sent from a disposable whonix qube

  • keiko@fedia.ioOP
    link
    fedilink
    arrow-up
    0
    ·
    13 days ago

    @OwOarchist@pawb.social Honestly, it’s bonkers that the standard, default approach for all mainstream browsers is to let every random website in the world run any arbitrary code it wants on your computer.

    This, this, 1000 times this! That is exactly how I feel and was hoping to convey.

    @OwOarchist@pawb.social Yeah, they usually attempt to sandbox it, but still. Sometimes sandboxes can be escaped. And sometimes the code can do significant harm while still inside its sandbox.

    Yes, defense-in-depth includes minimizing threats rather than simply relying on protections. It shouldn’t be necessary to lower one’s shields constantly, and it’s better to avoid doing so if possible, from a security & privacy perspective.

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      0
      ·
      13 days ago

      @rtxn@lemmy.world Sure, it’s bonkers for you, but an alternative browser that can’t immediately show a website that works perfectly well in Chrome wouldn’t get much of a user base.

      I think the main point is about what is default. People have been and continue to be trained by the defaults (tyranny of the default), and in this case they are trained to expect sites to utilize scripts, which is (imo) unhealthy for society. It would be better if scripts were denied by default and the user could allow them per-site with a single click, similar to how sites will ask the user to allow notifications or location services which the user is able to allow or deny.

      Sure, most users simply allow everything. But kids are curious and would be more likely to read and understand such things if presented with the options, and that could translate into a more-informed adult population with better security practices. And overall, I think that’d make for a healthier and happier society which doesn’t continue to crumble into worse and worse outcomes.

      If the default were to deny scripts, sites would have to at least look somewhat presentable without the scripts, so as to ask the user to enable them. And my hope is that people would prefer the sites that don’t pester them for permissions.

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        0
        ·
        13 days ago

        @wonderingwanderer@sopuli.xyz That’s the problem though, why is it standard for websites to be built in such a way that their basic functionality depends on allowing such arbitrary scripts? Shouldn’t there be some regulatory body that tells them that’s against the rules or something?

        @rtxn@lemmy.world Do you want regulatory overreach?

        @wonderingwanderer@sopuli.xyz I don’t view basic consumer rights as “regulatory overreach.”

        @rtxn@lemmy.world Imagine forcing every small project or self-hoster to adhere to the rules set by the equivalent of the HDMI Forum, but controlled by the likes of Microsoft and Facebook.

        @wonderingwanderer@sopuli.xyz No and no. I never said it should be corporations setting the standard. That’s the FCC’s job, and comparable agencies in other countries. The FCC already regulates many things about the internet. Some things they don’t regulate enough. […]

        […]

        Also, there’s such thing as the IEEE. Standards for web development are not unheard of, and they’re not categorically wrong. There need to be rules governing the rules that govern web development to ensure those rules aren’t abused. But setting no rules or standards would be insane.

        @rtxn@lemmy.world To redirect your other question: you should ask the web developers. If they’re honest, you’ll get a dozen legitimate answers that can’t be solved without locally running code.

        @wonderingwanderer@sopuli.xyz That’s not honesty. That’s deflection and dissembling. Sure, you can think of a dozen different reasons why scripts need to be run locally. But that doesn’t excuse using those scripts as a trojan horse for malicious data mining practices. Permissions can be atomized.

        If a web developer can’t compartmentalize the part of the script that loads an image on their website from the part of the script that harvests sensitive fingerprinting data that the website has no legitimate need for, then they’re either a really bad developer who’s never heard of modularity, or they’re doing it deliberately and maliciously because they know they can get away with it and are choosing to make their website break for anyone who doesn’t let them basically peep under their device’s skirt.

        Oh la la!

        • keiko@fedia.ioOP
          link
          fedilink
          arrow-up
          0
          ·
          13 days ago

          @Kangae_Hishiryo@scribe.disroot.org I get your point, yeah. I actually do think that scripts should’ve hugely modularized, compartmentalized, and browsers should’ve using OCaps instead of ACLs, or at least make more granular ACLs so you can finetune what can or what cannot do a given site and/or a given script.

          @wonderingwanderer@sopuli.xyz Thank you! It seems pretty clear to me, modularity is supposed to be the modern standard for quality code, so why are we normalizing websites that use scripts with more arms than Cthulhu harvesting uniquely identifiable data from our personal devices by running arbitrary code locally? It seems insane to me…

          “One tool for one job.” It’s pretty basic Unix philosophy. So why do we now have “One script for several hundred different fingerprint variables, oh and also the website’s basic functionality”?

