Slashdot Mirror


Internet Explorer Bug Leaks Whatever You Type In the Address Bar (arstechnica.com)

The latest version of Internet Explorer has a bug that leaks the addresses, search terms, or any other text typed into the address bar. The flaw was disclosed Tuesday by security researcher Manual Caballero. Ars Technica reports: The bug allows any currently visited website to view any text entered into the address bar as soon as the user hits enter. The technique can expose sensitive information a user didn't intend to be viewed by remote websites, including the Web address the user is about to visit. The hack can also expose search queries, since IE allows them to be typed into the address bar and then retrieved from Bing or other search services. The proof-of-concept makes it transparent that the attacking website is viewing the entered text. The hack, however can easily be modified to make the information theft completely stealthy. A proof-of-concept site shows the exploit in action.

99 comments

  1. Internet Explorer? by DontBeAMoran · · Score: 1

    Haven't Microsoft users switched to Edge by now?

    --
    #DeleteFacebook
    1. Re:Internet Explorer? by Zaelath · · Score: 2

      There's still a lot of shit that works in IE but not in Edge...

    2. Re:Internet Explorer? by kilodelta · · Score: 1

      I rarely if ever use Edge.

    3. Re:Internet Explorer? by hcs_$reboot · · Score: 1

      You used it at least once, to download FF or Chrome.

      --
      Slashdot, fix the reply notifications... You won't get away with it...
    4. Re:Internet Explorer? by TheEden · · Score: 1

      In Edge leaking whatever user types is probably a feature, not bug.

    5. Re: Internet Explorer? by Anonymous Coward · · Score: 0

      Monkeyshit Corp is crawling with ugly smelly shitty hindu-chimps. That alone is the root cause of all troubles.

    6. Re:Internet Explorer? by quonset · · Score: 1

      You don't have to. IE could have been used as I did for my dad when he got his W10 system and I installed FF.

      Not everything is about Edge. Where there's a will, there's a way.

    7. Re:Internet Explorer? by ArmoredDragon · · Score: 1

      So far there are approximately 6 people in the world who use Edge.

    8. Re:Internet Explorer? by s_p_oneil · · Score: 1

      That's not true at all. Granted, the only reason it's not true is that there are more than 6 people in the world with Windows 10 who can't figure out how to either:

      1) Click the start button and type the letters "i" and then "e".

      2) Type "Chrome" or "Firefox" into Edge's search bar.

    9. Re:Internet Explorer? by s_p_oneil · · Score: 1

      Correction: You really only need to type the letter "i" to have Internet Explorer show up at the top of the list (unless you've installed a bunch of other stuff that starts with an "i").

    10. Re: Internet Explorer? by nazsco · · Score: 1

      they moved to chrome, which happily send that information to Google only. much secure.

      even localhost urls are sent to make sure the site is "safe" . much secure.

    11. Re:Internet Explorer? by Slashdot+Junky · · Score: 1

      Plus, in my opinion, Edge makes for horrible user-experience.

      --
      .
      Landfill Mining Co.
      Managing the (Un)natural Resources of Tomorrow
    12. Re:Internet Explorer? by hackel · · Score: 1

      Yeah, what does "latest version" even mean? I thought they had finally stopped development on that garbage fire. Is that not the case? Or did they introduce this bug in a security fix? (Sadly wouldn't surprise me!)

  2. RUSSIANS! HACKED SLASHDONG!!! by Anonymous Coward · · Score: 0

    Yessir, now that I'm a helpless, hopeless RUSSOPHOBE, an ADDICT of blaming the EEEEVVVVIIILLL Rooskies, let's blame this "bug" on the RUSSIANS!
     
    --BeauHD, esq.

  3. And worse, if you type a local hostname... by Anonymous Coward · · Score: 1

    like we have like "jenkins" for our CI server, but instead of doing a DNS lookup for that that returns an IP address since we have a properly setup search domain, it redirects us to a Bing search for jenkins. Microsoft really still doesn't grok DNS.

    1. Re:And worse, if you type a local hostname... by lucm · · Score: 1

      All browsers are like that. Chrome is particularly annoying since they insist on hiding the protocol, it won't even figure out it's an ip address and will search instead.

      --
      lucm, indeed.
    2. Re:And worse, if you type a local hostname... by Anonymous Coward · · Score: 0

      You can turn that off obviously.

    3. Re: And worse, if you type a local hostname... by Anonymous Coward · · Score: 0

      That drives me nuts. We use a lot of one word hostnames, and instead of showing us the website, IE sends the hostname to Microsoft.

