back to article Internet Explorer tracks cursor even when minimised

A security researcher has published yet another reason not to use Internet Explorer for anything, under any circumstances: it can track your mouse cursor movements, even when it’s minimised. Affecting all versions newer than IE 6.0, and with no plans for a fix by Microsoft, the bug is demonstrated here (not being an IE user, …

COMMENTS

This topic is closed for new posts.

Page:

        1. dssf

          Re: Faecebook Next? @dssf

          GROW UP. You do not know me, and have no real need to go off on personal attacks when I didn't single you out as a person. Why do you think I need a shrink? Yes, I incorrectly spelled a word, but reasonable people go for the intent, not the minor spelling error. Disclaimer: I am guilty of occasionally making hints about a spelling error in a post, but I try to elicit humor, not negativity, since I despise bullies or those behaving as bullies.

          1. James O'Brien
            Stop

            Re: Faecebook Next? @dssf

            Down voted and survey says:

            While you may have initially started out with a valid point you, yourself, went above and beyond on the rantings about the voting here. While it may be that you make some valid points about the voting system here these points can also be looked at as this: Why make down voting (or any voting on ElReg) require a post about why the vote was posted? This basically negated the AC icon here and opens up a world of shit on those who may agree or disagree with a certain point. I'm not having it. Once you went on the attack to bitch and whine about being down voted you came across as a 12 year old having a temper tantrum. Your continued responses to this fact just serve to make you look like even more of a child.

            Who gives a shit about the ups and downs a persons particular account has? About the only thing I cared about recently was that 1000 post milestone that has taken me 5 sad years to accumulate. If you want to bitch about your totals heres something you can shoot for.

            "In total, your posts have been upvoted 847 times and downvoted 345 times."

            Read from it what you will but I see from that, that at least most of the crap I spew resonants with the local commentards and that most tend to like what I have to say. I would rather not be Barry Shitpeas where everyone hates me but loves reading the next pile of trash I spew out.

            Just my 2 cents.

        2. dssf

          Re: Faecebook Next? @dssf

          Now, i will give my first -1 JUST because you had the unctuous temerity to accuse me of going after a badge. I do NOT gie a fuck about the posting badge. I never had any say in its arrival, and i do not know how to turn it off. My posting count is well over 650, and when the badge arrived, i was over 600 or so. So, go give yourself a cold, self-aggrandizing shower.

          I rarely, if ever see people downvoted for calling facebook facefuck or other names.

          As an ac, you have the luxury of not being doenmodded every time you post. But, i do not post as ac for any reason, especially not for the purpose of criticizing anyone. And, i do not vendetra rate, either.

          So, keep the run-him-away downmods. Oming. When the management wakes up, if ever it gets around to changing hands, it might enhance the voting code go nullify malicious voding and weed out vicious downvoters. But, we shall see...

          1. James O'Brien
            Trollface

            Re: Faecebook Next? @dssf 17:25

            And yet you continue to bitch and moan about something which has worked very well for several years now. This is the last time Im feeding this troll but it does piss me off when someone is so thick headed to continue to act this way.

  1. Eddy Ito
    Facepalm

    Lovely

    So basically anyone using the accessibility on screen keyboard tool and IE is pretty much screwed when entering a password of any sort. I can see I'll be calling my aunt this evening to ask which browser she uses.

    1. ChrisC Silver badge

      Re: Lovely

      You might also want to ask her if her if she's ever moved or resized the onscreen keyboard window, and if the way she moves the mouse pointer over the window would give any clues as to which keys she's selecting. The demonstration page linked to in this article shows that IE doesn't capture mouse clicks, so the attacker would need to infer clicks from some signature behaviour in the position data. And AFAIK, IE doesn't allow a script to determine the position or size of another application window, so unless the onscreen keyboard has never been moved/resized then there's no way for the attacker to know for sure whether or not the pointer position corresponds to a position within the keyboard window, let alone which of the keys within that window it then corresponds to.

  2. J.G.Harston Silver badge

    Mouse cursor? This: -> _ is a cursor, a text input position indicator. This is a pointer.

