6 ms·
It's time to retire javascript and css and any Turing complete scripting/styling, running random code from random websites is just never gonna be safe.
by morrisdoris 5y ago
It's time to retire javascript and css and any Turing complete scripting/styling, running random code from random websites is just never gonna be safe.
- kyrra 5y agoMay as well have the web just be a series of PDFs, I've never heard of exploits in those! /s Even just rendering engines can have bugs that can be exploited by specially crafted content. While it reduces the attack surface, it would be a massive hit to usability of web pages.
- catlikesshrimp 5y agoYou should have specified somewhere that PDFs are also vulnerable. It is not common sense. On that, PDFs run scripts and use graphic libraries, they are not text documents.
- kyrra 5y agoagreed, it was a bad example. You can fill them out like forms and the like.
- yjftsjthsd-h 5y agoPDFs can have full-on javascript and everything, too
- seanw444 5y agoGemini ¯\_(ツ)_/¯
- nonameiguess 5y agoYou write this seemingly as a joke, but someone a few months back actually posted a link to a blog that entirely consists of pdfs. What we really need is blogs that are all .txt files, to avoid the exploits in pdf active content.
- bennyp101 5y agoI dunno, 20 years ago it gave us an instant cup holder
- madars 5y agoFor those who might not have seen this reference: https://www.youtube.com/watch?v=gbVMdPDS1ak https://www.youtube.com/watch?v=gbVMdPDS1ak . Oh, VBScript, those were the times!
- _notathrowaway 5y agoLaptops were so sexy back then.
- cortesoft 5y agoIf you got rid of JavaScript, it will mean that a lot of things that can be websites today would have to move to an application on your computer/phone. It is just shifting the security risk somewhere else.
- boogies 5y agoBoth of my computers (laptop and pinephone) get their native applications through secure, vetted channels that have practically never let malware through (their distro’s package repos).
- cortesoft 5y agoAnd I have a browser that has practically never let malware through... and I get to visit any website without needing someone's approval. I'll take open and a slight risk vs closed and a slight risk.
- boogies 5y agoYou can't know how many times your browser's let malware through, there's practically no supply chain security, no reproducible builds, no way to know what code has been executed. I don't need anyone's approval to run native apps either, both my PCs run C apps I built from source and shell scripts I wrote myself without it, languages of my choice with implementations simple enough to write myself, not runtimes that literally no one that's not Google can afford to independently maintain. That's real openness.