As others have mentioned, nearly the entire internet breaks without javascript - it's a sad state of affairs. One protection I like to use is to disable javascript that is loaded over plaintext http - this breaks nearly nothing, and is easy to do via Chrome settings: https://i.imgur.com/NRVg5Xf.png
Chrome will always block an HTTP javascript call by an HTTPS page. So given the growing prevalence of HTTPS, I think this setting is probably doing less and less for you.
JavaScript is now required to sign in to Google
281–290 of 529 posts
Re: JavaScript is now required to sign in to Google
#282Re: JavaScript is now required to sign in to Google
#283Earlier quoted context omitted.
Modern cred stuffing is done by botnets. When I see a cred stuffing attack, it's maybe 1-3 attempts per IP address spread over 100-500k IP addresses. Often you'll have a family of legitimate users behind an IP address that's cred stuffing you at the same time. Throttling by IP address may have worked 10 years ago, unfortunately it's not an effective measure anymore. Modern cred stuffing countermeasures include a wide…
Any advice on where to read more about these modern cred stuffing countermeasures? I'd love to learn more.
Re: JavaScript is now required to sign in to Google
#284Earlier quoted context omitted.
> Throttle based on what? User Id?
That's the first obvious countermeasure and will prevent hackers targeting a specific account. But there are other ways to crack passwords, one is to try the same password but iterate over user ids instead. As hackers would start with the most common password you can't throttle globally on same password attempts either because well yeah, it is by definition the most commonly used one which should have a lot of traffi…
Re: JavaScript is now required to sign in to Google
#285Re: JavaScript is now required to sign in to Google
#286"When your username and password are entered on Google’s sign-in page, we’ll run a risk assessment and only allow the sign-in if nothing looks suspicious." In my experience (it is already the case with gmail and outlook up and now), this means I will not be able to login to my account when in holiday in another city, country, or when I use a borrowed device, or when I am behind VPN/Tor, etc, unless I give google my p…
Re: JavaScript is now required to sign in to Google
#287Earlier quoted context omitted.
Your first statement is incompatible with your second. (I think the second statement is reasonable, although I disagree with the conclusion). People aren't underestimating the risk to _their_ accounts, they are discounting the risk to _others_ accounts. That is, they're essentially saying, 'well, other users chose to have bad passwords, so bully them'. I think that's a fair viewpoint to have. We've entered a world in…
I think you may be giving people more credit than they deserve, but I'm willing to accept that they're making that argument. Even if that's their argument, that their personal habits around password use and being attentive to not being phished are so good they don't need Google's help defending themselves, so bully for everyone who does, I'm not convinced it's a good one. There are a few things needed for that to be…
You're right on, but I wouldn't call it sad.
The population is expected to operate vehicles without putting others in danger, not credentialize in how cars work. There are endless amounts of things we could demand people spend their precious time deeply understanding. We just like to demand tech-savviness because it's self-aggrandizing.
Like everything else, the solution is to help people on their own behalf.
At an online casino I once worked at, we ended up generating random passwords for our users. We had to, because otherwise attackers would lookup usernames in the large password dumps online and log in as our users. No amount of warnings on our /register page stopped password reuse. So we decided we could do better than that, and that "well, we warned you" was not an appropriate response.
If you look around at everyday objects, everything is designed to protect the user. But for some reason in computing we're still in the dark ages of snickering and rolling our eyes at users for making mistakes.
Re: JavaScript is now required to sign in to Google
#288"When your username and password are entered on Google’s sign-in page, we’ll run a risk assessment and only allow the sign-in if nothing looks suspicious." In my experience (it is already the case with gmail and outlook up and now), this means I will not be able to login to my account when in holiday in another city, country, or when I use a borrowed device, or when I am behind VPN/Tor, etc, unless I give google my p…
Re: JavaScript is now required to sign in to Google
#289ITT: people dramatically under-estimating the risk to their accounts from credential stuffing and dramatically over-estimating their security benefits from not running JS. They're probably right that not running JS is privacy accretive, but only if you consider their individual privacy, and not the net increase in privacy for all users by being able to defend accounts against cred stuffing using JS. The privacy loss…
So what about a opt-out at account level? Something in the account settings, like this: [check] Allow sign-in from javascript disabled browsers. WARNING etc. (usual warnings about security etc.) Edit: because users who know to use long passwords and 2FA do exist and don't need all that extra security stuff ...
Usually the login is in incognito, guest mode, and even from different locations and machines. Google asks for a second factor (i dont have it on for my accounts) like phone verification for my usual accounts (not so complicated password) but not for the one with complex password. So I think the level of extra steps/security is linked with how complex your password is. Not so sure if this is a good thing or bad. But, I hope they should continue basing their security measures based on the security measures you take.
Re: JavaScript is now required to sign in to Google
#290I'm not really sure how it works if you don't want to use JavaScript, do you then whitelist sites that you're ok with it? Wouldn't the solution for folks who don't want to run JavaScript just to whitelist it for Google? Maybe I'm missing something but that seems pretty simple, would let Google do their thing and the folks who don't want to run it run it just for Google and places they want to. If someone already does…
Unfortunately El Goog is now a de facto monopoly both for makers (organic traffic) and users (AMP, discovery, federated logins etc).
I'm not angry at Goog for winning, they did it by (mostly) being 100x more awesome than the competition and surfing the network effects into the endgame. But here's the elephant in the room: outside walled gardens, Goog runs da tubes, and they're not as fluffy as Mr Cutts would have you believe. Mandatory JS and AMP are the not-even thin end of the wedge.