6 ms·
Web security is completely broken. We have super complex web browsers (written in unsafe languages such as C++) that we try to secure by installing 'add-ons' an
by _wldu 5y ago
Web security is completely broken. We have super complex web browsers (written in unsafe languages such as C++) that we try to secure by installing 'add-ons' and those have vulnerabilities that can steal our data.
Who thinks this is a good idea for online banking?
- morrisdoris 5y agoIt's time to retire javascript and css and any Turing complete scripting/styling, running random code from random websites is just never gonna be safe.
- kyrra 5y agoMay as well have the web just be a series of PDFs, I've never heard of exploits in those! /s Even just rendering engines can have bugs that can be exploited by specially crafted content. While it reduces the attack surface, it would be a massive hit to usability of web pages.
- catlikesshrimp 5y agoYou should have specified somewhere that PDFs are also vulnerable. It is not common sense. On that, PDFs run scripts and use graphic libraries, they are not text documents.
- kyrra 5y agoagreed, it was a bad example. You can fill them out like forms and the like.
- yjftsjthsd-h 5y agoPDFs can have full-on javascript and everything, too
- seanw444 5y agoGemini ¯\_(ツ)_/¯
- nonameiguess 5y agoYou write this seemingly as a joke, but someone a few months back actually posted a link to a blog that entirely consists of pdfs. What we really need is blogs that are all .txt files, to avoid the exploits in pdf active content.
- bennyp101 5y agoI dunno, 20 years ago it gave us an instant cup holder
- madars 5y agoFor those who might not have seen this reference: https://www.youtube.com/watch?v=gbVMdPDS1ak https://www.youtube.com/watch?v=gbVMdPDS1ak . Oh, VBScript, those were the times!
- _notathrowaway 5y agoLaptops were so sexy back then.
- cortesoft 5y agoIf you got rid of JavaScript, it will mean that a lot of things that can be websites today would have to move to an application on your computer/phone. It is just shifting the security risk somewhere else.
- boogies 5y agoBoth of my computers (laptop and pinephone) get their native applications through secure, vetted channels that have practically never let malware through (their distro’s package repos).
- cortesoft 5y agoAnd I have a browser that has practically never let malware through... and I get to visit any website without needing someone's approval. I'll take open and a slight risk vs closed and a slight risk.
- boogies 5y agoYou can't know how many times your browser's let malware through, there's practically no supply chain security, no reproducible builds, no way to know what code has been executed. I don't need anyone's approval to run native apps either, both my PCs run C apps I built from source and shell scripts I wrote myself without it, languages of my choice with implementations simple enough to write myself, not runtimes that literally no one that's not Google can afford to independently maintain. That's real openness.
- danr4 5y agocomputer security is generally broken, and will always be. Code will always have bugs, some of them will be security bugs. Always.
- prionassembly 5y agoYeah. But the web is like a VW Bug four-cycle motor rigged to a ratty tricycle overlaid with a stage-looking platform where large bears perform pole dances (poles glued to the tricycle's handle), and there's classrooms for ants on top of the heads of the bears and underneath it all the water level keeps rising... Maybe we should have a dozen protocols for different kinds of applications. (I mean user-facing applications!) Maybe online banking shouldn't involve CSS and JavaScript. Spending some time with Gemini is a real eye opener in this respect.
- deleted 5y ago[deleted]
- brokenmachine 5y agoWhat's Gemini?
- boogies 5y agohttps://gemini.circumlunar.space/ https://gemini.circumlunar.space/
- VWWHFSfQ 5y agoThat's why banks are responsible for the fraud risk, not the customer. It's pretty much the only way this can work. It's also why something like bitcoins will never replace traditional banking. Because people make mistakes or have their stuff stolen due to no fault of their own and they would have no recourse.
- notyourwork 5y agoThat's right, as interesting as crypto currency may be it doesn't solve the customer fuck up problem in a way that the masses would tolerate.
- brokenmachine 5y agoCouldn't insurance cover that gap?
- notyourwork 5y agoSure, who is going to provide that? FDIC is a government backed insurance. I imagine there is little to replace government backed insurance with a private equivalent. If there is it would surprise me but even if this were to happen but is the benefit over a non-crypto currency?
- nathanyz 5y agoThis is exactly my thoughts on crypto as well. Being unable to fix a "whoopsy" is the biggest weakness. Humans make mistakes, and computers make mistakes. When it comes to money, you need to be able to apply common sense and be able to reverse those mistakes. Crypto seems too absolutist for this use case. (Although I should mention that they seem to discuss rolling back the blockchain whenever a big heist takes place. But if you can rollback then chain, then doesn't that circumvent the core tenant of no trust needed as now you have to trust that the group doesn't decide to rollback the chain?)
- jaywalk 5y ago
- KarlKemp 5y agoName any CSS or JS exploit that had meaningful real-world impact in the last decade. In 20 years on the Internet, most without an ad blocker, I haven't suffered from any lapses in browser security (that I know of, sure, but I don't much care about those I don't know about) The tale of frequent compromises of browsers via ads is told merely to legitimize the practice of blocking even entirely plain and benign ads.
- jyrkesh 5y agoGreat, but you're computer-savvy. You know not to click the 9 phony "Download" buttons and to find the nondescript text that says "Download link (slow)", and you probably don't even end up on sites like that in the first place. Nowadays, the first thing I do when "cleaning up" a non-tech friend/relative's computer is to install uBlock Origin. Since I started doing that, the number of repeat calls dropped precipitously. (To be honest, it's probably good for their fake news intake, too...) The web is a lot scarier for most people than you might realize if you've been successfully navigating away from sketchy sites for 30 years.
- Brybry 5y agoPeople lose website account credentials, with meaningful life impacts, all of the time. Even simple image ads that are fake "click here to login" have tricked my elderly relatives before. I install an ad blocker on the computers of relatives out of reaction to real events that happened, not paranoia. You were never clickjacked? Never had pop-up or pop-under ads/windows created without your consent? Recursively? Crashing your browser? Never visited a page that was hijacked with an iframe? I've experienced a lot of malicious ads in my time on the internet, it baffles me that someone has not.
- autoexec 5y ago> Name any CSS or JS exploit that had meaningful real-world impact in the last decade. The tale of frequent compromises of browsers via ads is told merely to legitimize the practice of blocking even entirely plain and benign ads. I think the actual malware infections themselves legitimize the practice of blocking even entirely plain and benign ads. Ads do still infect people with malware. https://blog.confiant.com/tag-barnakle-the-malvertiser-that-hacks-revive-ad-servers-redirects-victims-to-malware-50cdc57435b1?gi=9fbcec4471e2 https://blog.confiant.com/tag-barnakle-the-malvertiser-that-... Hell, yahoo was hit not that long ago and users were at risk of infection just by loading yahoo.com. JS exploits and malware written in JS are common, but so far I haven't seen CSS used to infect systems, just steal data/log keystrokes and add a lot of privacy concerns which is bad enough. I'm already keeping an eye out for a CSS blocker that will only allow a sane subset of CSS and block or limit externally hosted resources.