Earlier quoted context omitted.
I agree, and on my computer I disable custom fonts in the web browser anyways. A better web browser is really needed; one of things it can have is support for the Gemini protocol and file format. (It can also omit many things, as well as adding things.)
What else to omit? Not snark. I'm playing with a Firefox fork and ripping stuff out (pocket).
Hackers used zerodays to infect Windows, iOS, and Android users
131–140 of 156 posts
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#132Earlier quoted context omitted.
I have a $12 flip phone, pay as you go, not in my name. It can't browse the web and if someone sends me binary data in a text message its shows up the same as if I read binary data in my terminal. The phone has no idea what to do with it. Battery life would be great if the did not remove the cell sites near me. I think this model was replaced by one that is $29 but its basically the same thing. Check Walmart or an eq…
I would do that also, if I could replace the live traffic of google maps. Did you find a solution to that, or do you just not need it?
b) Google Maps could advice direction to some smaller not so well maintained roads, that could increase travel time a lot, or lead to some road where it's hard to turn back. So maybe planning ahead and writing driving instructions at home before driving would be better. Or just trying to follow main street signs for major roads.
c) There are some DIY projects like Raspberry Pi navigator: https://www.raspberrypi.org/forums/viewtopic.php?t=70517
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#133Earlier quoted context omitted.
The only thing that comes to mind is having most websites be sites and not apps . Most sites don't need custom fonts, JavaScript, and CSS. If Firefox & Chrome had support for something lightweight like Gemini ( https://gemini.circumlunar.space/ ) then most sites could just use that. With that sort of setup, restrictions on the web like uMatrix would be a lot less painful because most sites wouldn't ever need to be wh…
>If Firefox & Chrome had support for something lightweight like Gemini ( https://gemini.circumlunar.space/ ) then most sites could just use that. But they wouldn't, because they couldn't track people.
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#134Earlier quoted context omitted.
Microsoft aren't going to care. Then the obvious solution is to make them care. We penalise corporations for financial negligence and failing to take proper precautions and report correctly. We increasingly penalise them for violations of privacy and data protection rules, where similarly they are expected and required to provide adequate infrastructure to comply with the regulatory obligations. If failing to impleme…
There isn't law that mandates they split security updates from feature updates. What if they rewrote a component to have new features and it also fixed a security issue? What's the difference between a security patch and a bug fix? At the end of the day if someone gets so angry that Microsoft added Paint 3D in an update that they disabled updates. What's the obligation here? They chose not to update their computer.
I'm suggesting that perhaps there should be.
In what other area of consumer protection law does a manufacturer or reseller get to provide a seriously defective product and then refuse to deal with the problem unless the buyer also accepts other changes that might make the product significantly different and possibly in their view significantly worse than the one they chose to buy?
The principle is important here. Your example about Paint 3D is cute, but in reality, there are plenty of other examples where user-hostile software changes have been pushed out after purchase, including those that disabled previously available functionality, reduced privacy, introduced advertising, or dramatically changed the look and feel of the product. People shouldn't be forced to accept these kinds of unwanted retrospective changes to the product they originally chose to buy just to maintain an adequate level of security.
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#135I said this once and I'll say it again: To counter such threats we need a healthy heterogeneous ecosystem. According to the article, the attack would have been prevented by using Firefox, (because it relied on a Chrome CVE). It also did not work on Linux and presumably not on Apple's ARM CPUs. But unfortunately we don't get exponential security. Normally, one would expect that n variables (Browser, OS, CPU architectu…
Hmm, anyone else find this interesting? I haven't looked into the actual exploit itself yet, but having it work on Android, which has SELinux and/or other protections by default, but not on (presumably) a generic Linux distro, is weird.
I would have assumed it exploited something present only on mobile builds of Chrome, but it affects Windows as well. Odd.
