7 ms·
Normalising running arbitrary code delivered over the internet (in the form of JavaScript and WASM), as a necessary condition for accessing most web pages may n
by publlus_enigma 1mo ago
Normalising running arbitrary code delivered over the internet (in the form of JavaScript and WASM), as a necessary condition for accessing most web pages may not have been one of the best decisions we have made.
- eru 1mo agoIn the future we can ask that your JaveScript and Wasm comes with a proof of being benign.
- valleyer 1mo agoPrior art: the evil bit https://datatracker.ietf.org/doc/html/rfc3514 https://datatracker.ietf.org/doc/html/rfc3514
- muvlon 29d agoWhat would that even look like? What is "benign"? The browser environment already has pretty strict rules for what the JS can do. It's not allowed to read your files, see your webcam without permission, know about other tabs or windows etc. The problem here is that the browser failed to correctly implement those rules. If the chromium team cannot do that, what makes you think they can implement any other kind of "benign code" verification with zero bugs?
- eru 29d agoTo give an example that goes beyond what you already suggested: You can prove that your code terminates (or rather responds to events in a finite time, even if the event loop itself runs forever.) Or you can even prove that your code reacts quickly, ie within some time limit. You can also prove memory limits. > The problem here is that the browser failed to correctly implement those rules. If the chromium team cannot do that, what makes you think they can implement any other kind of "benign code" verification with zero bugs? Defense in depth. And you can have competing implementations relatively easily for this, and another way to find and report bugs. Especially if the verifier is open source. The verifier itself can be pretty simple: it's the prover that's complicated and needs smarts, but that's being run on the author's computer, not in the user's browser.
- muvlon 22d agoI'll believe this when it's done. Nothing I've seen so far indicates that this would be feasible. As a practical counterexample, the Linux kernel has a verifier for eBPF code that is loaded by untrusted users. That is a much more constrained environment than JS, but they still constantly have verifier bugs. It's so bad that distros almost universally distrust the verifier and instead set things up s.t. only root can load any eBPF code.
- account42 27d agoIn practice it would be "big tech has provided a digital signature that the author has paid the required software tax".
- eru 27d agoSignatures are very different from proofs.
- asveikau 1mo agoI remember noticing this shift in nerd culture. In the early 2000s, it was common for people to say on places like Slashdot that they don't trust JavaScript and run their browser with it off. In the early 2010s, I noticed HN commenters thought this was insane, tinfoil hat type thinking.
- Espressosaurus 1mo agoIt became insane because nothing bloody worked without Javascript some time in the early 2010s. Like cellphones, javascript became necessary if you want to use webmail, access your bank's website, or whatever.
- nixosbestos 1mo agoI say this as someone does NOT disable JS in my main browser (because like, I have a job), but also knows a fair bit about why Firefox inside Tails now restarts in some cases... It's the classic thing. Across every gdmf metric, excluding with "true empathy", no one *gives a fuck* until it affects them, or someone within (1-3) degrees of separatation. And having broad empathy is generally a good way to get yourself labeled/astrocized: both about as obvious "compriate" and obvious "adversary".
- dbdr 29d agoIs compriate a typo, a neologism? I could not find a definition.
- abanana 29d agoThe end of that post came out in such a mess, it must be a typo for something - "compatriot" maybe? I like the other standout neologism in there though, I can see it in a dictionary now: astrocized - banished to outer space.
- nixosbestos 29d ago
- tcdent 1mo agoV8 as a runtime goes far deeper than just webpages.
- grishka 1mo agoRunning code by itself isn't that bad, it's the fact that browser developers have decided for some reason that this code needs to be as performant as possible, so, JIT. I don't get it! The way JS is typically used, it doesn't even benefit from JIT all that much. Making ajax requests, doing stuff with strings, and moving DOM elements around doesn't need every CPU clock cycle to be used as optimally as possible. It's exceedingly rare for websites to actually be doing something that needs raw performance. And SPAs will be slow no matter what.
- cute_boi 1mo agoAgree. Chrome should just disable JIT by default and boom many website owner will start to optimize their website.
- andrekandre 1mo agojira and confluence come to mind...
- macintux 1mo agoI suspect the people who agree to buy Jira & Confluence are not particularly heavy users of them. At least, that's the only explanation I can fathom for their continued sales.
- DANmode 29d agoEnterprise Software
- DANmode 1mo agoIs it their app’s features that are slow, or the analytics bolted on top?
- shakna 1mo agoBoth. And all the dependencies of both are slow. And the dependencies of those are slow, too.
- pizlonator 1mo agoI think the problem is that we've let JS engines become absurdly complex so there's no way to avoid them having really gross bugs. That said, I think that the V8 team has done a fantastic job of securing their engine. Their heap sandbox feature is really inspiring! It's really wild that (as far as I can understand this issue) someone is able to bypass it. (Posted from a memory safe browser - WebKit MiniBrowser compiled with Fil-C. Pretty sure this is safer than even V8 and the heap sandbox.)
- ruuda 29d agoIn Chromium you can turn off V8's JIT compiler for this reason. You can even opt in again for sites you trust that need the additional performance.
- a022311 29d agoI'm glad I've already done that! I haven't seen any difference in performance like others mention though. Weird. The only override I've made is for a website which needs to run some client-side cryptography code and it would take ages without the JIT.
