Closed Bug 347289 Opened 13 years ago Closed 13 years ago
Bug 315536 comment 14 describes a "problem 2", which is then later suggested to be fixed using a notification box in bug 315536 comment 31. We should implement this notification box for all downloads that were *not* initiated by a user click. It would look like: [ Download %S from %S? [ Download ] [ Cancel ] ]
This would break a large percentage of software download sites, since many (including SourceForge) only start the download after you've been on a "your download will begin shortly" page for a few seconds. I don't see how this improves security unless we do this for *all* downloads (rather than just downloads not initiated by a user click). If I'm on an untrusted site, I'm not thinking "I better not click anywhere on this page, because if I do, the site might be able to silently put something in my downloads directory". I vote for wontfix in favor of what I've said on bug 249951.
*** This bug has been marked as a duplicate of 344267 ***
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.