@jzb @Discourse Why do browsers allow code received from web sites to do that? I mean, sure, the sites shouldn’t try to do it either, but also the browser should be easily configurable to not let keys be redirected if the user doesn’t want them to be (and maybe the browser should ship with a default configuration that protects certain key commands).