Live data from Hacker News

JavaScript is now required to sign in to Google

security.googleblog.com

141–150 of 529 posts

Re: JavaScript is now required to sign in to Google

#141

Earlier quoted context omitted.

Switching email providers is reasonably painless, fwiw. Set up forwarding, migrate mail when you can. Even better if you set up the majority of your non-security-essential mail to be at your own domain, hosted by Fastmail/etc. Then you can easily change your email provider and your contacts don't even care. I've yet to implement this is in my own life, I just switched to fast mail - so I can't speak from personal exp…

I switched to Fastmail years ago and it was the best mail-related thing I ever did. I was dreading the migration but it literally took ten minutes, switch DNS records (I have my own domain), run Fastmail's import, done. I still can't believe how fast the UI is. It's by far the fastest web app I've ever used, and the same goes for the service in general. Seriously, just ditch Gmail now, the alternatives are great.

Gmail is more than just mail, it's also integration with other Google services, like calendar. How does Fastmail fare in that regard?

Re: JavaScript is now required to sign in to Google

#142

Earlier quoted context omitted.

Recent new version of Google Mail flat out doesn't work to any usable standard in Firefox. Ten seconds to open a new 'compose mail' window. A context menu does a multi-second HTTP fetch before showing. The previous version worked great. Either the dev team has just given up on quality or they're intentionally goading me into installing Chrome. I'm not going to play that game -- at this point Thunderbird works better.

Switching email providers is reasonably painless, fwiw. Set up forwarding, migrate mail when you can. Even better if you set up the majority of your non-security-essential mail to be at your own domain, hosted by Fastmail/etc. Then you can easily change your email provider and your contacts don't even care. I've yet to implement this is in my own life, I just switched to fast mail - so I can't speak from personal exp…

Last time I tried fast mail they didn’t really support labels, only folders. Is that still the case, or is there a good workaround?

Re: JavaScript is now required to sign in to Google

#143
post #137

Earlier quoted context omitted.

ha well turn off javascript too and you won't be able to use even hackernews, so good luck with that.

Hacker News works perfectly fine without Javascript. In fact, I don't think I've ever enabled Javascript here on Hacker News.

> Hacker News works perfectly fine without Javascript.

keyword being "too".

> In fact, I don't think I've ever enabled Javascript here on Hacker News.

I mean, that's super, but it's just one more point in the column of how HN's population is out of touch with any regular person. It's really annoying to wait for the page reload on even a fast network, and good luck finding your place again if a thread is even moderately busy.

Re: JavaScript is now required to sign in to Google

#144

What a bunch of, excuse the language, paternalist fear-mongering bullshit. Of course Google wants you to enable JS, because it allows them to monitor and track everything about you more easily. Twisting it into "this will make you safer" is sad and undeniably repugnant. I've noticed a lot of other sites practically begging you to "enable JavaScript for a better experience", when all their content is static text and i…

> Browser exploits are almost all JS-based, and even the few that aren't, are in practice deployed using obfuscation involving JS, to make analysis and detection harder. Go take a look through Pwn2Own. Most browser exploits do not involve JavaScript. JavaScript can be a delivery mechanism for a certain class of payloads, but it's not the substantial weakness in browser vulnerabilities (as opposed to web application v…

The security bugs found during Pwn2Own are usually kept under embargo, and only published later by the browser developers. Here's an article about a Chrome bug found in 2017's Pwn2Own:

https://www.computerworld.com/article/3186686/web-browsers/g...

and it does involve JavaScript. Could you provide some recent examples of the sort of browser exploits you mean, that don't require JavaScript? (I assume you're not including exploits in extensions/plugins like Flash or PDF viewers.)

Re: JavaScript is now required to sign in to Google

#145

Earlier quoted context omitted.

I switched to Fastmail years ago and it was the best mail-related thing I ever did. I was dreading the migration but it literally took ten minutes, switch DNS records (I have my own domain), run Fastmail's import, done. I still can't believe how fast the UI is. It's by far the fastest web app I've ever used, and the same goes for the service in general. Seriously, just ditch Gmail now, the alternatives are great.

Gmail is more than just mail, it's also integration with other Google services, like calendar. How does Fastmail fare in that regard?

I wouldn't know, I have a self-hosted calendar. From the little I've seen, though, the calendar part of Fastmail is very good too.

Re: JavaScript is now required to sign in to Google

#146
I try hard not to be a luddite as I age, but this level of automation and machine learning is so concerning.

It is SO frustrating to accidentally appear as a bot and get stuck at the mercy of an automated system. I was on some random site the other day and spent 3+ minutes solving Captchas until it finally let me through. I thought I was losing my mind. I don't spam, I don't automate queries, I come from an IP that has two residential users (netflix, xbox traffic dominate everything). Who knows what I did to offend the algorithm.

Re: JavaScript is now required to sign in to Google

#147
post #68

Earlier quoted context omitted.

Running untrusted code on your machine _is_ a bad thing though.

Yeah, because permissions, sandboxing, and access controls don't exist. Oh wait, they do, and they work, so you're wrong.

No, they don't always work. We have bullet proof vests but it's still not safe to put one on and have someone start shooting you.

Re: JavaScript is now required to sign in to Google

#148

ITT: people dramatically under-estimating the risk to their accounts from credential stuffing and dramatically over-estimating their security benefits from not running JS. They're probably right that not running JS is privacy accretive, but only if you consider their individual privacy, and not the net increase in privacy for all users by being able to defend accounts against cred stuffing using JS. The privacy loss…

And indeed it's time to give up on the web being a document format only. The internet is about loading remote applications in your local sandbox. That's what it is. It sucks, but it is what it is. As part of loading remote applications, we now might be asked to compute whatever anti-abuse puzzles are required. So it goes.

Re: JavaScript is now required to sign in to Google

#149
post #4

0.1% of Google's users is still quite a lot of users, is it not? Somewhere over a billion, perhaps, which would mean 1 million+ with JS off.

I'm gonna wager that 0.1% of users who don't or can't run Javascript aren't very valuable to Google.
Post reply on HN