    4. Re:And worse, if you type a local hostname... by lucm · · Score: 1

      You can turn that off obviously.

      How?

      --
      lucm, indeed.
    5. Re: And worse, if you type a local hostname... by Anonymous Coward · · Score: 0

      Maybe because all these clowns have a mandate to redirect you to their search. Things you don't search for they don't know about, so search for everything even though it's obvious.

      A search = data collected. Data collected = money. Math.

    6. Re:And worse, if you type a local hostname... by Aighearach · · Score: 1

      Try it with a dot on the end.

      And remember, a domain name and a URI are different things.

    7. Re: And worse, if you type a local hostname... by Anonymous Coward · · Score: 1

      Chrome can be taught. If you type something to the top bar which can be a url as well, chrome will suggest the exact typing twice, but with different icons in front. A magnifying icon will do a search. A paper icon will try to open the url directly. If you choose the url, the next time you do that, the default action will be the url again. If you want a search instead, you can select the magnifying icon from suggestions (this generally works: if you want to search for a url, instead of opening it).

    8. Re: And worse, if you type a local hostname... by Anonymous Coward · · Score: 0

      I love AI ... it makes life so much easier for stuff like this.

    9. Re:And worse, if you type a local hostname... by Anonymous Coward · · Score: 0

      You can turn that off obviously.

      How?

      In Internet Explorer, go to:

      Internet Options > Advanced
      Go to an intranet site for a single word entry in the Address bar.

      You're welcome :)

    10. Re: And worse, if you type a local hostname... by Anonymous Coward · · Score: 0

      That drives me nuts. We use a lot of one word hostnames, and instead of showing us the website, IE sends the hostname to Microsoft.

      In Internet Explorer, go to:

      Internet Options > Advanced > Browsing
      Go to an intranet site for a single word entry in the Address bar.

      You're welcome :)

    11. Re: And worse, if you type a local hostname... by cyber-vandal · · Score: 1

      I love you

    12. Re:And worse, if you type a local hostname... by Anonymous Coward · · Score: 0

      In Firefox at least that doesn't work. Only prefixing it with http:// works. But that is kind of more work than writing out the domain for most I guess...

  4. All browsers by Anonymous Coward · · Score: 0

    Don't all browsers (Chrome, MSIE, Firefox) have this problem? The default search provider gets whatever text you type in the URL bar.

    1. Re:All browsers by Anonymous Coward · · Score: 0

      You missed the point. Hint: Try typing something that won't get redirected to the search provider.

    2. Re:All browsers by omnichad · · Score: 4, Informative

      And so does whatever web site you were already on when you pressed enter. That's the difference. For some reason, they update the JavaScript location object before actually navigating.

    3. Re:All browsers by Anonymous Coward · · Score: 0

      Prefetching.

    4. Re:All browsers by hcs_$reboot · · Score: 1

      Incompetence?

      --
      Slashdot, fix the reply notifications... You won't get away with it...
  5. More of the same by lucm · · Score: 2

    Yet another feature of a major browser that doesn't work on Firefox. I hope this will get resolved when they release that unified search/address bar.

    --
    lucm, indeed.
    1. Re:More of the same by Aighearach · · Score: 1

      I dunno, I already have an integrated search/address bar. You can configure it that way in about:config.

      If you really want to be bug-compatible with IE on this one, surely there is an extension out by now for it? We can have whatever features we want, they don't have to all be good ones.

  6. Irrelevancies aside, SW non-freedom is the issue by jbn-o · · Score: 2

    Is this some question rooted in making sure future privacy leaks happen faster, in a more standards-compliant way, with a different web rendering engine, or some other technocratic detail that tries to obscure the underlying non-freedom problem?

    Since when would the non-free Edge browser be more trustworthy than the non-free Internet Explorer browser?

    The problem is the lack of software freedom; even users skilled and willing to help themselves and others fix the problem are not given permission to know what proprietary software does (whether intentionally or by mistake). So after years of people using Windows (a known security leaky proprietary OS written by an organization that partners with spies like the NSA) more problems arise with Microsoft Internet Explorer (an apparently security leaky proprietary browser). Proprietary software users must either switch to a free software OS and run free software on that, or wait for a proprietor they can't trust to issue a fix.

  7. That's fine by hcs_$reboot · · Score: 1

    All the three IE users have been warned.

    --
    Slashdot, fix the reply notifications... You won't get away with it...
    1. Re:That's fine by Anonymous Coward · · Score: 0

      I'm on Windows Vista you insensitive clod.

