Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Please let me read your blog page without needed to turn on lots of javascript. The page is blank without whitelisting JS content.


Seriously? Still on the disable-JavaScript kick? scratches head


Yeah, how silly to disable anonymous remote code execution by default. ;) Flashy pages that eschew compatibility and separation of concerns (even accessibility, seo at times) are the new standard, get used to it.

Would you accept a Word.doc that required scripting to display itself? Shouldn't the response to a non-visible blog post be WTF?

(Strangely enough, I am able to read the page w/o js, but responding in general to this type of comment I see on HN frequently.)


I wouldn't accept the word scripting because I don't trust their security model; I expect there to be a very high chance of getting a virus from MS Office scripting. I see a very low chance of getting a virus from js; there have also been 0-day exploits from <img> tags, why do you feel OK with images enabled?


There have been hundreds (thousands?) of javascript exploits. Javascript is also a major component in user tracking. Go to a news site and you'll see a dozen trackers most likely against your wishes, reducing privacy and performance. It's a hostile internet out there.

Hostile images may exist but they are an order of mag. or two less common of a threat. Of course, where to draw the line is subjective, but the idea that blocking js by default is silly is misguided, imho.


Can you link to a recent (for any reasonable value of the word) remote code execution vulnerability with JavaScript? Because my observation has been that RCE through codecs has been a much bigger vector for compromised systems.


Why does it have to be specifically RCE? Here are some lists of Firefox's and Chrome (fixed) security vulnerabilities. Browse the lists and you'll find plenty of critical issues related to Javascript.

http://www.mozilla.org/security/known-vulnerabilities/firefo...

http://googlechromereleases.blogspot.com/2009/08/stable-upda...


http://www.metasploit.com/modules/exploit/windows/browser/ie... was a cool one, but really, almost EVERY vulnerability requires JavaScript for the heap spray, even if the bug is somewhere else. Of course, running plug-ins in web pages is even more retarded than running JavaScript. By the way, images can spray the heap too, but, for some reason, they are not commonly used.



I see an obvious solution to this without disabling JS...


Not disabled, white-listed.

The internet is way better when you don't allow all of the annoying to dangerous JS to run.


Is there a possible way to use the internet without?

At least it is my experience, that without NoScript any given site will either take half an hour to load, or have some annoying ads, as an overlay over the content. ( Not to mention videos which start to play automatically, flash banners and sound effects.) Seriously I have no problem with an advertisement which just displays a picture or text. But any possible use of JS in a ad is a use I do not want.


Most of the internet is unambiguously better with js off.


Well, that sounds like the definitive word on the subject.


[deleted]


Do the Java vulnerabilities piggyback off of JS somehow? Or did you misread parent?


Java?


woops, let's go with mis-read.


Really? I browse with NoScript and JS turned off, and it worked just fine for me. (Which is more than can be said for most blogspot posts, e.g., by Google, which I always find frustrating.)


Maybe you already had blogger whitelisted?


Please let me read relevant discussion without having to scroll through a two page meta-debate. If you have an issue with the blog's presentation, kindly send it to the author directly.


This is as expected. If you want to disable the browser, you should a blank page. Javascript is as much a part of web content as html.

If you're worried about security, run Linux or OSX as your operating system.


Wow! That is not a comment I expected from HN.

You do know that Java7 (also part of the web) has a cross-platform 0day exploit. Your OS will not save you here (layered defense might help though).

Something as inelegant as click-jacking will not be prevented by your silver-bullet OS of choice, either.

> Javascript is as much a part of web content as html.

Why is javascript required to see content for a simple blog page?


Blank screening even with JavaScript enabled.


It's blank for me in 3 different browsers, looks like some javascript errors.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: