Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Would be great to add the options to disable Blur images. #46

Open
thezakman opened this issue Feb 8, 2023 · 2 comments
Open

Would be great to add the options to disable Blur images. #46

thezakman opened this issue Feb 8, 2023 · 2 comments
Labels
enhancement New feature or request

Comments

@thezakman
Copy link

Description

I think the addition of the blur cavas screenshot is great, but I think this should be optional.

@thezakman thezakman added the enhancement New feature or request label Feb 8, 2023
@thezakman
Copy link
Author

Any response from the Devs about this? @dxa4481 @dustin-decker @hxnyk @morph3

@dxa4481
Copy link
Contributor

dxa4481 commented Mar 1, 2023

Hey there. The concern is that user data ends up getting captured in BXSS payloads. When your payload fires on a local data scientist's jypiter notebook, and they load all the users up, you could end up with a screenshot with way more than just your user.

Pulling other user's data is almost always out of scope for bug bounty's, and it's also questionably from a privacy stand point. I gave a talk on this last year at Blackhat https://www.youtube.com/watch?v=qj0bre85DXY

So the short answer is we don't want to enable this feature as it may end up with a lot of data privacy issues. I think we're open to some creative alternatives, like maybe collecting and surfacing all the domains from URL's, or perhaps even a raw count of how many email addresses are on the page, without actually having them revealed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Development

No branches or pull requests

2 participants