4 ms·
Yeah, I thought that sort of quip might come along. ;) On the one hand, you have a real point. On the other, JavaScript running in my browser has significantly
by XCabbage 8y ago
Yeah, I thought that sort of quip might come along. ;)
On the one hand, you have a real point. On the other, JavaScript running in my browser has significantly less power to do anything bad to me than arbitrary executable programs running directly in my OS do.
- JohnFen 8y ago> JavaScript running in my browser has significantly less power to do anything bad to me than arbitrary executable programs running directly in my OS do. I think that depends on what you mean by "significantly less power". It's entirely possible to use Javascript to place malware (such as installing a binary executable) and do other assorted nastiness on a target machine. If the target machine is properly secured, it's still possible, it just requires more effort. This is the primary reason why I do not allow Javascript to run on my machines by default. If I'm at a site that I trust and I have no alternative to using, and the JS in question is essential, then I'll allow just the specific piece of JS to run. Otherwise, it's not happening.
- miohtama 8y ago> It's entirely possible to use Javascript to place malware (such as installing a binary executable) and do other assorted nastiness on a target This sounds interesting. Can you kindly link an example for this technique?
- Cpoll 8y agoBut if you want to go that far, it's entirely possible with Javascript disabled. Not every browser bug is a JS engine bug. Your best bet (not guaranteed) is reading the html as plain text, not rendering any images, etc.
- spenczar5 8y agoThese days, so much happens in browsers (banking, medical records, social communications) that it's hard for me to imagine a more dangerous place to give up execution. What sort of things are you thinking of that scare you more on the OS?