6 ms·
No no no. The problem isn't JavaScript or web capabilities here. It's the companies and people who use them in evil ways. I would rather handle that even if it'
by masa331 6y ago
No no no. The problem isn't JavaScript or web capabilities here. It's the companies and people who use them in evil ways. I would rather handle that even if it's much much harder.
- alentist 6y agoYes yes yes. Luckily for us, these problems are technically solvable, no handling (?) "evil ways" (?) needed. The latter proposal is both ill-defined and a waste of time and resources. Better to spend those resources on designing more secure systems.
- DavideNL 6y agoYea... You need either a law/sanctions, or a technical restriction that can't be circumvented. Hopefully both, someday :)
- xg15 6y agoAnd how would you address this problem?
- CogitoCogito 6y agoRegulation seems appropriate.
- Daho0n 6y agoSo different website features per country? Or do you mean regulation decides how a browser implements it? Either way I don't see how that would ever work.
- CogitoCogito 6y agoYou are aware there are country-specific (or even more local) regulations covering companies today right? In fact essentially all regulations are. So why are you acting like my proposition is somehow unprecedented?
- TaylorAlexander 6y agoIsn’t it obvious? Most companies subject to regulations are physically located somewhere. It’s much harder to enforce regulations against companies that operate in every global jurisdiction at once.
- CogitoCogito 6y agoThere are like 3 companies that do the vast majority of advertising. They have operations in countries they do business with. Do you think they’re hard to track down? Web tracking has consolidated over time hence enforcement is _easier_.
- Daho0n 6y agoBecause this is about websites, not companies. I'm not a company. Do my website use a different regulated subset of JavaScript than yours? If it is a company do they follow local rules or local for the hosting company? What about sites that incorporate sources from different locations? Do JavaScript library developers now have to create a version of their script for each countries regulation? Then the US regulation will decide the rules for all of the worlds JavaScript development and deployment. No, which technologies that can be used on a website doesn't belong at regulators but developers. What can and cannot be tracked and collected belongs at regulators.
- CogitoCogito 6y agoI'm kind of confused here. Websites have to do everything you're saying today already. There are already different rules regarding data privacy, protected speech, etc. in different countries. How you choose to fulfill those obligations is up to you. But yes if your point is that it requires work to follow various different regulations, then of course you're correct. In fact, that's the whole point. The regulations are there to change your behavior in the market in question. We've had regulations across varying markets since pretty much time immemorial.
- Daho0n 6y ago
- kortilla 6y agoRegulation as a solution for problems on the Internet is pretty stupid because jurisdictions are so diverse.
- silentbugs 6y agoBut the reason you're not brute forcing passwords on your bank's e-banking system isn't because you can't or because they are super secure, it's because if you do you'll probably go to jail. Also, good regulation is important to keep the big dogs on a leash and to have something to go after them when they don't behave. Technological solutions will of course come, but you also need regulation, especially until the technological solutions come.
- kortilla 6y ago> But the reason you're not brute forcing passwords on your bank's e-banking system isn't because you can't or because they are super secure, it's because if you do you'll probably go to jail. No, this is really out of touch with how crime online works. People that want to hammer a bank rent botnets, use tor, vpns, etc. Banks get absolutely zero protection from the law in that regard. It’s “illegal” but completely unenforceable to the point of being useless.
- CogitoCogito 6y agoI’m confused by your response given that regulations are a _standard_ solution for problems on the internet.
- sjwright 6y ago"Regulation" mandated stupid cookie consent overlays on every damn European website. Thanks, regulation.
- CogitoCogito 6y agoDoes the fact that some regulations are ineffective imply that all are?
- account42 6y agoThere is no regulation mandating cookie consent overlays - websites are free to not abuse cookies to track their users.
- deleted 6y ago[deleted]
- alentist 6y ago> There is no regulation mandating cookie consent overlays Yes there is. A mugging is still a mugging even if the victim is "free" to give their wallet. > websites are free to not abuse cookies to track their users. You're free to not use such websites. I dislike tracking and avoid being tracked myself. But this absolutely is a regulation and it's immensely disingenuous to pretend otherwise.
- tremon 6y agoNope, only on those that intend to abuse your personal information.
- mikem170 6y agoI browse in firefox with javascript turned off, in ublock, with a bunch of other restrictions [0], and temporary containers. I make exceptions for a couple dozen sites, like my bank, open street maps, etc. Youtube is my only soft spot here, the rest of google I keep blocked. I can make one-off exceptions to read a tab in front of me, but that's not routine, it's not hard to find sites that support this. [0] https://github.com/pyllyukko/user.js https://github.com/pyllyukko/user.js
- nunez 6y agoHow do you use the internet with JS turned off? Every time I try doing this, I undo it five seconds later because of so many sites breaking instantly. (I sometimes browse the web with w3m; sites blocking you because of no JS happens often)
- boring_twenties 6y agoMany sites break instantly. If I care enough about those sites, I whitelist them. Otherwise I move on. On the other hand, many sites work better with JS disabled: they load much faster, don't slow down scrolling, don't break copy & paste, and so on. edit: I should probably make clear that I'm not the same user you responded to
- mikem170 6y agoI can usually find alternatives that works without javascript. Or I find sources outside of the big tracking companies, like openstreetmaps instead of google maps, etc. I'm not a promiscuous browser, if I click on an interesting link and I get an empty page because it insists on javascript I close that tab and figure I saved myself from wasting my time on a crappy ad-tracking-infested website, so many of which are lame anyways. That being said I do sometimes enable javascript temporarily on sites when I am desperately looking for some specific bit of info, then I reset back to my default-off when finished. I've been doing this for a couple/few years, and it doesn't seem like a big deal to me. I'm happy to have that reminder that a site is irritating me insisting on javascript for no good reason, more often I go elsewhere and that suits me fine. It saves me from having to worry about so many nefarious things that go on in this space. Why not give it a try? Ublock lets you default disable all javascript and enable it on the page you are looking at with a couple clicks, and edit/revert your list of rules whenever you want. You might be pleasantly surprised at how few times you need to fiddle with it after you set it up for your important sites.
- ballenf 6y agoI don't think it's either/or. Yeah we need to act against companies abusing it, but we also need to be prudent and put locks on our houses when we know there are thieves and spies who would love to sneak inside and take notes on our every move. What frustrates me the most is that we can't individually disable web api's that provide no value to us. Yeah, that would give greater entropy to fingerprinting, but I'm willing to take that tradeoff if I could prevent webrtc, motion sensing, screen size detection, or web assembly e.g. except on selected whitelisted websites.
- throwaway9d0291 6y agoDoesn't the same argument apply to basically every security and privacy feature? "No no no. The problem isn't unencrypted network connections, it's companies and people who use them in evil ways. I would rather handle that even if it's much harder." Should we not have introduced HTTPS? Permission models on modern operating systems? 2-factor authentication? What about Javascript makes it different to the problems solved by these other features?