sent from a disposable whonix qube

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      1
      ·
      23 hours ago

      Those are websites I don’t want to use. As I’ve said in other comments, sites which break without javascript are what I consider broken sites. And I don’t like to use broken sites.

      Almost all websites stop working

      Another way of saying this: Most websites are broken and not worth accessing.

      Like, have you seen the web? Most sites suck. lol. The good ones don’t bully/coerce me to change my behaviour.

      • REDACTED@infosec.pub
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        2 hours ago

        I don’t know man. This seems extreme. JavaScript is part of web standard, nearly all sites use it, including every single of my own site/project. I don’t even consider people who have it disabled as I treat them same as bots.

        Imagine saying “Windows is less secure than Linux, so I’m not going to make any of my apps work on windows”. You’d get so many weird stares. It’s like instead of dealing with it, learning how to be safer, etc, you’re shutting out.

        EDIT grammar

  • keiko@fedia.ioOP
    link
    fedilink
    arrow-up
    1
    ·
    20 hours ago

    Okay, I’m going to reply to this message with my responses to various quoted comments from the big chain of comments which I can’t directly access from this instance, due to defederation with certain instances. I’m not going to respond to literally every message, but I hope you all know that I do appreciate you for participating in this thread and being part of a really fun and interesting chain.

    Thanks for all the comments and sorry for not responding until now. Since I can’t upvote any of the comments in that chain, to all of you I provide lots of hearts: 🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷🩷

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      1
      ·
      20 hours ago

      @OwOarchist@pawb.social Honestly, it’s bonkers that the standard, default approach for all mainstream browsers is to let every random website in the world run any arbitrary code it wants on your computer.

      This, this, 1000 times this! That is exactly how I feel and was hoping to convey.

      @OwOarchist@pawb.social Yeah, they usually attempt to sandbox it, but still. Sometimes sandboxes can be escaped. And sometimes the code can do significant harm while still inside its sandbox.

      Yes, defense-in-depth includes minimizing threats rather than simply relying on protections. It shouldn’t be necessary to lower one’s shields constantly, and it’s better to avoid doing so if possible, from a security & privacy perspective.

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        2
        ·
        20 hours ago

        @cley_faye@lemmy.world Bugs exists. But JavaScript running in the browser have, theoretically, little access to anything. […]

        The risk of allowing JavaScript on a website is more tied to the site data, or tracking. […]

        It doesn’t mean every site needs JavaScript, but having this enabled by default is not that big of a security risk for the system. […]

        This reminds me of an interesting phenomenon: Some security-oriented people praise the security of the surveillance-advertising corporation’s browser engine (chromium), while proclaiming that gecko-based browsers (firefox) are unusable due to inferior security. Yet the main security threat I see is that fucking surveillance-advertising corporation which spreads unvetted and often malicious ads around the web without a care in the world.

        • keiko@fedia.ioOP
          link
          fedilink
          arrow-up
          3
          ·
          20 hours ago

          Person A: “chromium-based browsers have superior security” Person B: “i use firefox-based browsers exclusively” Person A: “outrageous. it’s got inferior security” Person B: “i don’t allow scripts” Person A: “javascripts aren’t a major security concern” Person B: “firefox with scripts denied is more secure than chromium with scripts allowed” Person A: “javascripts are required for the modern web” Person B: “untrue, as evidenced by the fact that i access the modern web with scripts denied”

          checkmate ♟️

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        2
        ·
        20 hours ago

        @rtxn@lemmy.world Sure, it’s bonkers for you, but an alternative browser that can’t immediately show a website that works perfectly well in Chrome wouldn’t get much of a user base.

        I think the main point is about what is default. People have been and continue to be trained by the defaults (tyranny of the default), and in this case they are trained to expect sites to utilize scripts, which is (imo) unhealthy for society. It would be better if scripts were denied by default and the user could allow them per-site with a single click, similar to how sites will ask the user to allow notifications or location services which the user is able to allow or deny.

        Sure, most users simply allow everything. But kids are curious and would be more likely to read and understand such things if presented with the options, and that could translate into a more-informed adult population with better security practices. And overall, I think that’d make for a healthier and happier society which doesn’t continue to crumble into worse and worse outcomes.

        If the default were to deny scripts, sites would have to at least look somewhat presentable without the scripts, so as to ask the user to enable them. And my hope is that people would prefer the sites that don’t pester them for permissions.

