Yeah, how silly to disable anonymous remote code execution by default. ;) Flashy pages that eschew compatibility and separation of concerns (even accessibility, seo at times) are the new standard, get used to it.
Would you accept a Word.doc that required scripting to display itself? Shouldn't the response to a non-visible blog post be WTF?
(Strangely enough, I am able to read the page w/o js, but responding in general to this type of comment I see on HN frequently.)
I wouldn't accept the word scripting because I don't trust their security model; I expect there to be a very high chance of getting a virus from MS Office scripting. I see a very low chance of getting a virus from js; there have also been 0-day exploits from <img> tags, why do you feel OK with images enabled?
There have been hundreds (thousands?) of javascript exploits. Javascript is also a major component in user tracking. Go to a news site and you'll see a dozen trackers most likely against your wishes, reducing privacy and performance. It's a hostile internet out there.
Hostile images may exist but they are an order of mag. or two less common of a threat. Of course, where to draw the line is subjective, but the idea that blocking js by default is silly is misguided, imho.
Can you link to a recent (for any reasonable value of the word) remote code execution vulnerability with JavaScript? Because my observation has been that RCE through codecs has been a much bigger vector for compromised systems.
Why does it have to be specifically RCE? Here are some lists of Firefox's and Chrome (fixed) security vulnerabilities. Browse the lists and you'll find plenty of critical issues related to Javascript.
http://www.metasploit.com/modules/exploit/windows/browser/ie... was a cool one, but really, almost EVERY vulnerability requires JavaScript for the heap spray, even if the bug is somewhere else. Of course, running plug-ins in web pages is even more retarded than running JavaScript. By the way, images can spray the heap too, but, for some reason, they are not commonly used.
Is there a possible way to use the internet without?
At least it is my experience, that without NoScript any given site will either take half an hour to load, or have some annoying ads, as an overlay over the content. ( Not to mention videos which start to play automatically, flash banners and sound effects.) Seriously I have no problem with an advertisement which just displays a picture or text. But any possible use of JS in a ad is a use I do not want.
Really? I browse with NoScript and JS turned off, and it worked just fine for me. (Which is more than can be said for most blogspot posts, e.g., by Google, which I always find frustrating.)
Please let me read relevant discussion without having to scroll through a two page meta-debate. If you have an issue with the blog's presentation, kindly send it to the author directly.