12 ms·
A Javascript journey with only six characters
- kukx 10y agoWat https://www.destroyallsoftware.com/talks/wat https://www.destroyallsoftware.com/talks/wat
- thehesiod 10y agoI created an account just to thank you for that post, so funny :)
- amelius 10y agoI'm getting a browser security warning on the url on Android.
- deleted 10y ago[deleted]
- kyriakos 10y agothis is insane. someone should create a js obfuscator that converts human readable code to this.
- Normal_gaussian 10y agoIt is linked at the end of the article: http://www.jsfuck.com/ http://www.jsfuck.com/
- jbverschoor 10y agoWith some code you don't need to run it though an obfuscator for it to be obfuscated
- yomly 10y agothis would obviously be a fun thing to do, but I wonder how much larger the code will get via this means of obfuscating. Maybe space isn't a concern in your use case though...
- JJJollyjim 10y agoI imagine it could be largely mitigated by compression
- Centime 10y agoI have a "compression" feature for my jsfuck fork: http://centime.org/jsfsck/ http://centime.org/jsfsck/ only worth it for long enough code, but then the browser is having a lot of trouble parsing the obfuscated version... Still: "The js code of this page has been encoded (see source). Compression reduced it from 288k to 37k characters."
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- madflame991 10y agoThe title is incorrect; you need "!" and the only reason why I clicked on the article was that doing it without "!" would be a BIG deal. The title of the original article is "A Javascript journey with only six characters" and the topic has been posted/reposted and explained more times than I can count on HN
- Jazcash 10y agoOh sorry, how could I miss that :( Fixed it now
- tempodox 10y agoThis is an extreme demonstration of the validity of a delightfully snarky blog post by Robert Harper on how dynamic typing is actually static typing using a unitype: https://existentialtype.wordpress.com/2011/03/19/dynamic-languages-are-static-languages/ https://existentialtype.wordpress.com/2011/03/19/dynamic-lan... A string is a Boolean is a number is a function, and braindead conversions can happen without anyone noticing. How does one keep their sanity using a language like that?
- gloriousduke 10y agoWith something like flowtype.org.
- tempodox 10y agoGood answer. Of course, supplementing static typing after the fact only goes to show that it should have been built into the language to begin with.
- qwertyuiop924 10y agoKeep it straight in your head, and use strict comparison. Hey, at least when JS implicitly converts your types, it actually does type conversion, rather than merely casting them, so you often get what you want (looking at you, C).
- tempodox 10y agoAs for C, I have to contradict you. Implicit (numeric) type conversions do actual conversions (like char to int, or int to double; even pathological cases like pointer to what-counts-as-Boolean-in-C). The casts you are talking about must be explicit, and thereby are squarely the programmer's responsibility. Of course, a language that forces all conversions to be explicit is preferable.
- qwertyuiop924 10y agoI was pretty sure that char to int/int to char in addition was implicit...
- lell 10y agoReminds me a bit of the quest for alphanumeric shell code.
- qwertyuiop924 10y agoI'm a fan of Javascript. It has proper lambdas, true lexical scope, will soon have TCO, and is a really flexable language. But it's not without its warts, and this is one of the worst. Although it's sometimes fun to mess with, nonetheless. To see this taken to one of its logical extremes, check out If Hemmingway Wrote Javascript's entry for Douglas Adams: // Here I am, brain the size of a planet, and they ask me to write JavaScript... function kevinTheNumberMentioner(_){ l=[] /* mostly harmless --> */ with(l) { // sorry about all this, my babel fish has a headache today... for (ll=!+[]+!![];ll<_+(+!![]);ll++) { lll=+!![]; while(ll%++lll); // I've got this terrible pain in all the semicolons down my right hand side (ll==lll)&&push(ll); } forEach(alert); } // you're really not going to like this... return [!+[]+!+[]+!+[]+!+[]]+[!+[]+!+[]]; }
- digi_owl 10y agoThat reads like a close cousin of brainfuck...
