3 ms·
> It's your responsibility to make sure you trust that entity, and do your due diligence. What does this entail? I mean, ask the average person if they trust t
by nathan_long 8y ago
> It's your responsibility to make sure you trust that entity, and do your due diligence.
What does this entail? I mean, ask the average person if they trust the New York Times, the London Stock Exchange, or Spotify. Those are well-known names - sure we trust them. We trust that, as an organization, they are not plotting to steal our identities.
But trusting them means trusting their business people, their IT people, and their advertising partners, not only to be moral but also to be competent. And whoops, all of them have served malvertising in the past.
Nobody has the time and expertise to evaluate every site's JavaScript every time they visit. The "due diligence" you describe would be a very specialized full-time job.
Whereas turning off JavaScript in the browser takes about 10 seconds.
- horsawlarway 8y ago> It's your responsibility to make sure you trust that entity, and do your due diligence. > What does this entail? My whole point is that that's up to you to decide. No one else can make that choice for you. The VAST majority of people have decided that the risks they face today are worth it, and continue to use the web with js enabled. If you're not one of them, I absolutely respect that decision, but it means you'll have to accept that companies are making financial and security based decisions based on the behaviors of normal people. That means that when spotify (and lets be honest, every other streaming service) doesn't work without js, you go somewhere else, and use something different. That's the whole point I'm making. You can make any decision you'd like with regards to your own security, you can make any decision you'd like with regards to the sites you visit. But that site is free to act in it's own interests, including adding features and services that target the majority of their uses.