3 ms·
> Damn right you don't let random people drive your car! just like I expect you not to click every link you see! The difference is that I can interact with any
by nathan_long 8y ago
> Damn right you don't let random people drive your car! just like I expect you not to click every link you see!
The difference is that I can interact with any number of people, yet only trust a few to drive my car.
You seem to suggest that I should trust everyone I interact with to drive my car, and since that's risky, I should limit my interactions to a few people.
> You're shifting the responsibility from yourself to a different entity for the choices you're making.
Not trusting a site's code is taking responsibility for what it might do to me. Trusting their code is giving them the responsibility to do what's right.
> The single safest thing you can do while using the web is to simply be aware of what you're clicking on, and what sites you visit.
This is good, practical advice for non-tech people. But fundamentally there is no reason the web needs to be unsafe. Viewing a series of hypertext documents is safe, no matter who wrote them. The web is totally safe if you browse it using curl. It's only when we assume that "of course you're going to run that stranger's code" that things become dangerous.
It's great that we can have web applications. It's not great if every page is an application. There should be an explicit step from "I'm casually looking at your page" to "now I want to trust you and run your code".
> That said, modern browsers do a really, really good job at isolating the code running in that page from anything you care about.
That code can't wipe my hard drive, but it can track me everywhere if I let it.
The reason we need content security policies and cross-site request forgery tokens and cross-site scripting protection etc, etc is that our browsers are constantly eval'ing whatever code they're given.