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#136I said this once and I'll say it again: To counter such threats we need a healthy heterogeneous ecosystem. According to the article, the attack would have been prevented by using Firefox, (because it relied on a Chrome CVE). It also did not work on Linux and presumably not on Apple's ARM CPUs. But unfortunately we don't get exponential security. Normally, one would expect that n variables (Browser, OS, CPU architectu…
> It also did not work on Linux and presumably not on Apple's ARM CPUs. Hmm, anyone else find this interesting? I haven't looked into the actual exploit itself yet, but having it work on Android, which has SELinux and/or other protections by default, but not on (presumably) a generic Linux distro, is weird. I would have assumed it exploited something present only on mobile builds of Chrome, but it affects Windows as…
The Android vs Linux part still stands though.
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#137Earlier quoted context omitted.
>If Firefox & Chrome had support for something lightweight like Gemini ( https://gemini.circumlunar.space/ ) then most sites could just use that. But they wouldn't, because they couldn't track people.
Why do you think firefox is tracking you?
They wouldn't use it (or the VAST majority wouldn't) because it means losing tracking.
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#138Hackers ARE using zerodays to infect EVERYTHING. I really can't understand why people continue to just assume that their endpoints and networks are clean. Worse, they then use the lack of security events to justify not buying the tools and expertise that are necessary to identify compromises. EDIT: not just zerodays. Many organizations have patch schedules that are too slow.
I think the average person doesn't know how to prevent it and believes that learning out would be beyond their abilities.
If they did, there would be more effort and knowledge about the subject
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#139Earlier quoted context omitted.
What else to omit? Not snark. I'm playing with a Firefox fork and ripping stuff out (pocket).
Could I make a suggestion? It'd be great if it were possible to white-blacklist all web features? We can do this for some features like location, but I can't selectively turn off images, JavaScript, or web fonts (only globally). It might be nice to have a prompt like "This page wants to use a web font" like how you get for location. I realize that may be a lot of work to add in though. Really, I'd just like to re-ena…
Prompts do help, but the prompt should allow the user to allow or block once or always, and to override settings too (e.g. for location, the user can optionally specify a location to use, or specify a command-line of a program that provides the location; for camera, the user can specify the path to the device or to a picture or video file, or a command-line of a program that will produce the picture). The user can then specify whether or not to always make this selection in the future, and in what scope. If the site uses TLS, or is a local file which has been digitally signed, then the user can optionally specify certificate pinning too, in which case the automatic selection will be ignored if the certificate does not match.
I also have other ideas, about meta-CSS, presentation mode, table of contents window, animation skipping, capability of loading animated GIF and PNG files as videos (so that you can rewind and pause it), better keyboard controls, save form data to local files, regular expression search, full cookie editor, SQL access to HTML tables, Xaw-style scrollbars, relative location bar, ARIA view, etc. Most of this is configured and/or activated only by the end user, not by the document. Although, some are capable in the document too, such as, a HTML document with a referencing a GIF or PNG will work; such a file can be loaded with or and either way would work.
No "do not track" setting is needed. My idea is the user could set up request headers arbitrarily, as well as overriding response headers (including some "protected" ones, which are stripped if received from a remote site, so are only effective if set up by the user). For example, to enable "do not track", you can add the rule which adds the request header "DNT:1" with the criteria specified as "always".
I would also ensure that all timing APIs can be spoofed (including the JavaScript core Date object; in my opinion this is an I/O function so it shouldn't belong in the core). This is probably useful for testing, as well as for the end user to get rid of annoyances too.
Re: Hackers used zerodays to infect Windows, iOS, and Android users
#140Earlier quoted context omitted.
What else to omit? Not snark. I'm playing with a Firefox fork and ripping stuff out (pocket).
Rip out the clipboard API along with all the other functions that allow sites to manipulate text selection semantics, sticky overlays, and all of the other UX garbage that has accumulated over the years.
In normal view and ARIA view, the viewport height would always be reported as Infinity. In print preview and in presentation view (which is a paged/screen media type), the viewport height is reported correctly.