Hacker News new | ask | show | jobs
by jerbearito 14 days ago
"That seems like a major security issue."

Do you mean something you verified is happening or something you assumed is happening? You can go look at the site OP linked and find out what is happening and if it's a "major security issue". In this case, after user click/intervention, it renames the current history entry to "New Tab". This is not a security issue at all.

1 comments

Well, it’s right there in the headline that the website wipes itself from history, so I don’t need any realignment of my ability to discern what I’ve read from what I’ve imagined. If all the site is doing is renaming itself New Tab then that sure isn’t newsworthy. Maybe a domestic violence reporting site should just name itself something innocuous in general without the quick escape? But nonetheless, a web site replacing its own history entry with something from another domain sure doesn’t sound secure.
Not to start an argument but in lamence terms, renaming history to "New Tab" is as close to wiping history as a website can manage. Concealing, obfuscating, hiding might have been better words but the non technucal audience would not see an issue with the language. Nuance is important, though and i agree its slightly misleading
I just tested it on both iPhone and Android and it does indeed remove itself from history and replaces with a link to a weather domain. That’s incredible that it is allowed and I can trivially think of a way to get someone to get to a fake banking site right now, or for that matter, fill the history with a series of visits to domestic violence sites or even worse!
https://developer.mozilla.org/en-US/docs/Web/API/Location/re...

This is known and commonly used -- since 1996. What's the risk? You can't change records about other domains.

I knew about history.replace but I had no idea you could cross sites. Suppose a site, for example, leaves a trail of Amazon Shopping, and curious, you go to it to recall what you did, but it’s Amaz0n instead.
Well there's no need to suppose. While I think if it hasn't been exploited in 30 years, there probably isn't an attack surface, you can always demonstrate and report an exploit.
What does “lamence” mean?
It's an eggcorn for "layman's".
What does eggcorn mean?
That's a typo.
> Not to start an argument but in lamence terms, renaming history to "New Tab" is as close to wiping history as a website can manage.

"I did my best" is no excuse for this critical failure to deliver as advertised.

This fail is a horrifying abuse facilitator.

"so I don’t need any realignment of my ability to discern what I’ve read from what I’ve imagined"

Not what I asked but I'm glad you're doing okay! I share your concerns.