Live data from Hacker News

Please make your products work with URLs

anderspitman.net

321–330 of 353 posts

Re: Please make your products work with URLs

#321

Earlier quoted context omitted.

FWIW, I have the same setup (3.6 forever!) and it doesn't load. Are you sure you have NoScript set to default-deny?

OK, not that old: 60.3.0esr. And you're right, I wasn't paying attention. I did temporarily allow the site.

Heh. Damn whippersnapper! Get off my lawn! And button up that RCE vulnerablity of yours! Does your mother know what code you've been running? Kids these days...

Re: Please make your products work with URLs

#322
post #17

I hate smart TVs with a burning passion. They accomplish literally the bare minimum to keep people happy and sometimes not even that. Samsung’s Tizen OS is the most genuinely frustrating experience I’ve had with a consumer device outside of printing. Advertisements on my home screen that can’t be disabled, dubious privacy, bugs that require me to reboot my TV, and of course security so bad that they recommend install…

I've long since run with the notion that if you must have Smart TV features, do it with an external box. Last time I checked the Roku devices were decent for this, but there's a bunch of alternatives, and some lovely FOSS stuff (Kodi comes to mind) that is much more privacy focused. The TV itself is a black box of mystery, and does NOT get to go on my network. It doesn't need my wifi password, and I certainly don't w…

I've read of "Smart" TVs that will scan for and connect to open WiFi. That's fun. Even if you don't let the thing on your network it might still be able to ruin your television watching experience.

Re: Please make your products work with URLs

#323
post #317
post #200

Earlier quoted context omitted.

> People who choose to turn off JS are excluding themselves. JS is part of the web platform, and there are tons of amazing things it allows you to do. People who choose to turn off JavaScript are protecting themselves, because JavaScript enables all sorts of attacks on one's security and privacy. JavaScript is not part of the web platform. The Web is a web (hence the name) of interlinked documents: the core requireme…

> JavaScript enables all sorts of attacks on one's security and privacy Could you say more about this?

Not the original commentor, but I'll assume this is a sincere, open question.

To start with, I'm not on the anti-Javascript hype train. I write Javascript for a living, I think it's the arguably the most important modern language of the last decade. It's made computers more accessible, it has good ideas, it's reasonably well sandboxed. I love Javascript. I do advocate for progressive enhancement for a lot of reasons, but in part because that's the foundation of web architecture, and I think it's still relevant today.

The best web developers I know that I really respect all understand what progressive enhancement really means as an architectural pattern, and they don't dismiss it out of hand.

Also to be clear, the browser is (unarguably) hands down the best consumer-facing sandbox that we've ever built. And I like sandboxes, a lot. I think sandboxing is the future of user-facing application security -- not trusted stores, or signing, or managing dependencies in a special way, or SaaS.

Having said that, I'm also using the web as it exists today. And let's just very quickly list a few major security vulnerabilities that have happened within the past few years in browsers, all of which you would have been effectively immune from if you had disabled Javascript by default on even just most sites you visited:

1. Spectre/Meltdown

2. LastPass's browser extension leaking passwords to any page you visited.

3. Firefox's most recent 0-day (that is being actively exploited)[0].

4. Targeted vulnerabilities in mobile Safari (that went unpatched for years)[1].

On top of the numerous browser vulnerabilities that pop up, disabling Javascript by default will protect you from a nontrivial number of phishing attacks and cookie-hijacking attacks. Yes, you can do these attacks without JS/ajax, but in practice a large number of them use JS/ajax. Disabling JS will also make you effectively immune from crypto-mining attacks.

Even non-malicious pages are usually not coded well in terms of CPU-power. One way you can tell a browser disables JS by default is that the non-JS setup will gracefully handle several hundred tabs at the same time in normal everyday usage for extended periods (>1 month). The other browser will eventually get caught by a rogue tab that freezes everything and forces you to restart the browser.

On the privacy front... I dunno, don't you work at Google? You should know this.

Panoptoclick[2] tells me my current browser setup is leaking about 6.6 bytes of identifying information. That's low enough that with a decent VPN setup, I can browse the web (close to) anonymously in many situations. I would challenge you to get a better result than that without disabling Javascript -- especially if you're starting from the disadvantage of using an uncommon OS like Mac or Linux.

----

So there's an interesting philosophical conflict here, which is that the web is awesome, and browsers are awesome, and Javascript is awesome, but anyone who's both technical and privacy-minded should turn Javascript off by default. And this conflict is because where security is concerned, I am trying very, very hard to be a fox, not a hedgehog.[3]

My general advice, notwithstanding my opinion on sandboxes, is that everyone should install Ublock Origin, no matter who they are. If you're technically inclined and understand the web, you should also install UMatrix, which will at least get rid of the most common attack vectors: third-party scripts. If you're technically inclined and understand the web and you worry a lot about privacy, you should use UMatrix to disable JS by default.

That's not an ideological position about sandboxes or about the web. It's not saying native apps are better (native environments are in most cases objectively worse at security). It's purely an observation that roughly 75% of the sites I visit (including many major news sites) work fine without Javascript. It's based on the fact that I keep on seeing security vulnerabilities pop up where not running Javascript is an effective mitigation. It's based on practical concerns about privacy.

So the foxy perspective on web security/privacy is if there's an easy, effective way to improve my security that works most of the time, why wouldn't I do that? And why wouldn't I encourage developers to make it easier for me to do that?

It's not saying that nothing should run Javascript. It is saying that if you want to run Javascript, you should have a reasonably good justification, and if you're displaying pure text you should probably provide fallbacks when possible.

[0]: https://arstechnica.com/information-technology/2020/01/firef...

[1]: https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d...

[2]: Admittedly, Panoptoclick's usage numbers are skewed towards privacy-conscious users. In the real world, the pool of people like me will be smaller. However, people who use VPNs are also skewed towards privacy-conscious, which tilts that back in my favor a bit.

[3]: https://en.wikipedia.org/wiki/The_Hedgehog_and_the_Fox

Re: Please make your products work with URLs

#325
post #278

Earlier quoted context omitted.

Similar in New Zealand, although the exact time isn't defined. The parent comment's case would almost certainly fall under the protection of the Consumer Guarantees Act[1][2] and Sony would have to fix or replace it. Of course, getting a company to actually do something can be harder than just telling them the law. [1] https://www.consumerprotection.govt.nz/general-help/consumer... [2] http://www.legislation.govt.nz/…

In my experience the CGA is generally ignored until the Commerce Commission investigates. The best you could do is take them to the Disputes Tribunal (small claims court) and then the time and energy involved is probably outweighed by the replacement cost unless it's a ultra high end TV.

Would it really be that bad? Sounds like an easy win - even if they did show up (which they won't).

Re: Please make your products work with URLs

#326

Earlier quoted context omitted.

Ah so you can just cast whatever is on VLC? That was the first thing I tried with Roku but my TV doesn't support it, and I was disappointed there wasn't any VLC companion app.

Well, VLC does have casting, but here I more meant you can run VLC on the TV itself, and you can enter a URL directly into VLC on the TV itself. While that's a bit clunky, if you use the remote app on a phone you can enter keyboard data and, most importantly, paste keyboard data from your phone into an input field on the TV itself. So no casting would be required. Kodi would also enable the same use case.

Wait does Roku have a VLC app? I swear I checked for one.

Re: Please make your products work with URLs

#327
post #317

Earlier quoted context omitted.

> JavaScript enables all sorts of attacks on one's security and privacy Could you say more about this?

Not the original commentor, but I'll assume this is a sincere, open question. To start with, I'm not on the anti-Javascript hype train. I write Javascript for a living, I think it's the arguably the most important modern language of the last decade. It's made computers more accessible, it has good ideas, it's reasonably well sandboxed. I love Javascript. I do advocate for progressive enhancement for a lot of reasons,…

Thank you.

Excellent response and more patience than I could muster.

Re: Please make your products work with URLs

#328
post #222

Earlier quoted context omitted.

I've long since run with the notion that if you must have Smart TV features, do it with an external box. Last time I checked the Roku devices were decent for this, but there's a bunch of alternatives, and some lovely FOSS stuff (Kodi comes to mind) that is much more privacy focused. The TV itself is a black box of mystery, and does NOT get to go on my network. It doesn't need my wifi password, and I certainly don't w…

> I've long since run with the notion that if you must have Smart TV features, do it with an external box I'd go farther. I want everything to be external boxes. Right now I'm looking at having to get a new A/V receiver because mine cannot handle 4K video. It does all the audio stuff I need just fine. If video switching and audio processing was handled by separate boxes, I'd just be looking at changing out the video…

You could perhaps keep using your receiver with a HDMI switch and a HDMI audio extractor. Like these two: https://www.aliexpress.com/i/4000102712226.html https://www.aliexpress.com/i/32850215019.html

Re: Please make your products work with URLs

#329

Earlier quoted context omitted.

I feel like Hacker News main purpose isn't a news aggregator anymore, it's turned in to a place to test the usability of your Web site with the kinds of people who run NoScript or browse with a terminal.

Off topic: reading back through your comments here, I was surprised to learn you're Danish. Your written English is completely native and natural: is this typical of Danish people? Can schools be that effective?

Thanks! I've been reading and writing English since I was about 10 years old, and I really like writing, so that might have something to do with it.

I think that are various levels of proficiency, but in general, most Danes have a very good grasp of it, and it's easy to live here if you only speak English.

Re: Please make your products work with URLs

#330
post #6

Earlier quoted context omitted.

Meanwhile, please check https://archive.md/aGFRs

"Can’t find the server at archive.md"

Sigh.

Cloudflare and archive.fo don't play well together. Each blames the other.

I've explicitly coded an exception for the domain on my own networking kit, but that fix hasn't been working for a while, which is ... annoying.

Ordinarily, though, it's a useful fix. If you can point DNS at a provider other than Cloudflare (1.1.1.1), it should work.

Post reply on HN