4 ms·
Here's one live example: https://www.tujavortaro.net/ https://www.tujavortaro.net/
by clarry 6y ago
Here's one live example: https://www.tujavortaro.net/ https://www.tujavortaro.net/
- bloak 6y agoThat's a great example. Instantaneous response to queries even on an ancient Chromebook.
- throwaway_pdp09 6y agoPoint is, it uses JS and how do I know I can trust it? Not this site but in general. As I say elsewhere, JS is not bad, it's an issue of trust that the JS delivered will not abuse your permission to run on your machine.
- bloak 6y agoThat particular site: the code is properly formatted with comments, there's a link to a GitLab repo with the source, you could check your network traffic while using it, ... But in general: I suppose what we need is a flexibly configurable JavaScript engine that stops and asks permission before any suspicious operation is performed. I don't know enough about JavaScript to know whether or how that might work. I note that the way tujavortaro.net downloads a dictionary is by adding a <script> element to the head of the document (https://gitlab.com/sstangl/tuja-vortaro/-/blob/master/app.js#L98 https://gitlab.com/sstangl/tuja-vortaro/-/blob/master/app.js...). HTML+JS is naturally self-modifying, so it's hard to do a static analysis.