    2. Re:That's fine by jordanjay29 · · Score: 1

      Doesn't Lynx still work with Vista?

    3. Re:That's fine by Anonymous Coward · · Score: 0

      I telnet to port 80 you insensitive clod

  8. Re: Irrelevancies aside, SW non-freedom is the iss by Anonymous Coward · · Score: 0

    So how is Chrome or Safari any more 'Free' than I.E. or Edge?

    Everybody always disses Mozilla so we are not supposed to mention Firefox or Seamonkey.

  9. Every website and piece of software ever. by Anonymous Coward · · Score: 0

    Whatever you write goes into the system. Every keystroke into a text box is recorded.

  10. Re: Irrelevancies aside, SW non-freedom is the iss by Anonymous Coward · · Score: 0

    Hes right. Like it or not. Chrome and Firefox release all or most code.

  11. Headline reads like something from The Onion by AdamStarks · · Score: 1

    "New spoon has throws soup back into your face"
    "Cat sues owner for pooping in its litter box"
    "Internet Explorer leaks your address bar"

  12. Commodore 64 by Neo-Rio-101 · · Score: 1

    I tip my hat to the C64 background colours!

    --
    READY.
    PRINT ""+-0
    1. Re:Commodore 64 by Anonymous Coward · · Score: 0

      +1

      It's a very calming colour combination.

  13. Let's address the elephant in the room by blind+biker · · Score: 5, Informative

    More than two days of static Slashdot. Can't we have a headline about that shit?

    --
    "The agriculture ministry is not in charge of Gundam" - Japanese ministry official.
    1. Re:Let's address the elephant in the room by Tablizer · · Score: 1

      Why always blame Republicans?

    2. Re: Let's address the elephant in the room by Anonymous Coward · · Score: 0

      Soylent news is always an option. It uses old Slashdot code. I check it occasionally

    3. Re:Let's address the elephant in the room by phantomfive · · Score: 1

      Don't worry! They have NOT leaked your social security number and credit card # out through the IE address bar. Definitely not that.

      --
      "First they came for the slanderers and i said nothing."
    4. Re:Let's address the elephant in the room by phantomfive · · Score: 1

      Why not always blame Republicans? Trump did it.

      --
      "First they came for the slanderers and i said nothing."
    5. Re: Let's address the elephant in the room by Anonymous Coward · · Score: 0

      Can you change the color scheme? Those red headers suck.

    6. Re:Let's address the elephant in the room by rastos1 · · Score: 2

      Yes, we can. Head to the firehose and vote it up.

    7. Re:Let's address the elephant in the room by hcs_$reboot · · Score: 1

      You'll get a tweet very soon.

      --
      Slashdot, fix the reply notifications... You won't get away with it...
    8. Re: Let's address the elephant in the room by Coniptor · · Score: 0

      That's what Stylish is for!

    9. Re: Let's address the elephant in the room by Anonymous Coward · · Score: 0

      Don't use stylish, it has been bought. Use stylus instead.

    10. Re: Let's address the elephant in the room by ElizabethGreene · · Score: 1

      Someone mentioned this in the @slashdot twitter feed. It's actually really good. The SNR looks a lot better there. Thanks to the Anon that mentioned it. +1

    11. Re:Let's address the elephant in the room by CaptainDork · · Score: 1

      Yes. We're seasoned nerds who matter.

      We are capable of understanding an explanation.

      --
      It little behooves the best of us to comment on the rest of us.
    12. Re:Let's address the elephant in the room by Quirkz · · Score: 1

      Yes. We're seasoned nerds who matter. We are capable of understanding an explanation.

      Hell, I bet half of us could have fixed the problem, too.

    13. Re:Let's address the elephant in the room by CaptainDork · · Score: 1

      I think you're right.

      My motivation for being here is to read the comments by people who are much closer to an issue and much more informed than I am. /. should maybe tap into that.

      --
      It little behooves the best of us to comment on the rest of us.
    14. Re: Let's address the elephant in the room by Coniptor · · Score: 0

      From what version forward if you know?

  14. Oh, this ain't good... by QuietLagoon · · Score: 1

    But riddle me this... shouldn't Microsoft by now have developed some manner of understanding of how to write software, so that these things Don't Happen?

    1. Re:Oh, this ain't good... by Anonymous Coward · · Score: 0

      Riddle me this: Firefox has zero security patches now? Safari? Chrome? Are you a fucking moron? Only one of these questions is answered in a yes. Guess which one.