- qwertyuiop924 10y agoexactly
- djsumdog 10y agoFor those of you too lazy to open up a Javascript console, it's a function that returns "42".
- qwertyuiop924 10y agoIt also alerts all the primes between 0 and its arg.
- frostymarvelous 10y agoFor those not in the know or too lazy to Google, that's "the answer to life the universe and everything"
- 10y ago
- keyle 10y agoI knew about these languages but I've never understood how they were made. This is a fun, fantastic article! These articles make me excited about technology. Even bad ones.
- mooveprince 10y agoOne more reason for the world to hate JavaScript ? :(
- thanatropism 10y agoIt's too bad that people were willing to ostracize Brendan Eich for not being a cookie-cutter silly-valley progressive. Oculus is facing that now. It's the new mccarthyism.
- GavinMcG 10y agoIt's hardly the new McCarthyism when there's no government force that leads the charge against private citizens, driving them to be unable to find any work in their field in the US. The public deciding that it doesn't want to support someone is an entirely different phenomenon. The public can still be wrong, of course, but there's no need to conflate the two situations.
- jessedhillon 10y agoThey're both the phenomenon of policing thought and coercing others to publicly profess, or at least acquiesce to, only blessed opinions. It hardly matters, to this point, whether the behavior is centralized or emergent.
- qwertyuiop924 10y agoWell, that's hardly true. I thought we'd established that JS in inferior to Lisp. ;-)
- samstave 10y agoYou forgot this: (
- qwertyuiop924 10y agoThat's only funny once.
- samstave 10y agoThen it gets frustrating; DAMMIT where the heck is it!!!
- catscratch 10y agoThis doesn't make me want to use JS. The power of JS is in two things, it's in every major browser and it doesn't completely suck. JS syntax kind of sucks. The power in JS is that it's dynamic and lets you send functions around, but defining functions is much uglier than defining a lambda in Ruby: -> {anything goes here} or ->(a,b,c) {anything goes here} The problem with Ruby is that you then have to .() the lambda vs. (), so that is more verbose than just calling the function. If browsers were to embrace a language that was more Ruby-like and less clunky than JS, I'm sure I'd use it more.
- zuck9 10y agoES6 lets you define functions like a => a * 2 Or (a, b, c) => a * b ^ c
- catscratch 10y agoThat's succinct, but less clear than the Ruby version, imo, as you don't have any scope indicators required for the function body. JS: let f = (a,b,c) => a * b ^ c; f(2,3,4); vs. Ruby: f = ->(a,b,c) { a * b ^ c } f.(2,3,4) Ruby's shorter and clearer. But, when you use the Ruby lambda more than once in the code, you lose the brevity advantage, because of the "extra" dot. But, in Ruby I use methods more than lambdas, which would be: def f(a,b,c) { a * b ^ c } f(2,3,4)
- JelteF 10y agoThe article does not explain how it gets the {}, which is used to get the Object constructor string. Other than that it's very clear.
- kukx 10y agoIt does, see the "fill" step: «So now we have acquired the following extra characters: c,o,v,(,),{,[,],}, .».
- JelteF 10y agoThose characters are only inside a string, not as executable code.
- softawre 10y agoBut you can execute strings...as it says in the article.
- JelteF 10y agoYes, but not at that point in the article yet...
- kukx 10y agoGood catch. It seems that the "Object" string doesn't provide any crucial characters for further steps; in this case the literal curly brackets aren't needed.
- Jazcash 10y agoYou're right. It's possible to use it later on but I've removed it as it doesn't make sense being at that point in the post chronologically. Thanks!
- shp0ngle 10y agoWhy do I feel like I have read this article a few years ago? I remember it, but it has 2016...
- JohnDotAwesome 10y agoBecause you did. I came to the comments wondering if this was a shameless ripoff of the original or a re-post from the same author.
- Jazcash 10y agoIf it's similar to another article, I'd love to see it. I wrote this over the last two days using only the sources noted at the bottom of the post.
