We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

MSE FAULT - Links open in current tab instead of a new tab - action required

Options
1246789

Comments

  • pate-ci0
    pate-ci0 Posts: 3,056 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    Here's an explanation of a security risk, to do with opening a link in a new tab, which may be the cause of the current situation:

    https://www.jitbit.com/alexblog/256-targetblank---the-most-underestimated-vulnerability-ever/
  • robbies_gal
    robbies_gal Posts: 7,895 Forumite
    Part of the Furniture 1,000 Posts
    thanks matty does it interfere with other sites/settings

    will give it a try
    What goes around-comes around
  • moonshine
    moonshine Posts: 815 Forumite
    Part of the Furniture 500 Posts Combo Breaker
    I still think it needs putting back to how it was. I'm sure the so called risk is minimal and as this (not opening a new tab/window) doesn't happen on other sites, I really can't see the need for such paranoia here.
  • 100mg
    100mg Posts: 62 Forumite
    mattytun wrote: »
    Ok, I've downloaded an "Add-on" for Firefox called "open link in new tab" and at the moment its working ok.

    Thanks for that. Works well. Right PITA before.
    As if target="_blank" is a security risk.

    I've been using target="_blank" for the past 25 years to stop users deviating from my websites when they click on a link. No complaints of security breaches so far.
  • One-Eye
    One-Eye Posts: 69,934 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    If target="_blank" is such a security risk then:

    1) Why do "Martin's Twitter" and "MSE's Twitter" and all the links therein on the RHS of the forum still use it a week after the change to the forum was implemented?

    2) Why have MSE not trawled through the forum and changed the links in every post created before 11am 03/10 to remove it?

    If you study the background on the theoretical vulnerability caused by target="_blank" then it is a massive overreaction to disable it. In security terms, if allowing members to post links on the forum is akin to walking down the middle of a motorway, then disabling target="_blank" is like only allowing you do it facing the oncoming traffic. It also appears to me that the theoretical vulnerability can be easily eliminated with a few lines of code so the usefulness of target="_blank" can be retained.
  • mattytun
    mattytun Posts: 13,920 Forumite
    Rampant Recycler Xmas Saver! Savvy Shopper! Energy Saving Champion
    thanks matty does it interfere with other sites/settings

    will give it a try

    No it is working ok at the moment.

    Ive only been using it on MSE so once i log out i just disable it;)
    Can't sleep, quit counting sheep and talk directly to the shepherd :cool:
  • Mista_C
    Mista_C Posts: 2,202 Forumite
    Part of the Furniture Combo Breaker
    If you really must have links open in a new tab then for now you can use the old skool method of holding down CTRL while clicking the link.
  • rugmaker
    rugmaker Posts: 395 Forumite
    Part of the Furniture 100 Posts
    Mista_C wrote: »
    If you really must have links open in a new tab then for now you can use the old skool method of holding down CTRL while clicking the link.

    There are various ways around it on a laptop or PC, but it's more dificult on a phone or tablet.

    It would also have been nice for MSE to tell us about the change in advance or at least respond promptly when it was reported as a fault. If the website for a bank or rail company had handled a change like this, they would doubtless have been panned for poor customer service.
  • esuhl
    esuhl Posts: 9,409 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    pate-ci0 wrote: »
    Here's an explanation of a security risk, to do with opening a link in a new tab, which may be the cause of the current situation:

    https://www.jitbit.com/alexblog/256-targetblank---the-most-underestimated-vulnerability-ever/

    Riiiight... So a malicious site could cause the previously opened MSE tab to redirect to a fake/malware/phishing site...?

    Have I understood that right...?

    Surely that would be due to bad coding in the web browser...? Is that right? Does it affect all browsers?
  • esuhl
    esuhl Posts: 9,409 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    100mg wrote: »
    I've been using target="_blank" for the past 25 years to stop users deviating from my websites when they click on a link. No complaints of security breaches so far.

    I'm no pro, I'd never heard of this issue before. Strange. It sounds like the kind of thing for which there would be a very quick/simple patch.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.8K Banking & Borrowing
  • 253K Reduce Debt & Boost Income
  • 453.5K Spending & Discounts
  • 243.8K Work, Benefits & Business
  • 598.6K Mortgages, Homes & Bills
  • 176.8K Life & Family
  • 257.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.