        • keiko@fedia.ioOP
          link
          fedilink
          arrow-up
          3
          ·
          20 hours ago

          @hirihit640@sh.itjust.works Just another piece of evidence that people care more about convenience than privacy, sadly. People aren’t willing to put up with a single broken website

          Au contraire. Most people put up with broken sites all the time. The problem is that those people generally aren’t aware that the sites are broken, because they’re also unaware of the concept of allowing/denying javascripts. If they denied javascripts by default, they’d notice that most of the sites they access are actually broken sites. The ones that function without javascripts are the unbroken ones.

            • wonderingwanderer@sopuli.xyz
              link
              fedilink
              arrow-up
              2
              ·
              15 hours ago

              Oh, you made that one? I actually saved it because it’s legitimately helpful. A lot of tier lists really just reflect a person’s preference, but I liked how you grouped yours by category. I’ll be referencing it as I explore more distros

              • keiko@fedia.ioOP
                link
                fedilink
                arrow-up
                2
                ·
                13 hours ago

                I feel kinda weird replying since my comment to which you replied was removed by a mod, and I have no idea why, as there is no reason given in the mod log. I had been trying to respond to the messages which I was and am unable to directly access, due to my instance’s defederation policies, but it seems that I’ve inadvertently upset someone and feel that I should probably stop interacting here, so as not to cause problems.

                Thank you for your appreciation 🩷

                • wonderingwanderer@sopuli.xyz
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  13 hours ago

                  Ah, that’s strange. Sorry that happened to you. Maybe the mod missed you’re top-level comment where you explained so they thought you were spamming.

                  Have a nice day

        • keiko@fedia.ioOP
          link
          fedilink
          arrow-up
          2
          ·
          20 hours ago

          @chonglibloodsport@lemmy.world Most websites from when I was a kid did not need JavaScript. Heck, they didn’t even have any JavaScript on many of them! No CSS either, just HTML and images (which were very slow to load on dialup).

          Simpler times

    • relativestranger@feddit.nl
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      i really wish raymond would restart umatrix… it was the most flexible script blocker. noscript’s ‘per site’ permissions takes far too many clicks to do (some of) what umatrix does from one toolbar icon drop-down.

        • keiko@fedia.ioOP
          link
          fedilink
          arrow-up
          1
          ·
          20 hours ago

          It was really nice but was eventually discontinued. ublock origin can do most of what umatrix could do, and NoScript is similarly useful. But it’s also simple to just deny javascripts and call it a day. Whatever works.

  • obnomus@lemmy.ml
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 days ago

    Its not related to this but Tempermonkey amd scripts is insanely good experience.

  • Bluescluestoothpaste@sh.itjust.works
    link
    fedilink
    arrow-up
    5
    arrow-down
    1
    ·
    2 days ago

    Im not super tech saavy, especially compared to the lemmy userbase, but every complaint about software just reads to me like whining about something you chose to install on your computer. You can just not use someone else’s software, yes the mainstream software companies are fucking assholes and they will take all of your data and privacy in exchange for a subscription to their software. It’s on you if you accept that deal.

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      2
      ·
      1 day ago

      I’m confused (happens a lot). Is your comment responding to the meme or to some other comment? If the former, I am even more confused, since the meme isn’t complaining about anything at all. It’s poking fun some of the ways people view the web.

      You can just not use someone else’s software

      That is what I am doing when I deny a site to run scripts on my computer, yes. And I love that I have the ability to make that choice.

      yes the mainstream software companies are fucking assholes and they will take all of your data and privacy in exchange for a subscription to their software

      lol yes. That’s why I tend to avoid them and their products/services.

      It’s on you if you accept that deal.

      Well I do still find it fucked-up that they prey on unsuspecting people who are ignorant of what’s being done to them, including especially kids. It’s not on them. They don’t deserve the bad things done to them by the surveillance corporations. They can’t be expected to know and understand.

    • TorstenTyp@feddit.nu
      link
      fedilink
      arrow-up
      3
      ·
      1 day ago

      While technically correct, it’s a slightly shallow analysis. It’s like people complaining that companies put chemicals in the food, you could grow all of your your own food but it’s probably not feasible.

  • keiko@fedia.ioOP
    link
    fedilink
    arrow-up
    12
    ·
    2 days ago

    Hey, so there are a few threads I can’t see from this instance due to defederations and I wanna respond anyway.

    @Digit@lemmy.today open dyslexia font? nice touch.

    Thanks. Yeah, it’s OpenDyslexicAlta Bold. It felt like a good option for a meme font that was kinda different and maybe easy enough to read to make it useful too.

    @Onomatopoeia@lemmy.cafe That makes it easier for dyslexics?

    Possibly for some, as @Ludicrous0251@piefed.zip said. I think it would probably be more beneficial for those who are introduced to it at a young age. Otherwise it takes some time to get used to it, and I did end up falling back to the fonts I had been using. But I do like OpenDyslexicAlta font and think it makes a good meme font, so yeah.

    Okay so that’s my response to the chain of comments quoted above. Sorry I can’t give y’all upvotes due to the defederation, and sorry it took me so long to realize there were comments which were hidden from me. I do try my best to respond to everything that seems directed at me or which I can offer a worthwhile response.

    The next chain of comments is much longer (it’s a really good one too), and I’m thinking I’ll make one or more responses when I get back online a while from now.

    🩷

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      2
      ·
      22 hours ago

      Thanks. Yeah, it’s OpenDyslexicAlta Bold. It felt like a good option for a meme font that was kinda different and maybe easy enough to read to make it useful too.

      @Digit@lemmy.today This, I applaud. I aim similarly.

      tyvm for the appreciation. and since I can’t send upvotes directly, you get extra hearts: 🩷🩷🩷🩷🩷

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        1
        ·
        1 day ago

        I have a brand??! 🫨 (seriously tyvm 🩷) I’m currently going through my notifications and responding to stuff before using another qube to find that other chain of comments (and any new ones too). I am pretty obsessive ^^’ (and maybe trying to show more of myself here in the hopes that people can truly see me when I say things that matter)

    • Digit@lemmy.today
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      Thanks. Yeah, it’s OpenDyslexicAlta Bold. It felt like a good option for a meme font that was kinda different and maybe easy enough to read to make it useful too.

      This, I applaud. I aim similarly.

  • OwOarchist@pawb.social
    link
    fedilink
    English
    arrow-up
    89
    arrow-down
    3
    ·
    3 days ago

    Honestly, it’s bonkers that the standard, default approach for all mainstream browsers is to let every random website in the world run any arbitrary code it wants on your computer.

    Yeah, they usually attempt to sandbox it, but still. Sometimes sandboxes can be escaped. And sometimes the code can do significant harm while still inside its sandbox.

    • Err(()).unwrap()@lemmy.worldM
      link
      fedilink
      arrow-up
      42
      arrow-down
      4
      ·
      3 days ago

      Most websites would break, or not even display, without javascript. Sure, it’s bonkers for you, but an alternative browser that can’t immediately show a website that works perfectly well in Chrome wouldn’t get much of a user base.

        • OrganicMustard@lemmy.world
          link
          fedilink
          arrow-up
          4
          ·
          edit-2
          3 days ago

          There are protocols like gemini that only have text and files, no executing code. I wish there was more of the web moving towards that.

          *Edited for wrong language autocorrect.

          • libewa@feddit.org
            link
            fedilink
            arrow-up
            2
            ·
            2 hours ago

            There are valid use cases for JS and AJAX, but they are few. HTML/CSS is great, and has gotten many new features that can replace JavaScript in the long run: Popovers, commandfor etc. One thing I am missing is opening arbitrary popovers on a long hover. For that, you still need mousemove event listeners.

      • chonglibloodsport@lemmy.world
        link
        fedilink
        arrow-up
        15
        arrow-down
        2
        ·
        3 days ago

        Most websites from when I was a kid did not need JavaScript. Heck, they didn’t even have any JavaScript on many of them! No CSS either, just HTML and images (which were very slow to load on dialup).

      • OwOarchist@pawb.social
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        3
        ·
        3 days ago

        Most websites would break, or not even display, without javascript.

        I use NoScript – I’m well aware.

        But a lot of those websites could function without javascript. A lot of websites use it unnecessarily, for reasons such as:

        • They want their ads and trackers and other malicious code (such as soft paywalls) to work as intended.

        • They want to add fancy cosmetic elements to the content and are too lazy to think about failing gracefully and still displaying the content if javascript isn’t working.

        • They built the website in a framework that depends on javascript, and are again too lazy to bother worrying about graceful failure if javascript isn’t working, even if their content could, in theory, be displayed just fine without it. (Or maybe the framework developers deserve a bit of the blame for that laziness, since they could have made graceful failure a feature of the framework, but chose not to.)

        In a hypothetical world where most browsers didn’t allow every website to run arbitrary code, then every website would be forced to take that into account and only depend on javascript when it’s absolutely necessary for the website’s core functions.

