Live data from Hacker News

Web Security is Too Hard

textslashplain.com

101–110 of 127 posts

Re: Web Security is Too Hard

#103
post #93

Earlier quoted context omitted.

> "The web" was never designed to be an application platform. It was only designed to be a document platform. And then it expanded to serve the needs of billions of people instead of the needs of a few researchers. Womp, womp. Get over it, use a JS-free browser to browse your documents, and accept that the world has moved on. Or don't, and rant at clouds, I guess.

You realize the same argument applies to Word macros.

I think someone should ask Vint Cerf whether he ever intended the web to run executable code, and enforce that answer on the existing web.

I bet the world would crumble. Good.

Re: Web Security is Too Hard

#104
post #83

Earlier quoted context omitted.

The point is to show how AI you are.

Why would Cloudflare want to lose credibility and reputation though? Doesnt seem to make sense.

Credibility and reputation with who? Their target audience is rich people, who love AI.

Re: Web Security is Too Hard

#105
post #62
post #39

Earlier quoted context omitted.

JavaScript (and other forms of executing logic within the browser) have made the situation worse, though. To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.

If a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.

Bad actors have been social engineering passwords for years even before a single line of JS was written. Restricting the backend is a way of heavily reducing the attack surface. The expansion of hardware access to browsers is the largest scam enabler of the 21st century. The only reason it's happening in the long term is because companies like Google (DoubleClick) wish to use hardware attestation to tie people to hardware for advertisement purposes, and that requires complete vertical attestation.

We're losing general-purpose computing like frogs in a slow cooker, and millions of people don't even notice. Fuck TPM, fuck hardware attestation, no internet company should get a single bit from me that I don't authorize. Any site that requires hardware attestation will be a hard "no" for me to ever visit again.

I maintain this all started when commerce was introduced to the internet. Things were better before money was transferred digitally. Allowing that was a major fuckup.

Re: Web Security is Too Hard

#106
post #103
post #93

Earlier quoted context omitted.

You realize the same argument applies to Word macros.

I think someone should ask Vint Cerf whether he ever intended the web to run executable code, and enforce that answer on the existing web. I bet the world would crumble. Good.

This is base stupidity. Suppose you used your web-dictator powers to strip JS from the web based on historical decisions made 50 years ago. Then everyone other than you would use Web2 and ignore you. Indeed Web 2.0 is already a term recognising that the web has changed since it was first conceived; I guess it would make you feel better if we formalised it and formally created a new Web that's exactly like the current Web except with nobody who can claim things about how it was "supposed" to work in the 1970s?

Re: Web Security is Too Hard

#107
post #103

Earlier quoted context omitted.

I think someone should ask Vint Cerf whether he ever intended the web to run executable code, and enforce that answer on the existing web. I bet the world would crumble. Good.

This is base stupidity. Suppose you used your web-dictator powers to strip JS from the web based on historical decisions made 50 years ago. Then everyone other than you would use Web2 and ignore you. Indeed Web 2.0 is already a term recognising that the web has changed since it was first conceived; I guess it would make you feel better if we formalised it and formally created a new Web that's exactly like the current…

Clearly you have a vested interest in the status quo of today, instead of understanding why the whole network was created in the first place.

Your viewpoint enables billions of dollars of fraud every year, worldwide. Mine doesn't.

Email has similarly been destroyed by HTML email, at least partially.

It's like there is a coordinated effort to destroy every single legacy protocol and replace it with something centrally controlled. No fucking thank you.

Re: Web Security is Too Hard

#108
post #102

Cosmically I feel like the HTTPS certificate on Cloudflare.pay should provide sufficient info to confirm it's the same entity behind Cloudflare.com

You'd think, but nope, it def doesn't — the site's TLS cert is issued by Google Trust Services, which issues domain-validated certs via ACME, so no, the only thing the site owner had to do to get that certificate is demonstrate ownership of the `cloudflare.pay` domain. GTS is also one of the default CAs that Cloudflare's universal SSL uses, so that's also exactly what would show up for any Cloudflare-proxied site with TLS enabled.

The cert itself only has CN=cloudflare.pay. It lacks an org, an address, or any other identifying info. It's not OV/EV, so no details there, either.

The domain's whois is also devoid of identifying details:

https://rdap.nominet.uk/pay/domain/cloudflare.pay

Registered through 101domain, with nothing except a registrar abuse contact.

I mean, great that this is legit, but CF could have done a better job with making it actually _look_ legit. This looks sketchy as fuck.

edit - gawd, nevermind. they don't even have anything useful for cloudflare.com. Same GTS cert, redacted whois info. lol. how did we even get here.

Re: Web Security is Too Hard

#110
post #107

Earlier quoted context omitted.

This is base stupidity. Suppose you used your web-dictator powers to strip JS from the web based on historical decisions made 50 years ago. Then everyone other than you would use Web2 and ignore you. Indeed Web 2.0 is already a term recognising that the web has changed since it was first conceived; I guess it would make you feel better if we formalised it and formally created a new Web that's exactly like the current…

Clearly you have a vested interest in the status quo of today, instead of understanding why the whole network was created in the first place. Your viewpoint enables billions of dollars of fraud every year, worldwide. Mine doesn't. Email has similarly been destroyed by HTML email, at least partially. It's like there is a coordinated effort to destroy every single legacy protocol and replace it with something centrally…

"The whole network was created in the first place" to serve the needs of a tiny number of academic and military researchers. This legacy is completely irrelevant to why it exists today. Again, we can kill Web1 if it makes you happy, so we can get rid of your tired appeal to "but the 1970s design!!!". If we kill it, then people will just create some new network that serves the actual use cases of billions of people, because there will still be demand for software that does more useful things than sharing documents. And when that new network is created, it will be exactly the same as the current one, but it will have been made in the 2020s, so you can finally STFU about the 1970s. Would engaging in that farce make you happier?

> Your viewpoint enables billions of dollars of fraud every year, worldwide.

Yep. Having knives in every kitchen enables people to be stabbed, too. As a society we choose to allow useful things to exist rather than locking everyone in a straitjacket, even though the latter would be more safe and prevent all kinds of crime and tragedy. It's funny that you complain about centralizing control at the same time as making this argument that nobody should have tools because tools can be misused.

Post reply on HN