5 ms·
Whether or not the API is opt-in is orthogonal to its security hardening - this is a false dichotomy.
by ericflo 6y ago
Whether or not the API is opt-in is orthogonal to its security hardening - this is a false dichotomy.
- jeswin 6y agoBut that's not what parent was saying, I think. He was saying that WebGL not being opt-in was a security disaster; while saying nothing about the security hardening of the WebGL module itself. Even when a module is well tested, I'd like non-essential modules to be opt-in too.
- m_eiman 6y agoI’d like Javascript to be opt-in. Turning it on by default was a mistake.
- hutzlibu 6y agoYou are free to disable it as a very small minority. The web is not a static document viewing anymore. Now I agree, that sites should have a static fallback, as I also do not want to run a full webapp, when all I want is a static article for example. But this is because of a different problem - the financing of most of the web, through advertisment and not the fault of javascript.
- tracker1 6y agoMuch like frames, iframes and window.open are really useful features... advertisers and abusers made it bad. I remember the first time I saw a popup in the 90's, my first thought was, "oh this is going to get bad." And I would never buy a product from X10.
- MaxBarraclough 6y agoI'm not suggesting any false dichotomy, I'm trying to reason about the likely security consequences given what we saw with WebGL in Firefox: serious security flaws in its implementation, with the features enabled in the browser by default. See my links above, one of which summarises with anyone running Firefox 4 with WebGL support is vulnerable to having malicious web pages capture screenshots of any window on their system. My thoughts are along these lines: ┌────────────────────┬──────────────────────────┬──────────────────────────────┐ │ │ Secure implementation │ Insecure implementation │ ├────────────────────┼──────────────────────────┼──────────────────────────────┤ │ Opt-in │ Minimal security impact │ Significant security impact │ │ Enabled by default │ Minimal security impact │ Security disaster │ └────────────────────┴──────────────────────────┴──────────────────────────────┘
- AdmiralAsshat 6y agoFirst time I've seen a decent-looking ASCII table in an HN comment. Well-done!
- MaxBarraclough 6y agoThanks, it's technically not an ASCII table, it's from the Unicode (single line) style of https://ozh.github.io/ascii-tables/ https://ozh.github.io/ascii-tables/
- fulafel 6y agoRunning firefox 4 (or any other comparably old browser), this would be the least of your security problems, it's not even RCE. The stream of discovered vulnerabilities is constant.
- MaxBarraclough 6y agoWhat's your point? Do you really think I was suggesting that people are still running Firefox 4? When WebGL was first implemented in Firefox - long ago - it shipped with serious security flaws. This struck many people as sadly predictable, as graphics APIs like OpenGL are not intended to be accessible from untrusted code. WebGPU seems awfully similar to WebGL in this respect: it's trying to wrap a low-level graphics API in a secure sandboxed API. This isn't the equivalent of a routine addition like a new feature in CSS.
- fulafel 6y agoThe point was that seen from the future, old browser versions are always full of holes in all kinds of features, more in new features than old ones, we should fix the systemic problems that make browsers so ridden with vulnerabilities. But yes I am guilty of some whataboutism here, WebGL did have some unique problems and WebGPU devs hopefully learn from them.