      • hirihit640@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 days ago

        Just another piece of evidence that people care more about convenience than privacy, sadly. People aren’t willing to put up with a single broken website

      • wonderingwanderer@sopuli.xyz
        link
        fedilink
        arrow-up
        5
        arrow-down
        2
        ·
        3 days ago

        That’s the problem though, why is it standard for websites to be built in such a way that their basic functionality depends on allowing such arbitrary scripts? Shouldn’t there be some regulatory body that tells them that’s against the rules or something?

        • Err(()).unwrap()@lemmy.worldM
          link
          fedilink
          arrow-up
          4
          arrow-down
          2
          ·
          edit-2
          3 days ago

          Do you want regulatory overreach? Imagine forcing every small project or self-hoster to adhere to the rules set by the equivalent of the HDMI Forum, but controlled by the likes of Microsoft and Facebook.

          To redirect your other question: you should ask the web developers. If they’re honest, you’ll get a dozen legitimate answers that can’t be solved without locally running code. A chat web app, for example, needs to either poll the server at a given rate, or use a WebSocket to fetch incoming messages, both of which require Javascript. Then it needs to modify the DOM to display the new messages, which again requires Javascript. If it needs access to the microphone or webcam, it has to use some kind of local interface. I could go on. The point is, a lot of this arbitrary local code exists because there’s no other way to implement many features without it. Imagine having to reload an instant messaging app if you want to see if you’ve received anything. It would be like writing a GUI application using Qt or GTK, but without using any events.

          • wonderingwanderer@sopuli.xyz
            link
            fedilink
            arrow-up
            4
            arrow-down
            3
            ·
            3 days ago

            I don’t view basic consumer rights as “regulatory overreach.”

            to adhere to the rules set by the equivalent of the HDMI Forum, but controlled by the likes of Microsoft and Facebook.

            No and no. I never said it should be corporations setting the standard. That’s the FCC’s job, and comparable agencies in other countries. The FCC already regulates many things about the internet. Some things they don’t regulate enough. Were you one of those people who viewed Net Neutrality as “regulatory overreach” too?

            Sure, the current admin is corrupt and the current FCC can’t be trusted, but that won’t be forever.

            Also, there’s such thing as the IEEE. Standards for web development are not unheard of, and they’re not categorically wrong. There need to be rules governing the rules that govern web development to ensure those rules aren’t abused. But setting no rules or standards would be insane.

            If they’re honest, you’ll get a dozen legitimate answers that can’t be solved without locally running code.

            That’s not honesty. That’s deflection and dissembling. Sure, you can think of a dozen different reasons why scripts need to be run locally. But that doesn’t excuse using those scripts as a trojan horse for malicious data mining practices. Permissions can be atomized.

            If a web developer can’t compartmentalize the part of the script that loads an image on their website from the part of the script that harvests sensitive fingerprinting data that the website has no legitimate need for, then they’re either a really bad developer who’s never heard of modularity, or they’re doing it deliberately and maliciously because they know they can get away with it and are choosing to make their website break for anyone who doesn’t let them basically peep under their device’s skirt.

            • Kangae_Hishiryo@scribe.disroot.org
              link
              fedilink
              arrow-up
              2
              ·
              3 days ago

              I get your point, yeah. I actually do think that scripts should’ve hugely modularized, compartmentalized, and browsers should’ve using OCaps instead of ACLs, or at least make more granular ACLs so you can finetune what can or what cannot do a given site and/or a given script.

              • wonderingwanderer@sopuli.xyz
                link
                fedilink
                arrow-up
                2
                ·
                3 days ago

                Thank you! It seems pretty clear to me, modularity is supposed to be the modern standard for quality code, so why are we normalizing websites that use scripts with more arms than Cthulhu harvesting uniquely identifiable data from our personal devices by running arbitrary code locally? It seems insane to me…

                “One tool for one job.” It’s pretty basic Unix philosophy. So why do we now have “One script for several hundred different fingerprint variables, oh and also the website’s basic functionality”?

    • cley_faye@lemmy.world
      link
      fedilink
      arrow-up
      5
      ·
      3 days ago

      Bugs exists. But JavaScript running in the browser have, theoretically, little access to anything. Definitely no FS access without user interactions, can’t access most of the system services, and the few that are accessible are through restricted API with permissions/confirmations.

      The risk of allowing JavaScript on a website is more tied to the site data, or tracking. Rogue browser extensions are way more dangerous.