    2. Re:Oh, this ain't good... by Anonymous Coward · · Score: 0

      Guess you forgot about all the fun open sores things like heartbleed eh? Or things like this? https://www.geek.com/news/majo...

    3. Re:Oh, this ain't good... by darth.hunterix · · Score: 1

      Sure they did. They just try to leak as much user's data as possible, so this count as huge success. Or, since it's M$ we're talking about, suckcess.

      --
      What is best in life? Hot water, good dentishtry and shoft lavatory paper.
  15. Are we no longer a community? by QuietLagoon · · Score: 3

    Mod up this parent. I mean, really, WTF. This is /. not some social media site. We care about the site. And now, all of a sudden, we are being kept in the dark....

    1. Re:Are we no longer a community? by Anonymous Coward · · Score: 0

      As a longtime reader, I also would love to see a story explaining the downtime.

    2. Re:Are we no longer a community? by bobstreo · · Score: 4, Informative

      As a longtime reader, I also would love to see a story explaining the downtime.

      There is an article describing the issues at:

      https://www.theregister.co.uk/...

      I don't know why they didn't bother putting out an article describing the issues. I was getting VERY tired of 503s...

    3. Re:Are we no longer a community? by deviated_prevert · · Score: 2
      Fried servers. Sounds like they were being hosted somewhere like in a cheap back room off the local Burger King and were having issues with over heating power supplies. LOL They say they are looking for a new service provider.

      SourceForge was acquired alongside its nerd news discussion board Slashdot by finance, business and technology service BizX in 2016. The duo of websites have suffered outages in the past: in 2015, "filesystem corruption" on the Slashdot Media storage platform took out SourceForge for days.

      "We recognize there have always been issues with SourceForge and Slashdot, both with our current provider and within the infrastructure," Abbott told us.

      "As a result we had already decided to fund a complete rebuild of hardware and infrastructure with a new provider. We have the hardware on hand and are at the final stages of negotiations with the new provider."

      --
      This message was not sent from an iPhone because Peter Sellers really was a deviated prevert without a dime for the call
    4. Re:Are we no longer a community? by rastos1 · · Score: 3, Interesting

      If you care, head to the firehose and mod up the relevant entry.

  16. Re:Irrelevancies aside, SW non-freedom is the issu by AC-x · · Score: 2

    It's been over 25 years and FOSS hasn't solved the issue of computer security either; Open source browsers and OSs also require regular security patches.

  17. Who's this Manual Caballero by Anonymous Coward · · Score: 0

    Is he related Automatic Caballero?

  18. Re: Irrelevancies aside, SW non-freedom is the iss by Anonymous Coward · · Score: 1

    "Many eyes make all bugs shallow" was pretty much debunked when OpenSSH was breached a few years ago. The code was open but only 4 eyes were looking at it.

    For as large as the OSS crowd might be the OSS code base is many times larger and most people are drawn to the latest hotness like so many moths. The reason OSS security gets broken is because the devs are busy building automatic Jenga-robots or self driving boondoggles with GPUs. And why shouldn't they? They're not paid staff, that's the whole point.

  19. Re: Irrelevancies aside, SW non-freedom is the iss by Aighearach · · Score: 5, Insightful

    The argument was never, "If you build it, they will all turn their eyes towards it checking for bugs."

    The idea is that if you know you have a bug, because you use the software, and there is only the programmer at some company that is even allowed to look at the code, then they might not fix it, and they might not even have time or interest to try. Hard problems are often going to receive (if you're lucky) a work-around unless you're paying extra to get it fixed. The same situation with free software, the worse the problem is the more people are looking at it, and the easier it is to solve.

    There was never anything about fixing bugs before you know about them because free software is magic. That part you made up yourself.

    OSS security isn't broken, it is powering most of the infrastructure. But that isn't in the news, because "trains ran on time, 700 days uptime" isn't news.

  20. He's right by Anonymous Coward · · Score: 0

    These people just got off of DOS.

  21. Remove Explorer Solution by Anonymous Coward · · Score: 0

    I know, remove the explorer.

    Microsoft explorer leak drama aside, the 404 error system along with reading the /var/syslog does setup a stealth communications system for those whom grep the logs.

