3 ms·
Knowing some folks that work on "major-browser-vendor" security in the era of Mythos-found-and-exploited vulnerabilities everywhere, the thought of running comp
by pcfwik 1mo ago
Knowing some folks that work on "major-browser-vendor" security in the era of Mythos-found-and-exploited vulnerabilities everywhere, the thought of running completely random untrusted Javascript on my machine has freaked me out to the point that I run NoScript on all of my machines now.
I've found NoScript actually very usable, as long as you allow yourself to be fairly liberal in marking domains "trusted." I only truly routinely visit a core 10-20 domains that require Javascript, and they're from "reputable" organizations (my bank, employer, etc.) so those all get marked "trusted" quickly and I don't worry about them going forward.
In the "long tail" of random things I click on from HN links, seeing a "You need to enable Javascript to view this app" message is actually a fairly good signal that I don't want to view that app (though you might be surprised how many websites are browsable comfortably---or even more comfortably!---without JS enabled).
One thing I wish NoScript supported was the ability to mark a domain as a "trusted page domain" in the sense of: "HTML served from this domain can load scripts from any domain" (rather than trust being assigned to the domain serving the script itself). Perhaps it has this feature and I just haven't found it.
https://noscript.net/ https://noscript.net/
- turpentine 1mo agoQubes OS is looking less crazy lately too.
- mitxela 27d agoQubesOS recently had an escape-the-qube-and-escalate-to-root exploit
- goodmythical 27d agoDidn't [insert literally any distro/operating system] have a root exploit recently?
- fsflover 24d agoWhich happened for the first time since 2006 (for the currently implemented architecture with VT-d).
- kogasa240p 27d agoIf they have a systemD-less version I'd seriously consider using it.
- fsflover 24d agoOn Qubes, everything runs in VMs, and you can choose many OSes for your VMs, including Devuan: https://forum.qubes-os.org/t/devuan-or-other-non-systemd-templates/14734 https://forum.qubes-os.org/t/devuan-or-other-non-systemd-tem... See also: https://forum.qubes-os.org/t/ultra-minimal-systemd-free-qubes/36575 https://forum.qubes-os.org/t/ultra-minimal-systemd-free-qube... https://forum.qubes-os.org/t/alpine-linux-template-non-official-available-for-testing/20595 https://forum.qubes-os.org/t/alpine-linux-template-non-offic... https://forum.qubes-os.org/t/systemd-inclusion-in-qubesos/22026 https://forum.qubes-os.org/t/systemd-inclusion-in-qubesos/22... The AdminVM is based on Fedora and has systemd, but it has no network and you you shouldn't run anything there. Unless you think that systemd is actively malicious and specifically targets Qubes, any vulnerabilities in it are not exploitable.
- wilkystyle 27d agoI do the same exact thing, except I disable JavaScript for all sites by default in uBlock Origin. Same experience as you, also: many sites actually work well enough without JavaScript, and the ones that do require it to display anything make me pause and ask if I truly want to give that site the privilege of running code on my computer. Majority of the time the answer is no.
- Panino 27d ago> also: many sites actually work well enough without JavaScript Some work better without JS. The most common are information-based sites with a paywall or signup or whatever. The JS loads some huge wall over the content. Bonus, no cookie popups or another annoyances, and most ads are loaded with JS. Popups are getting ridiculous.
- deleted 27d ago[deleted]
- Terr_ 27d agoI'm seriously strategizing how to best run a separate user-account for banking etc., to defend against a user-level compromise of my day-to-day stuff. It seems like anything that involves sharing a desktop window (e.g. xhost tricks) is not really security worth the effort, I've got to at least stop block any malware that monitors the screen, clipboard, keystrokes that come after the phrase "sudo", etc.
- pull_my_finger 27d ago> Knowing some folks that work on "major-browser-vendor" security in the era of Mythos-found-and-exploited vulnerabilities everywhere Is this a thing now? I hadn't seen any big browser vulnerabilities recently. Did I miss something? Or are the vendors not releasing horrifying bugs they found internally with AI fuzzing?
- pcfwik 27d agoIt's never clear what's "real" vs. marketing for the LLM companies, but Mozilla at least has made a big deal publicly about the "unprecedented" number of "latent security bugs" they've found using tools like Mythos: https://blog.mozilla.org/en/firefox/privacy-security/ai-security-zero-day-vulnerabilities/ https://blog.mozilla.org/en/firefox/privacy-security/ai-secu... https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/ https://hacks.mozilla.org/2026/05/behind-the-scenes-hardenin... To be honest, I'm not sure how many (if any) of them have actually been exploited, but in any case, it seems like the cost to at least find a vulnerability anymore has really dropped dramatically.