Comment by Vortigaunt

3 months ago

Thankfully this shouldn't become a large problem, because websites simply don't load that quick

They load in the background. Look at the second video attempting to attack Slack. Look closely at the first tab in the top left corner, you can see that it is loading and eventually settles on Slack before the victim clicks the button. The attacker website has a delay on the click button to allow it to finish.

It could be preloaded

  • I understood GP's joke, but I don't understand yours.

    • Neither are a joke.

      The exploit requires pages to load instantly. The first person was saying it usually takes a few hundred ms to load a page (at least). The second person points out that you can load the page in the background so it is in the local browser cache already, in which case loading is near instant.

      2 replies →