- preg_match 29d agoThe additional performance from the JIT is actually really small for most tasks. It should, ideally, be disabled by default. For your average JS you get <10% performance gain. Most of the cost is browser API, not JS, so the performance is underwhelming. It’s only very heavy calculations that see a boost in performance. But, realistically, how many websites require this or currently use this today? <1%? Maybe <.1%? This is pretty typical across JIT engines, too. PHP also sees only a slight increase in performance from the JIT. Because of the nature of PHP applications, most time is spend on the network and database. Only very CPU-heavy code sees a significant speed up. That’s even the case for C#, which is why the dotnet runtime only conditionally JIT compiles code. Only hot path code is eligible for JIT compilation.
- kccqzy 29d ago
- flippingheck 1mo ago> decision we have made This might oversell the agency that practicioners have. Sandboxed zero-install delivery will outcompete anything with more frictionful installs. It's probably not the right model for a pacemaker though. Web/JS has been a double-edged sword for FOSS: sure, I can run a free OS, but if most of my "apps" happen to be JS that I can't practically control, then I have won a battle and lost a war.
- JacobKfromIRC 1mo agoI wish Haketilo [1] would have caught on more. There's so many free JavaScript apps but we're mostly just missing a way to actually control which version or derivative of the JavaScript is run. There's also the problem of most free apps not doing a good job of providing license info and a link to source code, but this could be sidestepped by a trusted repository which provides license info itself. [1] https://haketilo.koszko.org/ https://haketilo.koszko.org/
- robalni 29d agoThat's basically the comment I was just going to write but you made me not need to. We need simpler protocols and formats, especially those that are used over the internet. I want everyone to really start fighting for this. I always use a browser that doesn't run any scripts (w3m) for both this reason and others. It hurts when I see websites that don't work without js. A bit funny though that this page is one of them so I was not able to read it.
- Levitating 29d ago> We need simpler protocols and formats But we do! It doesn't get much simpler than HTML/CSS/JS. It's just abused to make apps instead of web documents.
- christophilus 29d agoHm. HTML, maybe. CSS and JS? No way. View the CSS here sometime: https://a.singlediv.com/ https://a.singlediv.com/
- Levitating 29d agoThat you can do complicated things with it does not make it complicated.
- antonvs 28d agoThere is no possible interpretation under which JS fits “simpler protocols and formats,” and no world in which JS could form part of a truly secure network client environment.
- phoghed 29d agoWe have them, and have had them for a long time. Nobody wants to use them.
- throwaway27448 29d ago> Nobody wants to use them. Wikipedia is basically the most popular application of all time and it doesn't rely on javascript. People just generally don't give a shit about where their money goes.
- dingdong2026 29d agoMy thought exactly. Which is why I have NoScript in my Firefox and have gotten used to manually enabling javascript for select pages. Small price to pay. Unfortunately the web is full of trivial websites that have no business running javascript. Recently wanted to read the famed post on Gates Notes. But for some reason Bill requires javascript to render text and images. Which reminded me Bill is not a person with good judgement on matters of IT and policy. Time saved.
- razemio 29d agoWow... I understand your point but if you feel that strong about gates using js on his personal website, it is a bit harsh isn't it? Could have multiple reasons why it is needed. Especially for someone with such a huge follower base. Lazy loading, tracking, client based adjustments, using a framework, fun [:)]... I could go on with a 100 more points why js might be needed.
- dijit 29d agoI know that this is sarcasm, but there are people who really think this. They get emotional (usually angry) when you tell them you disable javascript- as if every site that serves any kind of content has an automatic entitlement to run arbitrary code on your computer.
- choo-t 29d agoHTML has lazy loading. There not a lot of reason to not have at least a fallback to serve your text-only content without JS.
- razemio 29d agoThat is true, but it is very basic and depending on the browser how it is implemented. On traffic heavy sites, which I assume gates blog is, js gives you full control over what get loaded when and at the same time enables tracking how far the user read the article and which parts he most likely skipped. I am not saying that this is good, however if you have these requirements js is a valid choice.
- zahlman 29d agoAnd people ask me why I complain about web pages failing to display basic content without JS. (I keep WASM and WebGL disabled in Firefox settings, too. Yes, I had another post ITT questioning why those things are any less secure than the JavaScript, given that they're supposed to be in a sandbox. But you know, defense in depth. It's insane that we're expected to put up with these grossly unnecessary risks all the time. Just like how it's insane that frontier models are being tested in environments that are physically capable of connecting to the Internet at large.)
- xorcist 29d agoThings such as WASM and WebGL should really be click-to-play, just like media files are. I am decidedly uninterested in those features for most web pages I visit. Should they be able to spin up my CPU fan just for that I would consider it a misfeature. Just like a movie on high volume would be. If anyone familiar with Firefox could implement that or point in the right direction, that would be most welcome.
- throwaway27448 29d agoAt this point it doesn't even feel good to flex evidence of a warning But, anyone who thinks we need JS for a functional internet is fucking retarded
- IshKebab 29d agoRubbish, it was a great decision. So many websites wouldn't have been possible otherwise - Google maps, YouTube, ChatGPT, WhatsApp, etc. etc. Do you remember what the alternative was? Flash, Java, ActiveX. No thank you. Sure security is difficult but vulnerabilities of this magnitude are rare. If anything the lesson is don't write highly security sensitive software in C/C++.
- ptx 29d agoBefore JS and WASM we had arbitrary code delivered in the form of ActiveX components, Java applets and Flash applications, which were much worse. At least now we have multiple open source implementations of the runtime.
- DangitBobby 29d agoControversial opinion on this website ;)
- account42 27d agoYes it's been a disaster for accessibility, compatibility, interoperability, energy efficiency and computing freedom (good luck using a Browser not approved by Buttflare). The security implications are just the cherry on top.