Tim Hastings - NonHostile (because there's no need)

Weblog and collection of geeky articles.

  Home :: Who? :: Contact :: Links :: Subscribe subscribe
Autumn 2007Autumn 2007Our Holiday in Costa De La Luz


Now, not a lot of people know this, but there is a wide-open privacy risk with Microsoft's Internet Explorer. It is possible for any website that you visit to obtain the current contents of your Windows clipboard. If you are not alarmed by this, you should be. If you use the clipboard to transfer data from one application to another, then this data is up for grabs.

You are at risk if you use Microsoft Internet Explorer and you have not changed your privacy settings. Keep reading, and I'll show you how to protect yourself.

To demonstrate, here is the current contents of your clipboard: (this will only show anything if you're using IE unsecured)
Using client-side scripting techniques known as Ajax or XML HTTP Requests, it is possible for the web page to transmit this data back to the web server.

Don't Panic! I will show you how to safe guard your privacy! Just follow these steps:

Step 1: On the Tools menu, choose Options.


Step 2: On the Security Tab, select Internet from the Web Content Zone and then choose Custom Level...


Step 3: Scroll down this list of options to the botton and find the 'Allow paste operations via script' setting.


Step 4: Either choose disable or select prompt. Press OK, and OK on the Internet Options form.
I recommend disable because the continuous prompting can get very anoying!


'Prompt' will ask you every time a script tries to sneek a peek at your clipboard, like this:


Alternatively, you could use Firefox which is an alternative web browser instead of Internet Explorer.
You can download Firefox from here or you can get it bundled with the Google Toolbar from the logo on the right.




1 comment, Web, Saturday, March 4, 2006 13:37

Timeline Navigation for Web posts
ASP Fix: XML transformNodeToObject - Not implemented (80004001) (made 145 weeks later)
Privacy Risk With Internet Explorer (this post, made Saturday, March 4, 2006 13:37)
ASP: Pinging Technorati from the Server Side using XMLRPC and Classic ASP (made 31 weeks earlier)


Comments
Thank you for this. I don't tend to use the clipboard much, but I can't have anyone peeking at my recipes, you know. Love, Mum

Posted by: Mum on Sunday, March 5, 2006 10:37

Post a Comment
Name:  Home page and email address are optional.
  Email addresses will not be displayed or spammed!
Remember these details
Email:
Home Page:
Comment:
Comments cannot contain HTML, URLs will be formatted into hyperlinks.
I reserve the right to remove any comments for any reason.