    I can't be the only idiot out there who's typed a big url... say ..

    http://dailycaller.com/2017/09/27/exclusive-chelsea-clintons-best-friends-defense-company-got-11-mil-in-contracts-but-doesnt-have-federal-security-clearance/

    SO say I see a TYPO on that page and I want to tell the sysop. PRETEND THE WORD IS "Grule" should be "Girl" I would hit the URL

    http://dailycaller.com/2017/09/27/exclusive-chelsea-clintons-best-friends-defense-company-got-11-mil-in-contracts-but-doesnt-have-federal-security-clearance/Hey-you-fux-fix-the-typo-grule-should-be-girl

    I enter that three times. (So you get three entries in the log) I could put a marker like -=[ MARK ]=-hey-you-fux-fix-the-typo /or-daves-not-here-bring-the-stuff

    If you don't do systems admin you probably have just had this tutor fly right over your poor head.

    404 eRRoR bitchez

  22. Address bars are for addresses. by nuckfuts · · Score: 2

    I can't stand it when browsers try to turn what I type in the address bar into a search. First thing I do is turn that crap off. So whether it's Internet Explorer or not, the only thing "leaking" from my address bar is the address I typed.

    1. Re:Address bars are for addresses. by Anonymous Coward · · Score: 0

      How is the address of the next page you are visiting any less important than you typing "cat pics" for a search?

  23. Awesome by easyTree · · Score: 1

    This is way better than the bugs IE6 used to have, 'back in the day.'

  24. Testing in progress? by Anonymous Coward · · Score: 0

    Wouldn't it be terrible, if such innocent flaws in a browser in reality were to be designed to enable experimentation and testing by the power that be, for having a secondary range of software, that scoops up such data from time to time. :| The kind of software that a government spy agency (or maybe even the police/military) might use, to keep collecting such personal data on demand for testing purposes.

  25. huh? by Anonymous Coward · · Score: 0

    What's an 'internet explorer' ?

    1. Re:huh? by Anonymous Coward · · Score: 0

      What's an 'internet explorer' ?

      A proprietary tool by MS which is used to explore the internet except the dark web.

    2. Re:huh? by Anonymous Coward · · Score: 0

      Also known as the Microsoft Virus Deployment Wizard.

  26. first thing I test with any new browser by Anonymous Coward · · Score: 0

    This is the first thing I test with any new browser:

    (1) type a short word into the search bar, and
    (2) type a long random string followed by .com.

    If either one returns anything other than a DNS error, then it's time to go digging in the settings and turn off whatever auto-search nonsense they've enabled.

    FWIW, most ISPs use DNS hijacking by default, but they'll let you call and opt-out (some let you do it via your account settings web page).
    Note: The opt-out only applies to your current MAC address, so so you'll have to remember to tell them to opt-out of DNS hijacking if your old cablemodem dies.

  27. Re: Irrelevancies aside, SW non-freedom is the is by Zero__Kelvin · · Score: 1

    Debunked isn't the way you spell pro ed. You can't identify bugs that were only identified and fixed BECAUSE it was open source and claim what you are claiming.

    --
    Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
  28. What??? by MerlTurkin · · Score: 1

    People STILL use that POS???

  29. Re: Irrelevancies aside, SW non-freedom is the is by cyber-vandal · · Score: 1

    You can look at the source fuckwit thatâ(TM)s how.

  30. Re: Irrelevancies aside, SW non-freedom is the is by cyber-vandal · · Score: 1

    Like Heartbleed?

  31. Re: Irrelevancies aside, SW non-freedom is the is by espenskaufel · · Score: 1

    So this is why Linux desktop is awesome and without bugs?

  32. Re: Irrelevancies aside, SW non-freedom is the iss by Anonymous Coward · · Score: 0

    > The idea is that if you know you have a bug, because you use the software, and there is only the programmer at some company that is even allowed to look at the code, then they might not fix it, and they might not even have time or interest to try

    Holy shit, are you for real?

    That's always been my argument *against* open source software. If you find a legitimate bug in closed source software you've actually paid for, the company that produced said software is on the hook to get it fixed; they have a financial incentive to do it, and it doesn't matter if one guy worked on that part of the program or a whole squadron. If it's truly broken, it'll get fixed.

    OTOH, if I'm using some open source software and find a serious bug, it might've been created by someone who writes software on the side, as a hobby, while he's got a real 9-5 job that's keeping him from dedicating serious cycles to his hobby project. There's no financial incentive for that guy to fix the bug, and in fact, since the source is public, the response is often going to be, fix it yourself and submit the fix, or find someone who can fix it for you.

  33. Re: Irrelevancies aside, SW non-freedom is the is by Anonymous Coward · · Score: 0

    Underrated comment. Wish I had mod points today.

