• 6 Posts
  • 157 Comments
Joined 1 year ago
cake
Cake day: July 2nd, 2023

help-circle
  • lando55@lemmy.worldtoTechnology@lemmy.worldBe careful.
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 days ago

    Yeah that’s what I’m curious about; I’m used to copying code snippets or codes from websites by clicking a button (presumably through some browser API?), but am just now realizing that this in itself has security implications.

    Using noscript or some such JS blocker would prevent this but break a lot of other things in the process. That’s why I’m wondering why the API isn’t locked down via some user prompt.


  • lando55@lemmy.worldtoTechnology@lemmy.worldBe careful.
    link
    fedilink
    English
    arrow-up
    21
    ·
    edit-2
    5 days ago

    Why isn’t the default behavior for browsers to not allow access to the clipboard? Similar to how it prompts you for access to camera/microphone

    Edit: On a per-site basis, like if you use the Zoom website it asks you for access to the webcam, would something like this work for clipboard as well or would it break stuff?






  • Make sure you back up all email and IM communications and don’t rely exclusively on server-side retention (provided your DLP policy allows for this.)

    If it ever comes down to it and you are facing the possibility of being the scapegoat for a security incident, your attorney can review the relevant policy and determine whether or not and when you can use these to demonstrate that you communicated your concerns to management and stakeholders.

    Depending on who you reached out to and who was included, absence of a response to your various methods of communication can be used to establish acceptance of risk by leadership.