4 ms·
> That said, I'd be willing to wager a fair bit that literally every line of code you've run on your machine (probably ever if it's been bought in the last few
by nathan_long 8y ago
> That said, I'd be willing to wager a fair bit that literally every line of code you've run on your machine (probably ever if it's been bought in the last few years) outside of the vendor installed OS and drivers came from the internet.
We explicitly decide to install software and we know where we're getting it from. We may not be careful enough, but I certainly trust `brew install` a lot more than I trust a random site I happen to visit.
> You bought that machine to run code. If you don't want to run code that sites serve you on the internet, don't visit them.
I bought my car to drive it, but that doesn't mean that every person I pass on the street gets to drive my car.
You seem to think that visiting a web site establishes a trusting relationship with that site. I think that downloading a site's HTML and running its JavaScript are quite different levels of trust. Especially when the content and the code come from very different entities - eg, the journalist writing the article vs the advertising network the publication uses.
Clearly if I'm using Gmail, I'm trusting Gmail and I don't mind running their JavaScript. But the blanket statement that "if you don't want to run code that sites serve you on the internet, don't visit them" seems out of touch with how pervasively nasty the internet is.
Taking a walk on a city sidewalk does not require eating whatever you find there.
- horsawlarway 8y agoI think this is a reversal of responsibility. You're shifting the responsibility from yourself to a different entity for the choices you're making. The single safest thing you can do while using the web is to simply be aware of what you're clicking on, and what sites you visit. > I bought my car to drive it, but that doesn't mean that every person I pass on the street gets to drive my car. Damn right you don't let random people drive your car! just like I expect you not to click every link you see! I'd also love it if you'd install an ad blocker, remove just about every other extension you have in your browser (ABSOLUTELY do this for old firefox extensions and IE BHOs) and trust your browser when it tells you that maybe visiting that particular site isn't the best idea. That said, modern browsers do a really, really good job at isolating the code running in that page from anything you care about.
- plankers 8y agoCorrect me if I'm wrong, but it seems that your personal philosophy places absoluely none of the onus for the internet being dangerous and unfriendly on the people who actually develop things for the internet. You instead blame the layman who has no power to control how websites are constructed. The heck?
- horsawlarway 8y agoI'd disagree entirely. I'd argue that I'm aware of how much effort has gone into making the web much, Much, MUCH more convenient and less risky for the average, day to day user. It's frankly stunning how much the ecosystem has changed just over the last 5-10 years. And I mean that as a developer who works in the security industry with a focus on browsers/extensions. It's ludicrous how much more secure the web of today is over the web of the past. That said, it's not yet secure. There's always a risk/reward decision for using the web, especially around HOW you - the user - uses the web. So to make an analogy: The infrastructure in place between root authorities, the IETF, browser vendors, ISRG (Let's Encrypt is just one), and website developers has done a DAMN good job in making the web less vulnerable than it was. It's a nicely paved two lane road that goes nearly everywhere. That said, you are interacting with the entity hosting the site you visit, NOT THOSE GROUPS, when you visit a site. It's your responsibility to make sure you trust that entity, and do your due diligence. Just like I wouldn't try to drive my crappy 1998 Mazda Protege offroad - It's dangerous and I would be unprepared. Its your responsibility to make decisions for yourself (or at least I fucking hope it is... that's a fundamental aspect of a democratic society that I STRONGLY believe in). That means living with the consequences. It can also mean choosing different service providers that are less convenient if you deem the easy ones too risky. If you're not willing to do that (aka: switch away from gmail if you want js disabled everywhere) and you still want to complain... I find it hard to treat you seriously.
- nathan_long 8y ago> It's your responsibility to make sure you trust that entity, and do your due diligence. What does this entail? I mean, ask the average person if they trust the New York Times, the London Stock Exchange, or Spotify. Those are well-known names - sure we trust them. We trust that, as an organization, they are not plotting to steal our identities. But trusting them means trusting their business people, their IT people, and their advertising partners, not only to be moral but also to be competent. And whoops, all of them have served malvertising in the past. Nobody has the time and expertise to evaluate every site's JavaScript every time they visit. The "due diligence" you describe would be a very specialized full-time job. Whereas turning off JavaScript in the browser takes about 10 seconds.