Live data from Hacker News

JavaScript is now required to sign in to Google

security.googleblog.com

391–400 of 529 posts

Re: JavaScript is now required to sign in to Google

#391
post #358

When I was at Google I started both the login risk analysis project and the Javascript-based bot detection framework they're now enforcing, so it's a pity to see so many angry comments. Maybe a bit of background will make it seem more reasonable. Firstly, this isn't some weird ploy to boost ad revenue. This is the login page - users are typing in a long term stable identifier already! The Javascripts they are requiri…

Javascript ist also required for the vast majority of web-based exploits. I find it somewhat strange that you ask me to make my system less secure so you can better secure my account.

> the vast majority of web-based exploits

Do you have a source for that? As far as I know, most web based exploit came from any external plugin such as flash, pdf, videos, etc...

Re: JavaScript is now required to sign in to Google

#392

ITT: people dramatically under-estimating the risk to their accounts from credential stuffing and dramatically over-estimating their security benefits from not running JS. They're probably right that not running JS is privacy accretive, but only if you consider their individual privacy, and not the net increase in privacy for all users by being able to defend accounts against cred stuffing using JS. The privacy loss…

Passwords are obsolete - actual security would involve keys. The fact they have to care about automation for security instead of availability is a sign they have already lost. If you have a disposable EC2 server administration password accessible you are already doing it horribly wrong because you /will/ get attacked frequently. Javascript is opening an attack surface for what will certainly turn into an arms race an…

To be fair, Google released their own OTP hardware keys and have already 2FA login mandatory for accounts that they deem "high risk."

I don't think it's fair to blame them for the facts that most folks are not willing to give up passwords yet. Given that passwords are the current reality, shouldn't they do everything in their power to make them as secure as possible?

Re: JavaScript is now required to sign in to Google

#393
I think this is a really braindead argument. Of course users are going to use javascript more, the more the internet demands it, the more people will be willing to allow it.

When I first started using noscript there were few exceptional sites which didn’t work and I didn’t bother with them after, if that was the majority of sites, I would probably just disable noscript.

The idea that I _have_ to let your site run code on my machine is only laughable when it’s an exception, the problem is the industry. And google is telling the industry that it’s ok.

edit: yes, I understand; I'm over the hill and you all absolutely love shoving javascript down peoples throats, I get it. But please take a moment to consider... not? maybe you have a financial incentive to avoid thinking about the ramifications you inflict on others, maybe you're paid to be a JS dev. But really, if you're making the web worse, I will not cry for being downvoted, just know that I hate you. :)

Re: JavaScript is now required to sign in to Google

#394
post #9

This is coming right after the reCAPTCHA v3 announcement https://news.ycombinator.com/item?id=18331159 Sorry, you don't have enough Google Points to browse the web. Please enable JavaScript and install Google Chrome.

If you enable privacy.resistFingerprinting in Firefox you automatically fail v3 Captcha with score 0.1 People who want to try it out: https://recaptcha-demo.appspot.com/recaptcha-v3-request-scor...

Thanks! I filed https://bugzilla.mozilla.org/show_bug.cgi?id=1503872

When we have time we'll have to trace through what it's doing and what components of RFP are causing the failure. (If anyone wants to do that and report in the bug, we (Mozilla/Tor) would much appreciate the contributions!)

Re: JavaScript is now required to sign in to Google

#395
post #393

I think this is a really braindead argument. Of course users are going to use javascript more, the more the internet demands it, the more people will be willing to allow it. When I first started using noscript there were few exceptional sites which didn’t work and I didn’t bother with them after, if that was the majority of sites, I would probably just disable noscript. The idea that I _have_ to let your site run cod…

> Of course users are going to use javascript more, the more the internet demands it, the more people will be willing to allow it.

I think you have this backwards; the vast majority of users like the benefits of js-enabled sites, so they get built. That ship has sailed long ago.

Re: JavaScript is now required to sign in to Google

#396

Earlier quoted context omitted.

Recent new version of Google Mail flat out doesn't work to any usable standard in Firefox. Ten seconds to open a new 'compose mail' window. A context menu does a multi-second HTTP fetch before showing. The previous version worked great. Either the dev team has just given up on quality or they're intentionally goading me into installing Chrome. I'm not going to play that game -- at this point Thunderbird works better.

I’m a little surprised to read this because Google Mail works fine for me in Firefox (ArchLinux). In fact it’s smoother than some of the Electron-based clients I’ve tried and less painful than trying to get push messages on Thunderbird working (sure, there is always IMAP but that requires regular fetches).

FIY, IMAP actually allows "push messages" via the IDLE extension. If you use K9 on android, it's enabled by default. I never used gmail, but I'd be surprised if the gmail imap server didn't support it (and I would dismiss gmail entirely if it didn't).

Re: JavaScript is now required to sign in to Google

#397

Earlier quoted context omitted.

