Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)
Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)
Posted Nov 26, 2014 11:33 UTC (Wed) by oldtomas (guest, #72579)In reply to: Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica) by bmur
Parent article: Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)
But this is exactly the problem. The very idea that a "document" can take total control of your document viewer (or put in another way: the idea that I have an application which downloads and executes random content from the Intarwebs) should stick out as a "very bad idea" -- this painful experience was made long time ago (remember Word macro viruses?).
A site (and especially the admin endpoint of a site) should offer basic usability without any client-side scripting whatsoever, so that a user (and especially an admin) should be able to disable client-side scripting if she choses to do so.
With HTML5 this ship is sailing away quickly. But any other fixes (server-side XSS protections, sandboxing in the clients, selective script execution à la Noscript) are bound to show cracks at ever-changing unexpected places.
The LWN site is currently under high scraper load, so comment display has been suppressed for anonymous users. If you are a human, you may read the comments by clicking the button below:
Note: you can avoid this step in the future by logging into your LWN account.
