← Back to team overview

ubuntu-phone team mailing list archive

Re: Reviews and bug reports

 

On Wed, 2014-12-17 at 18:34 -0500, Robert Schroll wrote:
> First off, although apps may have a support URL, it's not hyperlinked [2] and is therefore hard 
> to visit.

> [2] WTF!

https://bugs.launchpad.net/bugs/1350993

I'm not entirely sure if we should or shouldn't allow hypertext in the
text widget, or if maybe Unity8 should just linkify any URLs with a
regex. Allowing hypertext presents an interesting phishing attack
scenario, as one could have the text not match the URL at all, from
their scope, and handle the phishing URL directly from an accompanying
app with the scope. Granted the app/scope would be malware, and we'd
hopefully get it removed from the store quickly enough, but I think we
would want to limit the possibility of that being feasible for someone
to do, as well.




References