          @Kangae_Hishiryo@scribe.disroot.org *A wild Systemd spawns*

          @wonderingwanderer@sopuli.xyz You can’t escape!

          This kinda brings the thread full-circle back to my os tier list :D

          • wonderingwanderer@sopuli.xyz
            link
            fedilink
            arrow-up
            0
            ·
            13 days ago

            Oh, you made that one? I actually saved it because it’s legitimately helpful. A lot of tier lists really just reflect a person’s preference, but I liked how you grouped yours by category. I’ll be referencing it as I explore more distros

            • keiko@fedia.ioOP
              link
              fedilink
              arrow-up
              0
              ·
              13 days ago

              I feel kinda weird replying since my comment to which you replied was removed by a mod, and I have no idea why, as there is no reason given in the mod log. I had been trying to respond to the messages which I was and am unable to directly access, due to my instance’s defederation policies, but it seems that I’ve inadvertently upset someone and feel that I should probably stop interacting here, so as not to cause problems.

              Thank you for your appreciation 🩷

              • wonderingwanderer@sopuli.xyz
                link
                fedilink
                arrow-up
                0
                ·
                12 days ago

                Ah, that’s strange. Sorry that happened to you. Maybe the mod missed you’re top-level comment where you explained so they thought you were spamming.

                Have a nice day

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        0
        ·
        13 days ago

        @hirihit640@sh.itjust.works Just another piece of evidence that people care more about convenience than privacy, sadly. People aren’t willing to put up with a single broken website

        Au contraire. Most people put up with broken sites all the time. The problem is that those people generally aren’t aware that the sites are broken, because they’re also unaware of the concept of allowing/denying javascripts. If they denied javascripts by default, they’d notice that most of the sites they access are actually broken sites. The ones that function without javascripts are the unbroken ones.

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        0
        ·
        13 days ago

        @chonglibloodsport@lemmy.world Most websites from when I was a kid did not need JavaScript. Heck, they didn’t even have any JavaScript on many of them! No CSS either, just HTML and images (which were very slow to load on dialup).

        Simpler times

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        0
        ·
        13 days ago

        @OwOarchist@pawb.social But a lot of those websites could function without javascript. A lot of websites use it unnecessarily, for reasons such as:

        • They want their ads and trackers and other malicious code (such as soft paywalls) to work as intended.

        • They want to add fancy cosmetic elements to the content and are too lazy to think about failing gracefully and still displaying the content if javascript isn’t working.

        • They built the website in a framework that depends on javascript, and are again too lazy to bother worrying about graceful failure if javascript isn’t working, even if their content could, in theory, be displayed just fine without it. (Or maybe the framework developers deserve a bit of the blame for that laziness, since they could have made graceful failure a feature of the framework, but chose not to.)

        In a hypothetical world where most browsers didn’t allow every website to run arbitrary code, then every website would be forced to take that into account and only depend on javascript when it’s absolutely necessary for the website’s core functions.

        Perfect comment. No notes. <3

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      0
      ·
      13 days ago

      @cley_faye@lemmy.world Bugs exists. But JavaScript running in the browser have, theoretically, little access to anything. […]

      The risk of allowing JavaScript on a website is more tied to the site data, or tracking. […]

      It doesn’t mean every site needs JavaScript, but having this enabled by default is not that big of a security risk for the system. […]

      This reminds me of an interesting phenomenon: Some security-oriented people praise the security of the surveillance-advertising corporation’s browser engine (chromium), while proclaiming that gecko-based browsers (firefox) are unusable due to inferior security. Yet the main security threat I see is that fucking surveillance-advertising corporation which spreads unvetted and often malicious ads around the web without a care in the world.

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        0
        ·
        13 days ago

        Person A: “chromium-based browsers have superior security” Person B: “i use firefox-based browsers exclusively” Person A: “outrageous. it’s got inferior security” Person B: “i don’t allow scripts” Person A: “javascripts aren’t a major security concern” Person B: “firefox with scripts denied is more secure than chromium with scripts allowed” Person A: “javascripts are required for the modern web” Person B: “untrue, as evidenced by the fact that i access the modern web with scripts denied”

        checkmate ♟️