You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For example, I can post the following link which opens the Steam settings if Steam is installed. I am sure there are some protocols that can do much worse. Firefox shows a confirmation dialog before doing anything, but we shouldnt rely on this.
http (<- actually not allowing http link would be an interesting take, be the web is not there yet, or maybe it could be blocked by default and admin could allow it if they wish, or the other way around)
Basically the idea is not to allow protocols that are insecure in some way (or could have an unintended effect when opened). Or only allow "secure" protocols, whatever that means exactly.
For example, I can post the following link which opens the Steam settings if Steam is installed. I am sure there are some protocols that can do much worse. Firefox shows a confirmation dialog before doing anything, but we shouldnt rely on this.
Want to back this issue? Post a bounty on it! We accept bounties via Bountysource.
The text was updated successfully, but these errors were encountered: