Live data from Hacker News

JavaScript is now required to sign in to Google

security.googleblog.com

401–410 of 529 posts

Re: JavaScript is now required to sign in to Google

#401

When I was at Google I started both the login risk analysis project and the Javascript-based bot detection framework they're now enforcing, so it's a pity to see so many angry comments. Maybe a bit of background will make it seem more reasonable. Firstly, this isn't some weird ploy to boost ad revenue. This is the login page - users are typing in a long term stable identifier already! The Javascripts they are requiri…

"Google had the ability to enforce a JS-required rule on login at least 6 years ago and never used it until now."

Um ... this should terrify everyone.

'We had the power to impose this, and we graciously chose not to. You should be thankful for what we have done.'

No. Just ... no.

Re: JavaScript is now required to sign in to Google

#402
post #399

Earlier quoted context omitted.

> Of course users are going to use javascript more, the more the internet demands it, the more people will be willing to allow it. I think you have this backwards; the vast majority of users like the benefits of js-enabled sites, so they get built. That ship has sailed long ago.

Even so, making the assertion that: "javascript adoption in the browser will increase in future, therefore we will enforce javascript" is like saying: "more people will have passports in future, therefore we require passports to get a bus pass". By doing that; you make it true.

It's already true. You can quibble over who's fault it was, but it really doesn't matter at this point. The web serves code that users run. That's because the web is the best distribution medium for code we've ever seen.

I bet you've also installed client side applications that came from the web, on a vendor installed OS that came from the web, and drivers for your machine that came from the web.

Re: JavaScript is now required to sign in to Google

#403
post #360

Earlier quoted context omitted.

Ah, you're assuming it's the same strength on all places it's used - and also that it actually has been bypassed. There didn't used to be any public bots that can beat the strongest version and from a quick Googling around I don't see that it's changed. Someone took apart a single program manually, years ago, but the programs are randomly generated and constantly evolve. So that's not sufficient to be able to bypass…

I understand this is not a subject where details can be shared, but - I'm sorry - at this level, this sounds like marketing speak. "You can't possibly comprehend just how advanced our AI is. If it appears stupid to you then because we intentionally want to have it appear stupid..."

Yes, I know. Nothing much that can be done about that, sorry.

The point I'm trying to get across is that companies use these techniques because they are effective - it isn't as simple as "some junk that was beaten ages ago" - and the collateral damage is very small, relative to other techniques. Far fewer users run with JS disabled than the number of users who struggle with CAPTCHAs.

We can see the direction things are going with reCAPTCHA v3, which appears to be the logical end of the path Google started walking 8 years ago - reCAPTCHA v3 is nothing but risk analysis of anti-automation signals.

Re: JavaScript is now required to sign in to Google

#404
post #71
post #57

Earlier quoted context omitted.

Do you have a better solution for differentiating yourself as an actual user from a robot spammer?

Being allowed to pay for services with money, rather than being required to pay for services with your personal data. I browse the web via a proxy when I'm on public wifi, and Google is nigh unusable with how many captchas it forces you to solve to do a single Google search. Fortunately Bing and DDG still work, for now.

A paid account is just as vulnerable to password theft as a free one.

Re: JavaScript is now required to sign in to Google

#405
post #393

I think this is a really braindead argument. Of course users are going to use javascript more, the more the internet demands it, the more people will be willing to allow it. When I first started using noscript there were few exceptional sites which didn’t work and I didn’t bother with them after, if that was the majority of sites, I would probably just disable noscript. The idea that I _have_ to let your site run cod…

Sorry, but you're out of touch. Almost everyone wants the features that JS enables. Literally: Almost everyone. I understand you don't, and I absolutely respect that decision, but it means that you're not worth developing for. Full stop. It's not a matter of mal-intent, it's a matter of financial logistics. You bought that machine to run code. If you don't want to run code that sites serve you on the internet, don't…

You're making an assumption about me, I actually don't use noscript these days (I haven't for at least 6 years at this point) however I will fight for the right of my brethren who do not have machines with six CPU cores and 64G of ram, or those who have had their scrollbars hijacked, or their text to speech software go insane, or their web experience which used to be controlled by them insidiously invaded by people who want to use their webbrowser as a software distribution platform and virtual machine.

Javascript being enforced allows for a sub-par slew of web development which does not cater for performance(minor) or accessibility(major).

I dislike the trend of _forcing_ people to do something that doesn't benefit them. Even if I'm not personally affected.

Re: JavaScript is now required to sign in to Google

#406

ITT: people dramatically under-estimating the risk to their accounts from credential stuffing and dramatically over-estimating their security benefits from not running JS. They're probably right that not running JS is privacy accretive, but only if you consider their individual privacy, and not the net increase in privacy for all users by being able to defend accounts against cred stuffing using JS. The privacy loss…

So what about a opt-out at account level? Something in the account settings, like this: [check] Allow sign-in from javascript disabled browsers. WARNING etc. (usual warnings about security etc.) Edit: because users who know to use long passwords and 2FA do exist and don't need all that extra security stuff ...

I don't understand why anybody concerned about having JS on a login screen would want to log into Google in the first place. I imagine there's a tiny overlap between "Runs NoScript" and "Trusts Google"

Re: JavaScript is now required to sign in to Google

#407
post #399

Earlier quoted context omitted.

Even so, making the assertion that: "javascript adoption in the browser will increase in future, therefore we will enforce javascript" is like saying: "more people will have passports in future, therefore we require passports to get a bus pass". By doing that; you make it true.

It's already true. You can quibble over who's fault it was, but it really doesn't matter at this point. The web serves code that users run. That's because the web is the best distribution medium for code we've ever seen. I bet you've also installed client side applications that came from the web, on a vendor installed OS that came from the web, and drivers for your machine that came from the web.

You're equating my signed/sealed/delivered package management to javascript??

??

??????

Really? You honestly don't see a difference? I have a chain of trust with my OS manufacturer (apple) and a defecto trust with a centralised entity for most of my applications (IE; my company for things that we build, or the home-brew project for most other packages)

I should not have that trust with any idiot who manages to get a signed SSL certificate; IE: the whole internet.

Re: JavaScript is now required to sign in to Google

#408

What a bunch of, excuse the language, paternalist fear-mongering bullshit. Of course Google wants you to enable JS, because it allows them to monitor and track everything about you more easily. Twisting it into "this will make you safer" is sad and undeniably repugnant. I've noticed a lot of other sites practically begging you to "enable JavaScript for a better experience", when all their content is static text and i…

Google's tracking everything you do on _their properties_ to begin with because they're a marketing company. Use DuckDuckGo if you don't like that. The pearl clutching in this thread is unreal.

Re: JavaScript is now required to sign in to Google

#409

When I was at Google I started both the login risk analysis project and the Javascript-based bot detection framework they're now enforcing, so it's a pity to see so many angry comments. Maybe a bit of background will make it seem more reasonable. Firstly, this isn't some weird ploy to boost ad revenue. This is the login page - users are typing in a long term stable identifier already! The Javascripts they are requiri…

Thanks so much for chiming in here. Admittedly, bot detection is really interesting to me as a subject. It's not the kind of thing you can throw infinite ML at and expect it to break even in terms of scaling; you need careful tuning and optimization baked in from the ground up, which means a fundamentally "manual" approach involving lots of lateral creativity and iteration. That creativity and one-upmanship (along ma…

I'm glad you're interested! The world could use more people tackling spam.

I'm not going to discuss signals for obvious reasons. Suffice it to say web browsers are very complex pieces of software and attackers are often constrained in ways you might not expect. There are many interesting things you can do.

I have no idea how much effort Google will make to support old browsers going forward, sorry. To be double-super-clear, I haven't worked there for quite a while now. Over time the world is moving to what big enterprises call "evergreen" software, where they don't get involved in approving every update and things are kept silently fresh. With time you'll see discussion of old browsers and what to do about being compatible with old browsers die out.

Straightforward login API: that's OAuth. The idea is that the login is always done by the end user, the human, and that the UI flow is always directly with the account provider. So if you're a desktop app you have to open an embedded web browser, or open a URL to the login service and intercept the response somehow. Then your app is logged in and can automate things within the bounds set by the APIs. It's a good tradeoff - whilst more painful for developers than just asking for a username/password with custom UI each time, it's a lot more adaptable and secure. It's also easily wrapped up in libraries and OS services, so the pain of interacting with the custom web browser needs be borne by only a small number of devs.

Re: JavaScript is now required to sign in to Google

#410
post #405

Earlier quoted context omitted.

Sorry, but you're out of touch. Almost everyone wants the features that JS enables. Literally: Almost everyone. I understand you don't, and I absolutely respect that decision, but it means that you're not worth developing for. Full stop. It's not a matter of mal-intent, it's a matter of financial logistics. You bought that machine to run code. If you don't want to run code that sites serve you on the internet, don't…

You're making an assumption about me, I actually don't use noscript these days (I haven't for at least 6 years at this point) however I will fight for the right of my brethren who do not have machines with six CPU cores and 64G of ram, or those who have had their scrollbars hijacked, or their text to speech software go insane, or their web experience which used to be controlled by them insidiously invaded by people w…

I'm sorry, but who is _forcing_ you to do anything?
Post reply on HN