10 ms·
Please know that no one really cares. You must realise you cannot expect to consume our applications but only on your own terms. Theres no contract saying you s
by Ninn 8y ago
Please know that no one really cares. You must realise you cannot expect to consume our applications but only on your own terms. Theres no contract saying you should ONLY serve HTML on the web.
- Amezarak 8y agoI can't speak for gp, but the reason I whitelist Javascript is because the dozens of third party scripts pages load provide no benefits to me as a user and only waste my bandwidth and cpu while risking my security and privacy. Sometimes the first-party scripts do something useful and I enable them. That a simple document with embedded videos "needs" js to load at all is sheer lunacy. The modern web is a massive house of cards. I don't want to be uncivil but I find it very hard to understand how anyone thinks they're doing good work after they create a simple (and useful!) web document that requires javascript to load. If you're using Javascript to make a web application, fine, clearly there's no reasonable alternative. But if you need Javascript to produce a web document, what are you doing? I wonder how much more electricity is being consumed annually processing utterly pointless Javascript.
- chalupa-man 8y agoOne of the increasingly popular uses of JS is to save bandwidth. Using JS, you can ask the browser if the user is on a metered connection or an unlimited one, what their estimated bandwidth capacity is, what their real resolution is, and load appropriate assets (or conditionally load content). With JS disabled, a user on a pay-per-kilobyte 360x640 cellphone is going to get assets deemed acceptable on the manager's 1440p desktop. There are already quite a few websites where disabling JS more than doubles your bandwidth usage -- and sites that are only even usable in third world countries because of JS like this -- and that's going to increase as screen and media quality grow. Not to mention the huge accessibility benefits that can come from changing the way a site behaves (not just visually but in terms of things like tab and focus behaviour or separating components out) for disabled users. Doing that reliably and effectively for all content on all devices is much easier if you can identify the needs before downloading the content which means JS-loaded content and so it can come down to deciding whether to annoy NoScript users or disabled users.
- Amezarak 8y agoThat doubtless provides some reasonable bandwidth savings on certain media sites, but I'm pretty sure the whitelisting approach is going to come out far, far ahead in general, as most ads don't load and some Javascript assets are themselves megabytes in size. Also, IME, disabled users hate javascript. But my experience is limited to a few vision impaired folks.
- bunderbunder 8y agoWhy, if your goal is to save bandwidth, would you have the system default to loading the biggest assets when you can't ascertain these things, instead of loading the smallest ones? That said, given my experience of running the web with NoScript, I'd be surprised if those sites that double the usage when they can't detect these things come anywhere close to eating up all the bandwidth I'm saving by not loading auto-playing video ads.
- JoshMnem 8y agoIn general, one should serve HTML on the web unless you're doing something that requires JavaScript. JS is a big security/privacy risk. At the moment, I keep JS and CSS off by default on my main browsing profile, overriding it with umatrix when a site requires it and it looks useful enough to bother.
- shrimpx 8y agoThat's bezerk. You should turn off the CPU in your computer, too, and just use the screen and keyboard. The CPU is where all the security breaches happen.
- JoshMnem 8y agoThat's like saying that you shouldn't bother eating healthily because if you're really concerned about heart disease you should just have heart removal surgery.
- allover 8y agoIn general, one should consider the audience of the content, not NoScript users, in this case. > JS is a big security/privacy risk. No, 3rd party JS (and 3rd party cookies, JS regardless) allow you to be tracked. And ad-blockers deal with that. Blocking 1st party JS is of tenuous benefit w.r.t security/privacy.
- Amezarak 8y ago> Blocking 1st party JS is of tenuous benefit w.r.t security/privacy. Blocking all JS lets me click on any link fearlessly.
- arbie 8y agoWhat is your primary fear with JS enabled? Tracking/keylogging/cryptomining?
- JoshMnem 8y agoSometimes "3rd party" JS is served from within the page. Also many sites are hacked and will cloak the JS depending on how you visit the site. It's especially common with hacked WordPress sites.
- bunderbunder 8y agoI popped over to a different browser to take a peek. That's not an "application". It's static page with some embedded YouTube videos, and some hyperlinks. It just happens to be one where it takes about 5 seconds (on my computer) before the hyperlinks become clickable, for some reason. I do agree that there is no contract saying you should only serve HTML on the web. But still, you can do better than this.
- 9mit3t2m9h9a 8y agoLast time when nobody cared about a broken nest of security holes in the center of the Web, a small minority had organised a campaign to annoy people with complaints. I mean Mozilla's campaign asking users to send complaints to each and every webmaster writing IE5-only sites. It somewhat worked.
- specialist 8y agoI'm a true artist and no one understands my genius. Heathens!