5 ms·
It's quite incredible how the web managed to get along with such a janky sandbox model. It's a very important thing that users trust their browser and won't he
by obl 8y ago
It's quite incredible how the web managed to get along with such a janky sandbox model.
It's a very important thing that users trust their browser and won't hesitate a second to enter an unknown URL. They see "going to a webpage" as the equivalent to looking at a poster in the street, not eating candy provided by a random stranger.
Eroding this trust would ruin it for everyone, even well behaved static websites without javascript.
Maybe it's time to reconsider giving the same execution rights to gmail and unknown web pages ?
- pjc50 8y agoThe key thing is differentiating one set of pages from another set of pages - putting security boundaries into a hypertext system that was originally designed to allow mixing resources from different sources.
- simion314 8y agoI use a private window for banking/paypal , I don't trust the extensions or the other tabs so for this cases I get more security.
- felix_nagaand 8y agoThat hardly helps. For true security devote a device purely to banking. Preferably a diskless device running an updated live CD on a security oriented distro with no rewritable storage attached connecting out over a VPN through an equally dedicated firewalled router. Then you're just left to worry about your bioses getting infected off an unpatched or 0d exploit.
- r3bl 8y agoHe identified his threat model (other tabs + addons doing something shady) and made a security assessment based off of it. You're here bullshitting that he needs "true security" like he's dealing with APTs trying to access his bank account. He's not. He's concerned about other tabs + addons, and private browsing mode is a solution with the slightest friction for his threat model. Please, in the future, try making security assessments based on the actual threat model. EDIT: "threat" instead of "thread".
- seba_dos1 8y agoThis was pretty confusing to read until it came to my mind that "threat model" exists :)
- simion314 8y agoIf there were a big target on my back I would do that, but since I am running Linux, I am not a rich person or have an important job I assume that I will be attacked by regular malware and not skilled hackers.
- tzahola 8y agoSorry, but we need a Turing-complete language for ads and tracking. Preferably with JITting, and unfettered access to the GPU and other misc. peripherals like GPS, webcam, etc. In return you get free cat videos. You’re welcome.
- kevin_thibedeau 8y agoNo. The server just needs to send over an image and log the IP of the requestor for reconciliation at the end of the month.
- workinthehead 8y agoThe really ironic thing is trying to decide (before the internet was ever a thing, say 50 years ago) which of the 2 scenarios is more dystopian.
- datenwolf 8y ago…and with unfettered access to USB devices. WebUSB my ass.
- philipwhiuk 8y agoHow else are we going to tailor our adverts based on the music on your iPod Shuffle?
- WorkLifeBalance 8y agoDo you want to reinforce established monopolies? Because I can't think of a better way of doing that than having a technical difference between "trusted" and "untrusted" sites.
- yoz-y 8y agoWhat about differentiating applications and web sites? The line between the two is blurry, I know, but I would be happy if the document metaphor were divorced from the application one.
- dec0dedab0de 8y agoAbsolutely, there should be a different port for web pages than applications. Even if we started by disabling js on port 80
- krapp 8y agoBut what about applications that link to web pages or web pages that link to applications? What valid reason is there to have an "application" and any documentation or related HTML material from the same site on different ports? Or, as some have pointed out elsewhere when this has come up, to have "applications" and "documents" use completely different protocols, languages and native clients, when both are often used together?
- Retric 8y ago'Application' can be backward compatible with documents just fine. That does not mean a new category 'Document' that has reduced capability is useless. Banking websites for example don't need to be Applications and added protection for cross-site scripting etc. would be beneficial. Restrict things further and you default to supporting screen readers etc.
- krapp 8y agoWhat definitions of "application" and "document" are being used here? Banking websites are applications in terms of their functionality - they're certainly not documents. At least not the parts where I can access and modify my account.
- makmanalp 8y agoThe web didn't used to be able to do much, and we're using browsers that depended on tons of multi-decade old code, so I see how it happened. Agreed on the main point though.
- Endy 8y agoNo. The burden needs to be on the user to understand their own security. If we stopped taking the burden out of user's hands and tried to ensure that everyone on the Internet understood that anything they access becomes data on their computer/device, we'd have a smarter Internet. Frankly, I think if we made people understand that they have a responsibility to choose what they download, there might be more vocal group demanding the ability to do whatever they want with data transmitted to their computer, save for directly malicious acts against other users. The browser should be only two things: a client between a user and a server, passing information; and a parser which displays that information on the client-side. The moment a browser alone begins controlling what the user sees, or does not see, without the user having the ability to control it, we have a major problem. That becomes a security problem, a privacy problem, and a functionality problem. All data on the Internet should be treated the same by all browsers' client functions. The display may vary (e.g. the difference between Lynx and Firefox), but all data should be treated equally and the user should have both the authority and the responsibility for their own computer.
- lucideer 8y ago> The moment a browser alone begins controlling what the user sees, or does not see, without the user having the ability to control it, we have a major problem. What you're describing would be inordinately taxing for even the most experienced developer, not to mention the average internet user. The only way this could possibly be viable would be if we used gopher:// instead of http(s):// Currently, there are tools such as Privoxy Actions & Filters, which allow you to do 100% of what you're describing, Greasemonkey which allows you to do ~80% of what you describe, or uMatrix which allow you to do quite a lot. The prerequisites for using those range from full-blown programming skill (for the former 2) to managing a relatively advanced in-browser UI (for uMatrix), and having a lot of spare time. For every single webpage you visit on the web. This isn't viable for 99% of people.
- Endy 8y ago>The prerequisites for using [Privoxy & Greasemonkey] range from full-blown programming skill... Neither Privoxy nor GreaseMonkey require actual programming knowledge. I do not program, and I use Greasemonkey with some regularity - I use a combination of userscripts.org scripts and my own. They require a basic knowledge of specific scripting language implementations. Besides, Greasemonkey & uBlock/uMatrix both have a right-click menu entry that amounts to "hide anything like this". You're saying that 99% of the Internet's users can't handle being required to interact with the most basic front-end technologies which power the network they use every day, and which they willingly give up their private information to - thus having no ability to provide evidence for their trust or any expectation of their privacy. Frankly speaking, my mindset is that if it's not viable for them to understand it, it shouldn't be viable for them to use it. Uneducated users lead to nothing but trouble; and sure, I'll grant that I'm suggesting educating them the hard way, but I think the Web as a whole would be better off in the long run from smarter users and dumber clients. Heck, I think the whole world would be better off with smarter users and dumber clients/terminals/systems. Also, please, don't even begin to suggest that uneducated users should be directed to Gopher holes. You know as well as I do that if there's enough people going back to it, some yutz is gonna start trying to figure out how to add streaming this and scripted that to Gopher, and then Gopherspace will be ruined. And sure, on a technical level it would be a neat project to look at. But to reference Jurassic Park, a lot of very smart people have been so amazed at what they could do with the Web and the Internet as a whole, that they never really stopped to ask if they should do it.
- z3t4 8y agoSome browsers allow you to have many profiles. So you can use one profile for banking and e-mail, and another profile when browsing dubious sites.