Cool (and frightening) trick that allows sending cursor movements from one browser to another with both having JS disabled.
More frightening stuff with CSS:
Is there a way to disable network requests made by CSS? I searched quickly and found nothing.
Pretty scary. Someone had also sent this to me. It’s always a cat and mouse game. This is yet another mitigation that needs to be shipped with torbrowser.
Btw, there is a bare-bones twitter front-end with minimal functionality (like invidio.us): https://nitter.net/davywtf/status/1124146339259002881
I’ve added a link to this thread on an idea for a workshop we we’d work on “insecurity demonstrations”. Basically to show proofs-of-concept of fragilities in modern devices in a simple enough manner for regular folks to understand the insecurity they may be exposed to. Find it here.