Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This was one of those things that frustrated me so much that we ended building this natively into Orion browser (Tools menu -> Allow Copy & Paste). [1]

One of the joys of building your own browser.

[1] https://kagi.com/orion



Cheers for making Orion. I don't know how you guys managed to support Firefox and Chrome extensions (on iOS) but it's amazing and made moving from Android so much easier!


Just the sheer determination to build the best browser in the world :)


Brave has a "force paste" that I use now instead of Chrome and the linked plugin. I assume the motivation was the same. (What a*hole thinks blocking paste is reasonable??)

Good on you for solving this too. It's a nonsense bit of functionality.


It's always incapable product owners and business people who don't understand security but think they do.


The problem with orion browser is it is not opensource.


Why allow pages to disable copy & paste at all?


It's kind of a misfeature, but the non-evil idea was probably to provide hooks for customizing copy and paste (or other standard command functionality) in beneficial ways, for example seamlessly copying and pasting custom data formats between web apps, or between web and desktop apps.

It is a law of the web that any potentially beneficial browser feature will immediately be (mis)used in an abusive, user-hostile manner.


It's not about disabling it, it's about intercepting it by telling the browser that you're directly handling paste events and then doing nothing. The extensions just forces the browser default handler.


Sadly, I am not in that ecosystem :(


How would you rate the security posture of Orion compared to Chrome?


Well, there are apparently whole classes of JavaScript malware that Orion blocks but Google doesn't...


This is exactly what I was asking, not sure why my post was downvoted


Along what axis?


Size of security team? Mean time to patch actively exploited CVEs? Availability of source? Etc


Same as Safari in that regard, albeit with a much smaller team (we inherit upstream patches from the WebKit team and publish them regularly, sometimes even before Safari like in the case of patching iLeakage vulnerability).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: