4 ms·
Web security wasn't hard before we started trying to make the web a platform for full executable software. I never got hacked through the web before JavaScript
by LocalH 2mo ago
Web security wasn't hard before we started trying to make the web a platform for full executable software.
I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).
JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.
Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.
- OkayPhysicist 2mo agoNone of this required Javascript. At all. The same potential attack could have been done with good ol' forms. Sure, you think you're signing into "BigBensSuperStore.com", but you're actually handing your credentials right over to "BigBensSuperStore.net".
- LocalH 2mo agoJavaScript (and other forms of executing logic within the browser) have made the situation worse, though. To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.
- saghm 2mo agoIf a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.
- LocalH 2mo agoBad actors have been social engineering passwords for years even before a single line of JS was written. Restricting the backend is a way of heavily reducing the attack surface. The expansion of hardware access to browsers is the largest scam enabler of the 21st century. The only reason it's happening in the long term is because companies like Google (DoubleClick) wish to use hardware attestation to tie people to hardware for advertisement purposes, and that requires complete vertical attestation. We're losing general-purpose computing like frogs in a slow cooker, and millions of people don't even notice. Fuck TPM, fuck hardware attestation, no internet company should get a single bit from me that I don't authorize. Any site that requires hardware attestation will be a hard "no" for me to ever visit again. I maintain this all started when commerce was introduced to the internet. Things were better before money was transferred digitally. Allowing that was a major fuckup.
- applfanboysbgon 2mo ago> "The web" was never designed to be an application platform. It was only designed to be a document platform. And then it expanded to serve the needs of billions of people instead of the needs of a few researchers. Womp, womp. Get over it, use a JS-free browser to browse your documents, and accept that the world has moved on. Or don't, and rant at clouds, I guess.
- inigyou 2mo agoYou realize the same argument applies to Word macros.
- LocalH 2mo agoI think someone should ask Vint Cerf whether he ever intended the web to run executable code, and enforce that answer on the existing web. I bet the world would crumble. Good.
- applfanboysbgon 2mo agoThis is base stupidity. Suppose you used your web-dictator powers to strip JS from the web based on historical decisions made 50 years ago. Then everyone other than you would use Web2 and ignore you. Indeed Web 2.0 is already a term recognising that the web has changed since it was first conceived; I guess it would make you feel better if we formalised it and formally created a new Web that's exactly like the current Web except with nobody who can claim things about how it was "supposed" to work in the 1970s?
- LocalH 2mo agoClearly you have a vested interest in the status quo of today, instead of understanding why the whole network was created in the first place. Your viewpoint enables billions of dollars of fraud every year, worldwide. Mine doesn't. Email has similarly been destroyed by HTML email, at least partially. It's like there is a coordinated effort to destroy every single legacy protocol and replace it with something centrally controlled. No fucking thank you.