Live data from Hacker News

JavaScript is now required to sign in to Google

security.googleblog.com

411–420 of 529 posts

Re: JavaScript is now required to sign in to Google

#411
post #407

Earlier quoted context omitted.

It's already true. You can quibble over who's fault it was, but it really doesn't matter at this point. The web serves code that users run. That's because the web is the best distribution medium for code we've ever seen. I bet you've also installed client side applications that came from the web, on a vendor installed OS that came from the web, and drivers for your machine that came from the web.

You're equating my signed/sealed/delivered package management to javascript?? ?? ?????? Really? You honestly don't see a difference? I have a chain of trust with my OS manufacturer (apple) and a defecto trust with a centralised entity for most of my applications (IE; my company for things that we build, or the home-brew project for most other packages) I should not have that trust with any idiot who manages to get a…

You mean like the signed/sealed/delivered csp policies that browsers have supported for years?

https://developers.google.com/web/fundamentals/security/csp/

To quote the signature section:

'-'

A sha256, sha384 or sha512 hash of scripts or styles. The use of this source consists of two portions separated by a dash: the encryption algorithm used to create the hash and the base64-encoded hash of the script or style. When generating the hash, don't include the or tags and note that capitalization and whitespace matter, including leading or trailing whitespace. See unsafe inline script for an example. In CSP 2.0 this applied only to inline scripts. CSP 3.0 allows it in the case of script-src for external scripts.

Re: JavaScript is now required to sign in to Google

#412
post #405

Earlier quoted context omitted.

You're making an assumption about me, I actually don't use noscript these days (I haven't for at least 6 years at this point) however I will fight for the right of my brethren who do not have machines with six CPU cores and 64G of ram, or those who have had their scrollbars hijacked, or their text to speech software go insane, or their web experience which used to be controlled by them insidiously invaded by people w…

I'm sorry, but who is _forcing_ you to do anything?

Wow, I'm sorry... are you trolling?

This thread is about google forcing everyone to use javascript to use their services.

That's literally the topic of conversation.

EDIT: I'm not allowed to post because of downvotes, to reply to the child:

I am not forced to use google, no, but I don't think I'd get very far on todays internet without javascript.

Google are enabling that: Now people will say "Oh, well google are able to force javascript so why would we support more than google does? we don't have their resources!"

And thus, the next generation of websites have absolutely no hope of ever having a plaintext version.

Re: JavaScript is now required to sign in to Google

#413

Earlier quoted context omitted.

Gmail is more than just mail, it's also integration with other Google services, like calendar. How does Fastmail fare in that regard?

I wouldn't know, I have a self-hosted calendar. From the little I've seen, though, the calendar part of Fastmail is very good too.

Which self-hosted calendar do you use? would you recommend it? I'm in the market for a new one, but the current offerings that I've seen aren't great.

Re: JavaScript is now required to sign in to Google

#414

When I was at Google I started both the login risk analysis project and the Javascript-based bot detection framework they're now enforcing, so it's a pity to see so many angry comments. Maybe a bit of background will make it seem more reasonable. Firstly, this isn't some weird ploy to boost ad revenue. This is the login page - users are typing in a long term stable identifier already! The Javascripts they are requiri…

Sorry, but at this point it is pretty obvious that big tech companies care about account security only as far as it impact their services. The late revelation about Facebook abusing 2FA phone numbers for marketing is a great demonstration of how that works.

Google too does some really funny things to make it nearly impossible to create and maintain an anonymous accounts not tied to a phone number. Even when those accounts are just used for browsing and bookmarking, without sending any outgoing information.

>When an account is taken over it's abused and that abuse creates more victims.

Pushing JavaScript everywhere increases the attack surface for every single user on the web. Except it doesn't happen overnight, and big companies who do it (by affecting standards, or by doing stuff like this ^) aren't affected by client-side exploits and privacy loss.

If someone hijacks my browser through some clever JS API exploit and steals my credentials, what is Google's response? "Just use our 2FA." What about smaller websites that don't have resources to maintain 2FA? "They should authenticate through us." All roads seem to conveniently lead to centralization.

BTW, it is worth noting that the impact of a compromised account isn't nearly as significant if a single account doesn't hold keys to pretty much everything you do online. Somehow this is rarely factored in during such discussions.

Re: JavaScript is now required to sign in to Google

#415
post #393

I think this is a really braindead argument. Of course users are going to use javascript more, the more the internet demands it, the more people will be willing to allow it. When I first started using noscript there were few exceptional sites which didn’t work and I didn’t bother with them after, if that was the majority of sites, I would probably just disable noscript. The idea that I _have_ to let your site run cod…

Sorry, but you're out of touch. Almost everyone wants the features that JS enables. Literally: Almost everyone. I understand you don't, and I absolutely respect that decision, but it means that you're not worth developing for. Full stop. It's not a matter of mal-intent, it's a matter of financial logistics. You bought that machine to run code. If you don't want to run code that sites serve you on the internet, don't…

> That said, I'd be willing to wager a fair bit that literally every line of code you've run on your machine (probably ever if it's been bought in the last few years) outside of the vendor installed OS and drivers came from the internet.

We explicitly decide to install software and we know where we're getting it from. We may not be careful enough, but I certainly trust `brew install` a lot more than I trust a random site I happen to visit.

> You bought that machine to run code. If you don't want to run code that sites serve you on the internet, don't visit them.

I bought my car to drive it, but that doesn't mean that every person I pass on the street gets to drive my car.

You seem to think that visiting a web site establishes a trusting relationship with that site. I think that downloading a site's HTML and running its JavaScript are quite different levels of trust. Especially when the content and the code come from very different entities - eg, the journalist writing the article vs the advertising network the publication uses.

Clearly if I'm using Gmail, I'm trusting Gmail and I don't mind running their JavaScript. But the blanket statement that "if you don't want to run code that sites serve you on the internet, don't visit them" seems out of touch with how pervasively nasty the internet is.

Taking a walk on a city sidewalk does not require eating whatever you find there.

Re: JavaScript is now required to sign in to Google

#416
post #412

Earlier quoted context omitted.

I'm sorry, but who is _forcing_ you to do anything?

Wow, I'm sorry... are you trolling? This thread is about google forcing everyone to use javascript to use their services. That's literally the topic of conversation. EDIT: I'm not allowed to post because of downvotes, to reply to the child: I am not forced to use google, no, but I don't think I'd get very far on todays internet without javascript. Google are enabling that: Now people will say "Oh, well google are abl…

You're talking about a service that this company provides at no charge. No one is forcing anyone to use these services.

If you don't like that, go somewhere else. No one is holding a gun to your head and going "RUN JS OR I SHOOT!".

Why do you assume that you, and the people you claim to be advocating for, are able to compel this entirely separate entity, making a decision it believes is best for the majority of it's customers, to do something that benefits you - a user of a service provided at no charge, and with absolutely no binding contract?

Re: JavaScript is now required to sign in to Google

#417
post #371
post #358

Earlier quoted context omitted.

Javascript ist also required for the vast majority of web-based exploits. I find it somewhat strange that you ask me to make my system less secure so you can better secure my account.

Like the blog post mentioned, 99.9% of users already have JS enabled, and this number is only going to go up as websites rely more and more on JS. For them, this is a purely beneficial change, with no downsides. It's somewhat selfish for you to ask that your system be made more secure, even at the cost of security for 99.9% of other users.

I'm hijacking this thread to say we need a better ID system for the web! That preferably work without JS. Something built into browsers, that also allow you to create as many identities you want. When a id-signup header is detected, the user see a signup button, and can chose what information is sent to the web site/app. The user can login to any site with the push of a button, or even automatically. With a built in public-private key ID solution your friends will have the same ID-public-key on both site A and site B. The contact list can even be inside the browser, and web site's can ask for it, allowing for example white-listing in messenger apps, or let the user pick who are allowed to see their family pictures, etc. And web sites/app no longer have to store, username/password/keys, they only have to make a "challenge" where the browser automatically proves the ID. The private key should be exportable and standardized, and it should be possible to also use smart-cards and second factor logins. Having ID built into the browser means every site/app no longer have to build and manage all this functionality independently.

Re: JavaScript is now required to sign in to Google

#418
post #412

Earlier quoted context omitted.

I'm sorry, but who is _forcing_ you to do anything?

Wow, I'm sorry... are you trolling? This thread is about google forcing everyone to use javascript to use their services. That's literally the topic of conversation. EDIT: I'm not allowed to post because of downvotes, to reply to the child: I am not forced to use google, no, but I don't think I'd get very far on todays internet without javascript. Google are enabling that: Now people will say "Oh, well google are abl…

Does anyone force you to use Google’s services?

Re: JavaScript is now required to sign in to Google

#419

Earlier quoted context omitted.

I wouldn't know, I have a self-hosted calendar. From the little I've seen, though, the calendar part of Fastmail is very good too.

Which self-hosted calendar do you use? would you recommend it? I'm in the market for a new one, but the current offerings that I've seen aren't great.

I use Radicale and find it great, but there's no UI, so you need to use whatever client you want that supports CalDAV (I use Lightning and the calendar on my phone). Lately I've been liking Nextcloud a lot, and that's a one-stop solution for lots of things, so nowadays I would recommend that if you have a home server or want to pay someone to host it.

Re: JavaScript is now required to sign in to Google

#420
post #60

Earlier quoted context omitted.

Yep. Proper password hashing requires per-credential salt, pepper (for all credentials) and a strong algorithm (IV, iterations etc.) Revealing all those information is a leak and arguably making client side hashing less secure (by giving away a lot of parameters for attackers to attack)

NIST may say that you should use "peppers" for passwords, but nobody else does. None of bcrypt, scrypt, or Argon2 use them and are not materially worse for it.

Yes, adding pepper is a recommendation not a mandatory step. But a lot of sites do, I.E. PagerDuty [1], paired with PBKDF2 as many apps requires to meet FIPS certification or enterprise support on many platforms.[2]

[1]: https://sudo.pagerduty.com/for_engineers/

[2]: https://www.owasp.org/index.php/Password_Storage_Cheat_Sheet

Post reply on HN