5 ms·
Seriously considering running a JIT-less JavaScript free browser should be the standard for surfing these days, and only whitelisting sites you trust (like your
by sysadm1n 3y ago
Seriously considering running a JIT-less JavaScript free browser should be the standard for surfing these days, and only whitelisting sites you trust (like your online banking site or Amazon for example). Disabling JS wipes out entire classes of attacks. I know developers assume the user has JS enabled and codes their site to that end, but a small minority disables JS to get rid of various annoyances and for accessibility reasons, and, malware issues in the browser.
This attack can still be pulled off without JS though: using plain old CSS & HTML. It seems these attacks are targeted to the non tech savvy, but even I (tech savvy) get duped by persuasive messages in my browser. This is why I advocate for a Phishing/Malware 101 course which is mandatory for all types of tech-related courses and learning.
- sublinear 3y agoThis isn't that complicated. Like everything else in life it's a matter of trust and awareness, not really that technical. I'll never understand why the default stance on HN is always javascript bad.
- everdrive 3y agoIt's simple; the web becomes a much nicer place when you block javascript by default. Some things don't work, but they never compromise you, or bog down your computer, and throw huge ads and banners in your face. I could go on. I obviously see that JS can be used for good things, but it seems like people can't constrain themselves to that.
- simion314 3y ago>I'll never understand why the default stance on HN is always javascript bad. I am a web dev, and I agree that JS on the web is bad for pages that should be just documents like a news webpage or wiki page. JS makes sense for applications like a video game, video/audio/level/text editor, or some internal app that your company trust, but for random untrusted document pages JavaScript is a detriment, even if we only consider UX.
- andybak 3y agoYou're a web developer but your mental map of the web consists of "documents" on one end and "applications like a video game, video/audio/level/text editor(s)" on the other? You haven't in your career, stumbled across web (sites/apps) that sit somewhere on the spectrum between the extremes of "document" vs "app"? It strikes me that there's a fairly even distribution between those two points - even if we discount all the misguided "could have been a static site but someone decided it had to be an app" decisions. I actually agree with you on reigning in javascript but I think much of the web is poorer without it. We had an answer for this years back and it was called "progressive enhancement".
- simion314 3y agoMost links we opened daily are to read stuff not to interact with stuff, either read documentation, read news, read some social media page. Those pages should be readable without scripting but for some reason they do not load at all without JS.
- andybak 3y agoYes. That was the bit where I mentioned "progressive enhancement".
- thedaly 3y ago> Progressive enhancement is a strategy in web design that puts emphasis on web content first, allowing everyone to access the basic content and functionality of a web page, whilst users with additional browser features or faster Internet access receive the enhanced version instead. Why isn't this still the norm?
- andybak 3y agoThe ascent of SPA frameworks and the inexorable allure of "Development by CV".
- tremon 3y agoI don't think it's a matter of trust and awareness, because your browser is already happily executing the javascript payload before you have decided whether to trust the website or not. And users are completely unaware of what the payload is doing unless it's spinning at 100% cpu or throwing UI elements in the user's face. It's a matter of convenience mostly, from my point of view. The HN population consists for a large part of computer power users and developers who are fully aware of the capabilities of browsers and the dangers of remote code execution. I'll never understand why the default stance on HN still mostly seems to be javascript good, if not for the convenience factor.
- dylan604 3y agoThe browser had Javascript ON or Javascript OFF. If the browser had JS off for all until user whitelists the site, that would negate the need for plugins like uBO/NoScript/etc.
- klyrs 3y agoYour browser is a platform that downloads and runs arbitrary code on your local hardware. "JavaScript bad" doesn't capture the nuance I read in people's comments here, but history shows that JavaScript is a gaping maw of security nightmares.
- sublinear 3y agoModern browsers are what have removed the nuance. Please tell me what about the Web API for JS is truly dangerous. Native apps and programmable documents (PDFs and spreadsheets for example) are the real security nightmare. The danger on the web lies squarely with easily fooled idiots visiting shady sites.
- amelius 3y agoFingerprinting is one example.
- klyrs 3y agoFor me personally it isn't as much "danger" as annoyance. Most of the web is hidden behind piles of modals, dickbars, autoplay videos, etc. Almost none of that happens without javascript. But don't dismiss those fools, they're inside sensitive networks around the world.
- coldpie 3y agoJust install NoScript. Works great. https://addons.mozilla.org/en-US/firefox/addon/noscript/ https://addons.mozilla.org/en-US/firefox/addon/noscript/
- pcwalton 3y agoI would argue that a world that didn't have JS would make these types of attacks more common, not less common. Because in that world, people would have to download desktop apps for everything, which would make people used to downloading desktop apps from random Web pages, which would make malware easier to distribute. In fact, we don't have to imagine that world: it was the world of the late 90s.
- WhyNotHugo 3y agoNative applications should be downloaded via your distributions' channels, not from random websites.
- slikrick 3y agobut realistically they aren't, so why are you even mentioning it? not every app is on the windows or Mac App store, not every app is on the Linux package managers. even so there is no sandboxing so you're just waiting until one of them gets compromised and hope nothing bad happens sandboxing hostile apps is the only true way to protect yourself, and even that isn't perfect
- hollerith 3y ago>even so there is no sandboxing Lenovo sells all-in-one PCs that run Android, and in a world without Javascript, you can imagine such a thing having become much more common that it actually has become so far in our world (e.g., with more enhancements done to Android to work well with a mouse) and of course Android has very solid sandboxing of apps.
- livueta 3y agoThat's a very real problem, but one would hope that package managers would be a lot more widely adopted in that counterfactual world. Maybe that's a naive hope.
- yesco 3y ago
- fsflover 3y agoOr alternatively, you can pursue security through compartmentalization. My VM for random browsing has JS enabled, but if I'm hacked, the attacker will not get access to any files. Also the VM is destroyed when the browser is closed.
- lxgr 3y agoWhat’s the threat model here? Javascript sandbox escapes are extremely rare these days (subjectively they happen less frequently that image or video codec bugs).
- fsflover 3y agoApart from js escapes, you are protected even if you run random executables from the Internet, or any untrusted software in general. More reasons: https://forum.qubes-os.org/t/how-to-pitch-qubes-os/4499/15 https://forum.qubes-os.org/t/how-to-pitch-qubes-os/4499/15
- lxgr 3y ago> run random executables from the Internet Well, here's your actual problem. That's a vastly different threat model! Modern browsers are very well sandboxed.
- fsflover 3y agoEven with the original threat model, CVEs in the web browsers are much more frequent than in the hardware virtualization with Xen, aren't they?