5 ms·
Meanwhile if I see that I just move on. It just isn't practical to have a workable browser with JS whitelisting for the general case. I doubt people who do th
by stusmall 1y ago
Meanwhile if I see that I just move on. It just isn't practical to have a workable browser with JS whitelisting for the general case. I doubt people who do this actually do any kind of thoughtful review before hitting "accept". It just adds manual toil with limited benefit.
If they are doing meaningful review, I question how much they actually get done in life.
- braiamp 1y agoI have NoScript by default set to no run. Some sites work better without it.
- userbinator 1y agoI very clearly remember, many years ago, a site (which was otherwise perfectly usable) nagging me to "enable JS for a better experience"; curious, I did and was immediately assaulted with all manner of hostile and irritating crap like popups, text selection hijacking, and even attempts to disable the right-click menu. Hurriedly disabled JS again to regain sanity. Nope. I'm never falling for that again... Of course the problem these days is with sites that don't work at all without JS even if they're just static content, and I suspect part of the reason is to force-feed you the crap along with the real content.
- integralid 1y ago>and I suspect part of the reason is to force-feed you the crap along with the real content. Insert the quote about being malicious and incompetent. Modern frontend frameworks like react make sure that your site won't work without js at all, unless you intentionally put some work for that 0.1% of internet users who browse with js disabled
- memcg 1y agoNoScript also allows you to select which scripts you want to allow. It's not all or none. You can also view the source before you decide to let it run.
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- mixmastamyk 1y agoYou only have to whitelist your top sites once, not every day.
- userbinator 1y agoIt's quite telling that even the mobile version of Chrome, well known for being the most user-hostile browser, has the option to whitelist or blacklist JS and various other features like location access. Chrome didn't have anything other than a global JS on/off at first, so they clearly added this feature later.
- Sophira 1y agoWhen it was developed, uMatrix was a brilliant method of being cautious about what runs, and it had a logger so you could easily see what domains you should enable the current domain to have access to. I still use it honestly, but I'll need to move on at some point - not just because it's MV2-only, but also I've found a way in which uMatrix can be bypassed if a website were to specifically target it. (It doesn't affect uBlock Origin, although I haven't tested the Lite MV3 version.)
- SahAssar 1y ago> I've found a way in which uMatrix can be bypassed if a website were to specifically target it Please do tell.
- Sophira 1y agoI've been a bit wary of giving details due to it not getting updated. See my other comment: https://news.ycombinator.com/item?id=45085342 https://news.ycombinator.com/item?id=45085342
- neandrake 1y agoI'm a huge fan of uMatrix too, and have debated getting involved to help revive it. Can you share more information on the bypass you mention?
- Sophira 1y agoGiven that uMatrix isn't being developed any more, I've been a bit wary about sharing explicit details. I can say that the bypass works on uMatrix 1.4.4 (the latest release) and that even if you've disabled JavaScript from running via uMatrix - whether via a blacklist or via a whitelist - using this bypass will allow JavaScript to run on the page according to your browser settings. I haven't tested whether it allows the other elements that uMatrix can block - XHR, frames, etc - but I'm pretty sure that it does. I've been holding onto this info since the GitHub repository has been archived and read-only for years, and I'm not sure of the best way to handle it given that it's not being developed any more. I've wanted to get this out there but I want to make sure that people are safe, especially now that MV2 is deprecated, so there may be even less chance of an update. This is kinda new territory for me.