4 ms·
I don't often agree with Richard Stallman, but ... http://www.gnu.org/philosophy/javascript-trap.html http://www.gnu.org/philosophy/javascript-trap.html http:
by waps 12y ago
I don't often agree with Richard Stallman, but ...
http://www.gnu.org/philosophy/javascript-trap.html http://www.gnu.org/philosophy/javascript-trap.html
http://www.theguardian.com/technology/2008/sep/29/cloud.computing.richard.stallman http://www.theguardian.com/technology/2008/sep/29/cloud.comp...
The TLDR is simple : web apps makes Unisys, Microsoft, Apple, ... look like heroes of Freedom, even during their most anticompetitive days.
The worst behaviour microsoft ever exhibited is now standard practice. That's what web apps have gotten us.
That, of course, in addition to the fact that saying that the tools suck does not quite do justice to just how bad web development tools are.
- ewzimm 12y agoI do often agree with Richard Stallman, but... These are problems with particular web apps, not web apps in general. I host lots of web apps on my own servers, and they are just as free as any software, but I can access them anywhere from any device. In cases where web apps are non-free, I would have to say it's better than having them installed locally. Web browsers do quite a bit to keep apps in jails where they can't access and affect the rest of the system in the same way a local program can.
- waps 12y agoI disagree. The difference being : locally installed non-free web app app: not yours (BUT: communication between author and app is impossible if you want it to be) data: yours (meaning you can delete it) remotely installed non-free app app: not yours, and you can't prevent the author from updating their app under your feet. And the author can do nearly anything, meaning any encryption on your data is useless. data: not yours (meaning the author can read, change, delete, and you CANNOT unless the author, and anyone with a global root certificate (like Saudi Arabia, dozens of companies that have committed breaches of trust, ...) can mitm you, and gain the author's access to your data)
- ewzimm 12y agoNon-free web apps definitely come with their own range of problems. Data doesn't need to be out of your control though. JavaScript is usually run locally, so there are lots of calculations being performed by your computer before it reaches the remote server. For example, Mega encrypts data client-side before it is archived online. Just like with regular non-free software, you have to trust what it is doing. The best way to deal with these problems without throwing away non-free software would be to have security functions like encryption performed client-side with free software. I agree that server-run non-free software is neither safe nor private, but I still believe that this is the flaw of particular programs, not web-based software in general. It only emphasizes what a need there is for further development of open standards in web apps. But the ability to use a cross-platform browser as a universal client and run software that is built on the advantages of networking is a huge bonus for software in general. Free software just needs to catch up in a few areas, but in general it is dominating the backbone of the web. Now we just need to push that freedom forward to the user.
- waps 12y ago> For example, Mega encrypts data client-side before it is archived online. Just like with regular non-free software, you have to trust what it is doing. This is, sadly, not true at all. You have to trust 1) that the actual author of the site is playing fair 2) that you are not being mitm attacked by anyone in this list [1]. Note that 3 organisations on this list are known to have issued false certificates with the express purpose of stealing login credentials. They did this by sending through "amended" login javascript bundles. > I agree that server-run non-free software is neither safe nor private, but I still believe that this is the flaw of particular programs, not web-based software in general. It only emphasizes what a need there is for further development of open standards in web apps. No. Web apps can be replaced by malicious software every time you use it, and there is nothing you can do to prevent this. It is a fundamental design flaw of web based systems. And, of course, "cert pinning" simply means that a few organisations (google, facebook) get isolated from a few kinds of attacks. The flaw is that control is placed entirely in the hands of the remote side. Needless to say, this is not secure. I don't get where this idea of open standards being the solution to privacy problems comes from. Cookies are an open standard, the web is an open standard, TPMs are an open standard, the SSL certiciate chain principle is an open standard. Hell, microsoft palladium is an open standard. All are complete disasters for privacy and freedom. > But the ability to use a cross-platform browser as a universal client and run software that is built on the advantages of networking is a huge bonus for software in general. Free software just needs to catch up in a few areas, but in general it is dominating the backbone of the web. Now we just need to push that freedom forward to the user. I disagree. The web has brought back the "freedoms" of the mainframe era, only with a much bigger dependency on the mainframe system. Mainframes also in many cases ran free software. Can you claim with a straight face that a non-root account on a mainframe system is in any way free and private ? If you don't decide what software runs on your machine, like on the web, you have ZERO security guarantees. Zero. Nothing, nada, zilch, ... no matter how secure anything built on top of that is. I don't get why this is even the slightest bit controversial. [1] https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/included/ https://www.mozilla.org/en-US/about/governance/policies/secu...