Ah, you're assuming it's the same strength on all places it's used - and also that it actually has been bypassed. There didn't used to be any public bots that can beat the strongest version and from a quick Googling around I don't see that it's changed. Someone took apart a single program manually, years ago, but the programs are randomly generated and constantly evolve. So that's not sufficient to be able to bypass…

It's a lot faster and more scalable to not automate a full web browser. Bot developers would rather not do it, they only do because they're forced to. Forced to ... by requiring Javascript, like this. In other words, the bot developers are still getting through, and meanwhile it's the actual humans who don't want JS which get screwed. Reminds me of DRM... honest customers are the most inconvenienced, while crackers s…

> In other words, the bot developers are still getting through

There's no perfect solution but any solution is still better than none. Why do you keep a lock on your door if I can break it in 30 seconds? Your computer is even there! I can easily add a key logger there, why do you have a password then if all I need is to do that? You aren't stopping me thus any protection you add is meaningless.

Let say that having a full web browser takes 50% more resources (if you block javascript, you probably already use the argument that it use 99% of your phone battery so you can agree that 50% is pretty conservative), than you just blocked 50% of the tentative JUST by requiring it. That's seems pretty effective already and you haven't done much yet.

Now add all the information that you can gather using Javascript. Aren't you also blocking Javascript because it's capacity to fingerprint you? Again another easy gain you can get.

> honest customers are the most inconvenienced

A tiny fraction of the honest customers are inconvenienced, a huge portion of them allow Javascript. They probably inconvenienced more by blocking older versions of TLS.

Re: JavaScript is now required to sign in to Google

#398
This is unfortunate. On all my phones, I find the most annoying malware is spread via javascript. I'll get onto a page I read a few times a day, and suddenly, thanks to ads, I am served some javascript malware that attempts to tell me "my PC is infected" or other such garbage.

I grouse, turn off javascript, clean my caches, and then everything is copacetic for a bit.

If this means that, thanks to google's decision, that I must in no uncertain terms, have javascript on in order to interact with their product line, then I need to weigh risks and benefits. Not proclaim loudly that I will run away from the google ecosystem, as many are likely proclaiming in this forum.

But weigh the risks of using products which require me to be vulnerable to attacks, versus alternatives.

From the viewpoint of google, you don't want your customer to ever be in that position. As it is an arms race against bad actors, and forcing users to effectively lower their defensive posture means you really ... REALLY ... need to up your game on value for this to be even net neutral relative to previous state.

Given how completely horrendous google's customer support is, and how incredibly hard it is to administer basic stuff (it took me more than 1/2 hour! to search and find out how to close an unused business g-suite account, which I couldn't do, until I manually disconnected from a marketplace product ... where this disconnection was also hidden ... google doesn't do ux/ui worth a crap, and has no real support for smaller users), I am not sure this is in their best interests. I am sure there is a product manager trying to pull them back from this ... somewhere ...

Or at least I hope so.

Basically the risk calculation is when where you look at something holistically. Is using the google universe worth the risk that universe forces you to accept?

Part of the reason that facebook is in user count freefall, is this inherent risk. You are volunteering info that advertisers are dying to get, and they are the ones paying facebook. You are a packaged product, you can be microtargeted, and various bits of self-serving posturing over election non-interference and account termination aside, they haven't quite grasped that this intimate relationship brings substantial risk for participants.

I've dropped messenger from my phone, and am about a few months away from dropping facebook from the phone. I don't need it there, and the risk to me is far higher than the "value" it brings.

Back to google. You don't want customers thinking this. You want them happily and securely playing in your garden. You don't want to force them to go out without their armor. Turning off javascript strengthens that armor. Forcing it on strips users of their most important armor.

Put more simply, bad google, bad.

Re: JavaScript is now required to sign in to Google

#399
post #393

I think this is a really braindead argument. Of course users are going to use javascript more, the more the internet demands it, the more people will be willing to allow it. When I first started using noscript there were few exceptional sites which didn’t work and I didn’t bother with them after, if that was the majority of sites, I would probably just disable noscript. The idea that I _have_ to let your site run cod…

> Of course users are going to use javascript more, the more the internet demands it, the more people will be willing to allow it. I think you have this backwards; the vast majority of users like the benefits of js-enabled sites, so they get built. That ship has sailed long ago.

Even so, making the assertion that:

"javascript adoption in the browser will increase in future, therefore we will enforce javascript"

is like saying:

"more people will have passports in future, therefore we require passports to get a bus pass".

By doing that; you make it true.

Re: JavaScript is now required to sign in to Google

#400
post #393

I think this is a really braindead argument. Of course users are going to use javascript more, the more the internet demands it, the more people will be willing to allow it. When I first started using noscript there were few exceptional sites which didn’t work and I didn’t bother with them after, if that was the majority of sites, I would probably just disable noscript. The idea that I _have_ to let your site run cod…

Sorry, but you're out of touch.

Almost everyone wants the features that JS enables. Literally: Almost everyone. I understand you don't, and I absolutely respect that decision, but it means that you're not worth developing for. Full stop. It's not a matter of mal-intent, it's a matter of financial logistics.

You bought that machine to run code. If you don't want to run code that sites serve you on the internet, don't visit them.

That said, I'd be willing to wager a fair bit that literally every line of code you've run on your machine (probably ever if it's been bought in the last few years) outside of the vendor installed OS and drivers came from the internet.

Post reply on HN