3 ms·
Do you actually see it as a practical solution? When you use those features only when you're a web dev, not only you're actually using them anyway (which defea
by d33 6y ago
Do you actually see it as a practical solution?
When you use those features only when you're a web dev, not only you're actually using them anyway (which defeats the purpose by driving demand), but you also increase supply by creating new websites of the kind.
Also, if you not use the websites "that think they're an OS", you're ending up not being able to function in today's world to an increasing extent. e-governments are all about web applications, often with "bare metal functionality" such as legacy Java, ActiveX or Flash applets. They should be long gone, but given that somebody pumped millions into them, it will take them years to go away.
Hell, even regular JS is bare metal today with all the complexity of JIT. I'm getting the impression that suggesting to go away from this realm is naive and a better solution would be to look at it from the perspective of "OK, it happened. How can we make it more secure?".
After all, becoming an OS isn't an excuse to doing less. In fact, browsers now have more responsibility to keep their security philosophy up to date.
- labawi 6y agoHard disagree. I'm not giving WebGL a pass, nor wasm, web notification, webrtc, webusb, HTTP3, websocks, DOH or whatever bright idea they had last month, just to read a newspaper. I actually like and use webrtc, but only for actual RTC, otherwise it's a shitshow and disabled. Some things are indeed useful, but I don't see how you go OK, it happend, time to make it secure - with an ever expanding scope and attack surface. Note - "more secure" is not enough, we need secure.
- d33 6y agoI guess we misunderstood each other then. I got the impression from your post that you're willing to join the crowd that's never willing to turn on JS etc. If it's just about reading the newspaper, you can pick a less invasive data data source. But, say, for e-government, you really don't have a choice and given that all those things are already standard and can be used for good purposes, I guess we really have no option other than isolating those features the best we can. If your bottom line is "features should only be available when there's a legitimate use case for them", perfect. The problem is when there's a major website and you don't know why it's working, but you turned off entire JS stack and it can't even tell you that.
- labawi 6y agoI agree misunderstand each other. What are "all those things" that "are already standard"? And why should a rando government or other site requiring an API mean it should be available to all websites everywhere? Note, I didn't even mention javascript nor disabling it altogether, and I don't wish to imply we shouldn't secure any and all APIs/features. I'm saying (1) we will never secure all APIs/features; (2) they are ever growing so it would be futile even if we could secure the present ones; (3) even if all the APIs are "secure", they will be misused against users, so they should not be available by default like they currently are; (4) yes, I do think static/simple sites should be usable without JS. I used to think of Stallman's browsing habits as silly, but there may come a time where I will visit the web-at-large only from other people's or dedicated-use devices.