Hacker News new | ask | show | jobs
by steven_noble 516 days ago
The article’s headline says it’s a new technique. The article’s body does not really say this.
1 comments

This is just a variation of a trick that is as old as the internet. Most old attacks were using timing instead of double-clicking, usually by tricking the user to click on a bouncing monkey to win a price, instead hitting what was behind.

The real question is, how have browser vendors still not learned. Don't allow any clicks the first moments after a focus change.

If they implement that without an opt-out in the settings, even if buried deep, using the web as a 'power user' will become even more painful!