Comments (5)
shouldnt this be reported as a security vulnerability instead of made as a normal issue?
from scratchaddons.
I remember that metadata of audio files (artists, year, etc.) is preserved when uploaded into a project, and anyone can see it by exporting and downloading the audio track from the project. I haven't checked if the same applies to images or SVGs.
We can't really do anything if that is the case, other than maybe make an addon that omits metadata from all uploads?
from scratchaddons.
Can you check?
from scratchaddons.
Can you check?
I uploaded (normally) a JPEG image with an author and copyright specified and the metadata was not present in the exported file.
I was able to get the metadata by decoding the base64 of the image in the SVG file when uploading it with the HD uploads addon, so this issue can be confirmed.
from scratchaddons.
This seems dangerous, given that Scratch is targeted at kids. The priority should always be user safety, so I think we should fix this ASAP.
We could also consider adding a separate addon that removes metadata from sounds and maybe even existing images.
from scratchaddons.
Related Issues (20)
- Get a notification when someone enters an online game HOT 4
- Use black text and icons on orange backgrounds HOT 9
- Use blue as the accent color in light mode HOT 2
- Scratch adding refuses to load in Orion both mobile and desktop HOT 10
- Customize Home Screen HOT 1
- Make author names in forum quotes clickable HOT 12
- Audio fine tuning HOT 4
- Multi-select sprites and assets HOT 2
- Change the color of the extension UI HOT 5
- `hide-backpack`: impossible to drop in the backpack HOT 2
- Popup and settings page should know if the browser is unsupported HOT 1
- `addon.tab.direction` sometimes fails
- Make `safeMsg` a module instead of a function parameter
- Custom extension webpage CSS HOT 1
- Variable Manager Upgrade HOT 9
- "Enhanced full screen" (`fullscreen`) makes stage blurry (inconsistent canvas size)
- Mobile/Touch Tag HOT 2
- An AI assistant HOT 18
- Max list safe length too high in `variable-manager` HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from scratchaddons.