4 ms·
You're misunderstanding: you browse with JS disabled by default. Random sites shouldn't be running programs on your computer. If you trust the site, you whiteli
by tree_of_item 8y ago
You're misunderstanding: you browse with JS disabled by default. Random sites shouldn't be running programs on your computer. If you trust the site, you whitelist it.
- diminoten 8y agoYou're acting like "running programs on your computer" is a bad thing. It's not.
- vageli 8y agoRunning untrusted code on your machine _is_ a bad thing though.
- diminoten 8y agoYeah, because permissions, sandboxing, and access controls don't exist. Oh wait, they do, and they work, so you're wrong.
- cesarb 8y agoEven setting aside things like rowhammer and spectre, something like half of the browser vulnerabilities need Javascript to be exploited.
- hueving 8y agoNo, they don't always work. We have bullet proof vests but it's still not safe to put one on and have someone start shooting you.
- diminoten 8y agoDo you wear a bulletproof vest every time you go outside? No? Interesting.
- Dylan16807 8y ago>Do you wear a bulletproof vest every time you go outside? No? Interesting. You realize the bulletproof vest is the sandbox, right? You've just made an argument against enabling all javascript.
- diminoten 8y agoNo, it's not. The lack of availability of guns is the sandbox, the cultural more of not killing people is the access controls. "Bulletproof vest" in this analogy is "extraordinary activity designed to keep you safe". You don't "wear a bulletproof vest" (a stand-in for "take extraordinary measures") to prevent yourself from "getting shot" (a stand-in for "thing that happens very rarely"). In other words, your assessment of the risk of JavaScript running in a browser is higher than it actually is.
- hueving 8y agoI'm not sure you understand how many entities are trying to get into your computer to track you/steal data/mine bitcoin/etc. These are active attacks against your computer every day if you are a regular user clicking viral shit on Facebook, random ads for things, etc. Look at how many 3rd party JS libraries get loaded from remote sites for metrics, frameworks, tracking, ads, etc for something like a newspaper site. There are probably 15 servers involved, most of which run by companies with limited security expertise (if any) so frequently they end up compromised to inject garbage into visitors' browsers. There is absolutely no lack of availability of guns or people attempting to use them on you in this analogy. The bullet proof vests are good, but that doesn't mean there isn't someone attempting to shoot you in the chest every time you go out. Look at spectre/meltdown. Arbitrary code execution is not safe. Not in a browser sandbox, not in a kernel namespace, not in a hypervisor. You're protected from common thugs most of the time, but your bullet proof vest will fail if someone with a powerful gun takes aim. There is a reason the CIA doesn't use the same AWS servers as the public and it's the same reason you can't view Facebook from inside a secure military network. Sandboxes are just a protection mechanism from well-understood attacks, they don't provide anything near the level of real isolation that Internet companies would love you to believe.
- shakna 8y ago> and they work ... They break about as often as they work. [0][1] There are a lot of vulnerabilities that appear in web browser protections, and almost all of them get exploited via JavaScript. Running untrusted software is not safe. [0] https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=chromium https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=chromium [1] https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=firefox https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=firefox
- diminoten 8y agoThis is factually incorrect. It is entirely safe to run JavaScript in your browser. Your definition of "a lot" doesn't fit this conversation, because it doesn't represent constant and regular vulnerabilities. Browsers are very safe. Not perfectly safe, but very safe. Thinking otherwise is paranoia, just like not running JavaScript by default in your browser is paranoid.
- quickthrower2 8y agoPutting security to one side, disabling JS is an easy way to performance optimise their pages on their behalf.
- jazzyjackson 8y agoWell I don't want to run EVERYone's program on my computer, I want to run MY programs on my computer. Most websites are made of text, I usually want the text, not whatever program they're running.