4 ms·
> unless you're using a browser from <2010 To be fair, a lot of Jason Scott's audience is people who might choose to use ancient browsers on obsolete platforms
by csixty4 6y ago
> unless you're using a browser from <2010
To be fair, a lot of Jason Scott's audience is people who might choose to use ancient browsers on obsolete platforms.
- oneplane 6y agoDoesn't that make it double-bad? Again, people might come up with the argument that it's their own problem if they get abused, but also that is just not the reality we live in; any compromised system can (and will most of the time) be used to infect/compromise/attack other systems.
- anthk 6y agoGood luck trying to a attack an HTML only browser under a Z80 machine, for example.
- oneplane 6y agoWell, getting an RCE on that wouldn't be that hard I imagine. Not a whole lot of protections in there, and if there is an OS between the browser and the metal you can exploit that too. And if you don't want to exploit the browser or the hardware, you can still simply inject a self-refreshing iframe in to the plain text html stream and have that z80 act like a (slow) proxy so you can do things that will point to that Z80 being the 'origin'. Everybody assumes that 'simpler' or 'reduced' systems are always safer, but as soon as you deal with external interfaces and the outside world, that goes out the window. Lynx was thought to have less of an attack surface because it just did basic text-based browsing with HTML and not much else. Turns out that wasn't the case either.
- anthk 6y agolinks in Unix for example has automatic refreshing as a checkbox.
- oneplane 6y agoWell, then you use progressive rendering, or you use chunks, or you use something else. Sure, there might be specific mitigations that someone might have or have not set up, but that is not the point. The point is that assuming your system is safe is a bad position, and ignoring easy to use systems and processes to thwart complete classes of abuse is bad when you use a shared medium like the internet.