  34. Re: Irrelevancies aside, SW non-freedom is the iss by epine · · Score: 1

    "Many eyes make all bugs shallow" was pretty much debunked when OpenSSH was breached a few years ago.

    It any maxim this pithy, language is being used in a special register where the "modulo" term is user supplied—if the user has the wits and can ass himself to do so.

    There are so many things you got wrong here, do I need to strip gold stars off your chest on both sides of this equation?

    First off, the OpenSSH bug was shallow, right from the get go, to any competent pair of eyes.

    Second, cryptographic software is notorious for having failure modes that require exotic instrumentation and extreme wonk vigilance to so much as notice, from any perspective outside the black box.

    The cryptographic PRNG is Exhibit A in defying external validation checks. If the cryptographic protocol exchanges random values, is your randomness compromised? Somebody else's cipher, enciphering with a key you don't know, actively leaking vital state from your most precious host (though at a fairly low bit rate) is indistinguishable from true pseudo-randomness, by GRAS convention, in anything under 2^128 operations.

    Third, any discovered ability to debug cryptographic software from the black box end-user perspective is almost universally regarded as itself being a bug, not a feature.

    The truly ridiculous thing about the OpenSSH story is that everyone competent already knew that changes to this part of the system required explicit eyeball recruitment.

    I'm a more competent driver than many other drivers in the parameters I personally care about (they might say the same, and also be correct). They say in chess that experts only see the good moves. Well, on the road, this "good move" filter should be considered hazardous. Most of my worst driving errors—the ones I've learned to notice—are where I simply fail to see that another driver might choose to push the lynchpin pawn of his or her king protection fortress. In chess, that leads to certain victory for the other side. On the road, that leads to exchanging paint or a fender bender, and contentious litigation over cause, a state of heated affairs one would rarely list under "certain victory". Therefore the wary driver should make a serious effort to tamp down any presumption of competence from anyone else. This is the hardest of driving skills to master. You're basically telling your mirror neurons to go to hell (there goes any presumption of multitasking), because the other side of the mirror is a certifiably crazy place.

    I assume this is what happened in the OpenSSH saga. The original competent developers failed to put flags in the comments in all the right places to mandate extra eyeball review, because they simply couldn't comprehend that anyone would gain a commit bit to edit such a module and not already know this.

    If my view is true, then one could say that OpenSSH was in fact hoist by the extreme shallowness of the risk posed, to the degree that the competent eyeballs failed to even imagine a dunce whose eyeballs who couldn't see it (they should, however, be roundly slapped for failing to conceive of a dunce whose vision was perfectly fine until impaired by a copious application of NSA grease, but with less than full decapitation mustard, as this threat vector remained mildly hypothetical prior to the horrific Snowden dump).

    Overall score—way to not understand how maxims work.

    I do grant that this maxim is far from perfect. Even on day one, it was properly understood as somewhat aspirational in tone, and as having a legitimate counter-propaganda mandate, because the reverse opinion (widely held) was even more wrong.

  35. Re: Irrelevancies aside, SW non-freedom is the is by that+this+is+not+und · · Score: 1

    And you then submit your patches where??

  36. Nothing New by Anonymous Coward · · Score: 0

    Web Analytics has been capturing this data for the past 10-15 years, this is nothing new, its not a bug, its a feature everyone uses for web analytics

  37. Re: Irrelevancies aside, SW non-freedom is the is by Aighearach · · Score: 1

    Exactly. Fixed almost instantly. As soon as the bug was in the news, there was also an open solution in the news. When the eyes turned to the bug, it became shallow. And not before that, of course.

  38. Now you know by Anonymous Coward · · Score: 0

    And THAT is why I use Chrome for surfing porn!!!

  39. Re: Irrelevancies aside, SW non-freedom is the is by cyber-vandal · · Score: 1

    In existence for how many years though?

  40. Re: Irrelevancies aside, SW non-freedom is the is by Aighearach · · Score: 1

    That's not on topic, you're just burbling words and hoping somehow it might add up to a point.

    Do try to comprehend words before replying to them.

  41. Re: Irrelevancies aside, SW non-freedom is the is by cyber-vandal · · Score: 1

    https://en.wikipedia.org/wiki/.... Now off you fuck, there's a good boy.

  42. Re: Irrelevancies aside, SW non-freedom is the is by Aighearach · · Score: 1

    Sorry little boy, you were born yesterday and you didn't play nice so you were stupid and ignored too. When you've been here as long as I have, you don't care what idiot new users blather about.