4 ms·
Depending on the number and variety of sites that you visit, enabling javascript universally is hazardous. You can easily observe this to be true by clicking 30
by nanoscopic 12y ago
Depending on the number and variety of sites that you visit, enabling javascript universally is hazardous. You can easily observe this to be true by clicking 30-50 links randomly as fast as you can in your browser. You will find that inevitably your system will become infected with malware in the process of doing this, regardless of protection.
Generally for accessibility purposes websites should be designed so that basic text and links appear and are functional with JS disabled, and even CSS disabled. If the website is some sort of dynamic application with moving widgets than I can understand that JS might be needed, but not for a basic list of project Microsoft has put on Github.
Even if JS is used for templates, it is preferable to use semantic HTML that can be enhanced rather than using a template for the entire page and show "{tags}" all over the page when JS is disabled.
TLDR: A page with a basic list of projects shouldn't need JS. Web applications: yes, basic lists: no.
- adam12 12y ago> clicking 30-50 links randomly as fast as you can in your browser This will not give you malware. It might temporarily bog down your system though.
- nanoscopic 12y agoThis is not a naive statement by me caused by assumptions. I actually did exactly this with a patched modern browser and good antivirus and my system became infected in the process. Mind you I indiscriminately clicked on known "bad" advertisements in the process of doing this. Don't believe me? Try it for yourself. It is actually very easy to get malware if you click around foolishly. Also, I have written multiple web crawlers, and have collected a large variety of JS based malware that can and does break modern browser security just in the process of fetching domain homepages. ( JS code embedded directly in index.html on domains )
- adam12 12y ago> Mind you I indiscriminately clicked on known "bad" advertisements OK
- MichaelGG 12y agoIf you're correct, you've uncovered some 0days in the wild. Go figure out which site, capture what happens, and turn it in to the respective browser developers for a nice bug bounty. Or, you know, maybe they aren't wasting a 0day on "obviously bad advertisements".
- nanoscopic 12y agoThat's actually a really good idea. Thanks. :)