    1. NomNomNom

      http://msdn.microsoft.com/en-us/library/system.windows.forms.cursor.aspx

    2. HAL4000
      Headmaster

      Downvote...

      ...for failing to properly deploy your pedant icon.

    3. Kubla Cant
      Headmaster

      @J.G.Harston

      Well, it's called a cursor in CSS and in such GUI APIs as I'm familiar with.

      The trouble with calling it a pointer is that "pointer" is normally used for a particular type of cursor, to distinguish it from text cursors, resize cursors, wait cursors and so forth. But you can call it whatever you like.

  3. RAMChYLD
    Flame

    "Although they see Redmond recapturing some market share thanks to the introduction of Windows 8 and Windows Phone 8"

    I cannot see how. Given that Windows Phone 8 is still pretty much as useful as a paperweight in many countries and Windows 8 is still getting flak over the Metro/Modern/whatever UI.

    1. Anonymous Coward
      Anonymous Coward

      Windows 8 is still getting flak

      Only on forums like this. Up to now I have seen 4 Win 8 laptops and 2 Win 8 phones brought into my office to have them connected to the wireless network (we don't give out the password) and the people who bought them have been surprisingly positive about it. I was expecting them to be asking if they could replace it with Win 7 but they don't want to.

      Small sample size of anecdotal evidence to be sure, but it seems to be popular with the people actually using it and not just slagging it off because of what they have read elsewhere

      1. Anonymous Coward
        Trollface

        Re: Windows 8 is still getting flak

        Of course it is popular with Microsoft employees!

        Or are you implying anyone else is using it by choice? And no, replacing TIFKAM with classic shell doesn't count as using windows 8.

        1. Hooksie

          Re: Windows 8 is still getting flak

          Yup. I have, as any commentard who has seen my rants will tell you, 3 machines all happily running Windows 8 and I wouldn't go back to Windows 7 if you paid me. In fact, currently at a client site using Windows XP and it's amazing to see how dated it has become. Like if you saw a picture of Maria Whittaker as she is now.

          Anyway, back to the 'debate', this supposed security flaw is, as others have pointed out, not a security flaw. There is not a chance in hell of anyone gaining any meaningful or useful information and certainly no chance of giving away any password information.

          Personally I've used Chrome for a few years now, pretty much since it came out, but all the tracking and tracing it does scares the crap out of me. Would you rather trust MS or Google? Tough question. But I have to say that since upgrading to Windows 8 I've found myself using IE again. It works fine, it's fast, doesn't crash and ive had no issues at all. This bullshit post and all the Linux dribblers have done nothing to convince me otherwise. I know Linux/UNIX is great and has its place but seriously, how many non technical people would have a shit clue what to do with it? By all means criticise when necessary and point out flaws where they exist but this is just bollocks scare mongering. I'm starting to think TheRegister was bought by an Apple owned company :-)

  4. JaitcH
    Thumb Down

    Internet Explorer? Oh, yes ...

    it's one of the things we remove when installing Windows, along with a whole lot of other fat ware.

    We practice safe(r) browsing.

    1. historymaker118
      Linux

      Re: Internet Explorer? Oh, yes ...

      I didn't think it was possible to fully remove IE from a windows machine? I would really appreciate some instructions on how to do this, because for now, I've just shoved it out of the way where my parents can't find it and have disguised firefox as IE so they don't complain about where the 'internet button' has gone.

      1. Hooksie
        Trollface

        Re: Internet Explorer? Oh, yes ...

        You're right, it isn't. He's lying. Or he doesn't know what the fuck he's talking about. I'm going to give him the benefit of the doubt and say it's the latter ;-)

  5. John Tserkezis

    I've given up on trying to get people off IE onto something else - anything else.

    Same with trying to get people to back up.

    You don't have to take my advice, but you lose the right to cry and whine about it after the fact.

  6. Anonymous Coward
    Anonymous Coward

    Touch screen?

