3 ms·
I guess we misunderstood each other then. I got the impression from your post that you're willing to join the crowd that's never willing to turn on JS etc. If
by d33 6y ago
I guess we misunderstood each other then.
I got the impression from your post that you're willing to join the crowd that's never willing to turn on JS etc. If it's just about reading the newspaper, you can pick a less invasive data data source. But, say, for e-government, you really don't have a choice and given that all those things are already standard and can be used for good purposes, I guess we really have no option other than isolating those features the best we can.
If your bottom line is "features should only be available when there's a legitimate use case for them", perfect. The problem is when there's a major website and you don't know why it's working, but you turned off entire JS stack and it can't even tell you that.
- labawi 6y agoI agree misunderstand each other. What are "all those things" that "are already standard"? And why should a rando government or other site requiring an API mean it should be available to all websites everywhere? Note, I didn't even mention javascript nor disabling it altogether, and I don't wish to imply we shouldn't secure any and all APIs/features. I'm saying (1) we will never secure all APIs/features; (2) they are ever growing so it would be futile even if we could secure the present ones; (3) even if all the APIs are "secure", they will be misused against users, so they should not be available by default like they currently are; (4) yes, I do think static/simple sites should be usable without JS. I used to think of Stallman's browsing habits as silly, but there may come a time where I will visit the web-at-large only from other people's or dedicated-use devices.