. At least Google and Mozilla are working on removing them entirely (for new properties)

This plus the fact the other vendors have been prompt in supporting unprefixed properties when a spec reaches maturity, for instance even IE10 has support for unprefixed CSS3 gradients, yet Webkit is still behind. Considering the release cycles of Trident and Webkit, that is absolutely shameful.

Also, people have found another vector for this, IPv6. Each IPv6 host is considered separate (so gets their own localStorage block), yet a single person can have 18,446,744,073,709,551,616 v6 addresses (Assuming they get a /64 route, even more if they get a /48)

Personally I'd just restrict the ability to access localStorage from an IP address, v6 or otherwise. I think having a domain as a requirement is a fair trade.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Owing to the nature of Windows feature enablement updates, it was distributed over Windows Update services as a complete system upgrade rather than as an ordinary cumulative update
    • Microsoft confirms Windows 11 26H2, urges IT admins to prepare for release by Usama Jawad Windows 11 typically follows an annual update cycle, but Microsoft recently broke that tradition a bit by releasing a "26H1" version in the first half of this year as a "scoped" build for select new silicon PCs only. This version was not available for customers using 24H2 and 25H2 builds, as Microsoft is busy preparing version 26H2 for them, confirmed officially for the first time. In a Windows IT Pro blog, Microsoft has urged IT admins to prepare for the upcoming release of Windows 11 version 26H2. The company has confirmed that this will be a small enablement package (eKB) that will simply light up certain disabled features that are already present in the operating system's code base. This means that the "refined" Windows update and deployment experience will be simpler and quicker, with minimal disruptions, as the feature update will simply toggle a few flags rather than performing a complete replacement. Microsoft has explained that this is all possible because the standard Windows 11 releases share the same servicing branch and hence, the same source code. However, this also means that Windows 11 26H1 users won't be able to upgrade to 26H2 as that is a different branch, but this is something we have known for a while now. Similar to previous annual feature updates, Windows 11 26H2 will offer the following support cycles: 24 months of support for Home, Pro, Pro EDU, and Pro for Workstations editions 36 months of support for Enterprise, Education, IoT Enterprise, and Enterprise Multi-session editions Microsoft has not confirmed a concrete release date for Windows 11 26H2, but noted that it is "coming soon". If we go by the ongoing release cadence, we can expect it to begin rolling out in early October 2026. As such, IT admins have been encouraged to begin validating Windows Insider releases in the Experimental Channel, plan rollout rings, and strategize the utilization of their existing deployment tools.
    • Windows 11 gets new audio improvements in the latest builds by Taras Buria Today's Experimental builds (26H1 and Future Platforms, formerly Canary) pack several audio-related improvements. If your device is enrolled in the Experimental Channel (26H1), you can download build 28120.2315, while those in the Future Platforms version have build 29613.1000 to try. Here is what is new in build 29613.1000: [Audio] Following up on our previous improvements, we’re making some more adjustments to Settings > System > Sounds based on your feedback. Namely, we’ve updated the “All sound devices” page so: You now have the ability to change default devices from this page. Each of the devices displayed on this page now has a little volume meter next to it to show if there is audio actively playing. We’ve adjusted the page design slightly so now you can filter whether you’re viewing input or output devices. We’ve added toggles so you can choose if you want to hide or show disabled, disconnected, and unplugged devices on this page. We’ve also updated the input and output audio properties page for devices in Settings to now include jack information for those that need it. And here is the changelog for build 28120.2315: This update includes a small number of minor bug fixes and improvements. [Accessibility] This update improves caption style responsiveness by redrawing captions immediately for caption style changes. If no current caption is visible, a sample caption string is displayed. [Audio] This update improves the reliability of the inbox HD Audio driver. You can find the official release notes for build 28120.2315 here and for build 29613.1000 here.
    • I agree with what I think you are saying, just not in the way you are saying it. Like any tool, the amount it represents your work is perorational to the effort you put into it. It is similar to why 2nd grade math students learning to add and subtract are not allowed to use calculators, but a high-school calculous student is. For the 2nd grader, that tool would completely replace the work they are doing, for the calculous student the same tool allows them to work far more effectively while in no way replacing their effort or knowable. If you spend 30 seconds writing a prompt, then the image that comes out is no more "yours" than if you found the same image with a Google Image search. However, many of these generative tools also support highly iterative processes that allow back and forth, and merging generated images with photos or human created images. I am sure you would agree that a human spending hours of time working on a project, even if AI was involved in the process, still reflects that human's work.
  • Recent Achievements

    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      575
    2. 2
      +Edouard
      189
    3. 3
      Michael Scrip
      79
    4. 4
      PsYcHoKiLLa
      78
    5. 5
      neufuse
      71
  • Tell a friend

    Love Neowin? Tell a friend!