- gry 10y agoPrevious HN context: https://news.ycombinator.com/item?id=11024511 https://news.ycombinator.com/item?id=11024511
- vacri 10y agoThose links are to generators, not easy-to-read long-form explanations.
- ricardobeat 10y agoI think the problem is your post reads like it's a discovery of your own, jsfuck and previous artwork are only hinted at the end.
- dwaltrip 10y agoThe style makes it easier to see how the approach works, and wouldn't say it implies the OP came up with the technique. It seems that explanatory articles of this sort often use this style, as it is a great way to get the idea across.
- GirlsCanCode 10y agoThe fact that eBay can't or won't fix the vulnerability this enables is disgusting.
- novaleaf 10y agoDoes anyone know a good sandboxing technology to execute user written javascript in a safe way? (like, on other user machines or on the server)? I have some ideas like "learn programming" that would benefit from this immensely.
- dougk16 10y agohttps://developers.google.com/caja/ https://developers.google.com/caja/ Used it a few years ago. It was a little finnicky to get working right but I was impressed at the time. No idea where the project is at nowadays.
- novaleaf 10y agoi saw caja, but it looks really complex, was hoping for something better these days :(
- AgentME 10y agoNote that caja doesn't protect against local denial-of-service attacks: user-written javascript executed with it could allocate tons of memory or run forever (`while(true){}`). This may or may not be a problem depending on your use-case. (If you're using caja for code written by mostly-trusted 3rd parties, or for one user's code only on their own machine, then it's not much of an issue. If you're serving code written by one user to another, then it could be a problem.)
- dougk16 10y agoHa, here's an old thread where I asked the caja developers about that exact scenario: https://groups.google.com/forum/#!topic/google-caja-discuss/RAi-hHiClRA https://groups.google.com/forum/#!topic/google-caja-discuss/... Some possible mitigations but I don't know if they ever implemented them.
- SomeHacker44 10y agoWhat about Node.js's `vm` module?
- Centime 10y agoWithout parenthesis (requires 8 characters though): http://centime.org/jsfsck/ http://centime.org/jsfsck/
- a_c 10y agoI don't see the point of a programming language allowing itself braining fucking its users(developer) for serious use
- atemerev 10y agoAll those idiosyncratic moments were taken into Javascript right from Perl. Perl can do this and much more. And Perl codebase is huge. Perl is used quite heavily at Amazon, Booking.com and Yahoo, among others. Say what you want about Perl, but it is fun and hacker-friendly. I enjoyed it for many years.
- kqr 10y agoIt's optimizing for writeability rather than readability.
- arundelo 10y agoIf you don't like JavaScript's type coercion rules, fair enough. But if you're criticizing the fact that you can write JavaScript programs with nothing but punctuation characters, remember that no-one ever does so except as a joke, and that you can do ridiculous stuff in most languages. (Try Googling "obfuscated $YOUR_FAVORITE_LANGUAGE".)
- sjclemmy 10y agoThis is quite timely. I was looking at a library the other day which had IIFEs preceded by '+'. I wondered what the purpose was. Now I know!
- fibo 10y agoWow, JavaScript is also an esoteric Language. I remember similar strange and interesting stuff in Perl, like the spaceship operator.
- eweise 10y agoSo glad I don't write in a "weird and wondeful language that lets us write some crazy code that's still valid"
- CiPHPerCoder 10y ago> Javascript is a weird and wondeful language that lets us write some crazy code Wondeful! A typo six words in.
- omnimus 10y agoWhy do you care?
- CiPHPerCoder 10y agoI thought it was an amusing parallel to the title.
- joshschreuder 10y agoI saw a similar video recently called Code Without Keywords which was quite interesting. https://www.youtube.com/watch?v=LG-ozmTnhdI https://www.youtube.com/watch?v=LG-ozmTnhdI
- pvdebbe 10y agoI sighed with relief that the characters were not emoji.
- tofupup 10y agoneat