    Does this work for touch screen use? Eg if one were to use an application to write with a stylus, could this thing capture the whole of the written text? If so, then definitely dodgy.

  7. Michael H.F. Wilkinson Silver badge
    Mushroom

    One more reason (as if I needed one) not to use IE

    <- Nuke it from space, it's the only way to be sure

  8. Anonymous Coward
    Anonymous Coward

    Shit happens when you make your browser your shell too. Who cares if you fuck over your customers as long as you're fucking up any chance of fair competition. Well, Fuckwits meet Karma.

  9. Anonymous Coward
    Anonymous Coward

    Could not get it too work for me.

    Key presses worked fine but would nto track my mouse.

  10. NomNomNom

    oh no some ad company might record a bunch of x and y coordinates!

  11. Crisp

    Exploits have become mainstream

    You know you're screwed when admen start exploiting browser vulnerabilities.

  12. Camilla Smythe

    Ah but....

    Consider those Banking, and other forms, where you have to pick three letters from your 'memorable' word from a drop down alphabetical list. The browser has already reported your screen resolution, font type and font size back to the 'mothership'....

    1. Colin Millar

      Re: Ah but....

      You shouldn't be running any other windows or tabs when you go to a banking logon page.

      Your bank's initial page shouldn't contain any uncontrolled links.

      The logon page should allow you to close the initial page behind it and should not contain any links at all other than those needed to actually log on.

      If your banking pages contain off-site links get a different bank - they are not serious about security.

  13. Anonymous Coward
    Anonymous Coward

    Doesn't track mouse movements on the extended screen!

    I can browse as much as I want and no mouse movements are being recorded.

    As soon as I move the mouse to the primary display, then you can see the mouse movements being tracked.

    Also, it doesn't show you what is being clicked and it doesn't show you what is being displayed on screen.

    1. Chemist

      "Doesn't track mouse movements on the extended screen!"

      It's a bug- you need to report that

    2. Pookietoo

      re: Doesn't track mouse movements on the extended screen!

      Probably just hasn't been coded to - I expect the info is there if you want to read it.

  14. Mark Allread

    If, in Windows 9

    .. they removed the metro start screen and put the tired old start menu back, there'd be a *lot* of people pissed off about that.

  15. Anonymous Coward
    Anonymous Coward

    Shame Firefox doesn't have this "feature"

    Because ad companies would get a lot of cock shapes from my mouse movements.

    Well, they wouldn't, because I use AdBlock Plus and NoScript, and indeed Ghostery.

    But.. ah, never mind.

  16. Colin Millar

    Extended screen

    It doesn't appear to track to the extended screen

    Also - loved this piece of advice

    "NB If you're not currently using Internet Explorer, then we suggest you view this page again with Internet Explorer"

  17. Anonymous Coward
    Anonymous Coward

    @ dssf

    Hang in there brother.

    1. dssf

      Re: @ dssf

      Thanks, :-)

      I slept it off. It is a new day. I will leave my posts visible, partly to knock myself in the head to remember to use fewer polarizing, inventive, (except, iexploDer, whic I first saw in IT around 1997, loked, and used when a fitting context arose) words. Otherwise, i will incur more negs faster than any positive recovery.

      Again, thanks.

  18. Anonymous Coward
    Coat

    His cursor was doing this while mobile doing this.

    With GPS, microphone, camera and motion sensing phones, IPV6, built in Webcams, Bluetooth, NearField, CCTV, ANPR etc we can be tracked to mm and that's just the "Visible" technology.

    I personally don't fret about it too much as I don't have a life worth watching but there are times when I wonder if tin foil covered safe houses free of data connections will spring up, areas with poor cell coverage will command a premium.

    Won't be long and Faraday cages and "alternative browsers" will be outlawed.

    And to the hoodie wearing teenagers you're just not thinking it through.

    Mines the one with your life path on a USB stick in the pocket.

  19. Anonymous Coward
    Anonymous Coward

    Potential Solution:

    Uninstall Javascript

Page:

This topic is closed for new posts.

Other stories you might like