      It doesn’t mean every site needs JavaScript, but having this enabled by default is not that big of a security risk for the system. It can help with phishing, though, if you don’t know what site you’re viewing.

      • OwOarchist@pawb.social
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        3 days ago

        Still can have issues with javascript crypto miners. And there’s always the possibility of malicious javascript finding a way to escape its sandbox and escalate permissions.

        • cley_faye@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          1 day ago

          JavaScript in the browser have no “sandbox” to evade. It does not have the ability to run outside of it’s virtual machine, at all. It’s completely different from a native executable, that actually have the ability to make system calls, that would evade a container/chroot/whatever.

          Also, running a crypto miner in a browser tab (or even as a service worker) is probably more costly to put in place than it will ever bring back. It’s just not efficient enough.

        • Tanoh@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          3 days ago

          Most (all?) browsers throttle tabs that take too much cpu for too long (especially background). The actual numbers vary, but hidden cryptominers are not that effective anymore.

  • TrickDacy@lemmy.world
    link
    fedilink
    arrow-up
    52
    ·
    3 days ago

    Those last two panels are so far past the inconvenience I’d ever be willing to put up with. I’m not sure how it could ever be worth it.

    • Secret_Music@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      6
      ·
      2 days ago

      I tried it for a while. I got caught up in the ‘privacy’ crowd on Reddit and went all out for a bit. Even de-googled my Android phone at the time. It is inconvenient as fuck. And you’re going to be spending more time tinkering and looking for workarounds and alternate software than actually ever getting anything done. All just to stop an advertising company from detecting what you clicked on, or for the website owner to never get any telemetry.

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        2
        ·
        1 day ago

        I got caught up in the ‘privacy’ crowd on Reddit and went all out for a bit.

        Same.

        Even de-googled my Android phone at the time.

        I went from iOS and OSX to linux mobile and Qubes OS.

        It is inconvenient as fuck.

        It certainly can be, living my digital life on my own terms like this. And yet I persist.

        And you’re going to be spending more time tinkering and looking for workarounds and alternate software than actually ever getting anything done.

        I wouldn’t have it any other way. I don’t feel that I’m held back by FOSS. I feel strengthened by the wide array of free software available to me. I have no use for anything from google other than their free noto fonts.

        All just to stop an advertising company from detecting what you clicked on, or for the website owner to never get any telemetry.

        It’s far beyond that. From the moment I began my journey into understanding and attaining privacy, security, and freedom, I was challenged. It was as if the world itself denied me the right to walk that path. And so I persisted.

        I will continue to make decisions for myself based on what I want and what I’m willing to sacrifice. Sites which require javascripts aren’t even a sacrifice. I do not like them. I do not value them. I lose nothing by avoiding them. I have rare exceptions, and those are handled in disposable qubes.

        The world has hardened me into defiance in many ways, and I won’t be bullied into compliance by corporations.

        • Secret_Music@piefed.blahaj.zone
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 days ago

          Nah it’s really not convenient when it comes to things like banking apps that get fussy about how customised your phone is. It’s fine most of the time but you’re going to be running into issues at inconvenient times when you don’t really have the time to sit and play. Although I’m also talking a couple of years ago now, chances are things have improved.

          disabling javascript

          Yeah you’re basically breaking everything. I did this before it was chic when I had a Nokia phone running Opera Mini lmao.

          • keiko@fedia.ioOP
            link
            fedilink
            arrow-up
            3
            ·
            1 day ago

            Nah it’s really not convenient when it comes to things like banking apps that get fussy about how customised your phone is.

            I don’t trust banking apps, and I have absolutely no desire to install software that is so controlling.

            Yeah you’re basically breaking everything.

            Sites which are non-functional without javascript are already “broken” in my view. So I simply don’t use them.

            I did this before it was chic

            Is it though? Most people tend to try to talk me out of it. There seem to be lots of people who view it as unacceptable, and I’ve actually been bullied about it on a few occasions by people whom I’d thought were friends. I’ve learned to be defensive as a result, but that can come across the wrong way sometimes. I’d certainly rather it be chic than what it currently is, though I’m glad the comments in this thread have remained civil and generally positive.

            (I spent a long time typing that last paragraph and debating about whether or not to include it in this comment. Hopefully it’s fine.)

            • Secret_Music@piefed.blahaj.zone
              link
              fedilink
              English
              arrow-up
              2
              ·
              1 day ago

              I don’t trust banking apps

              Yeah, even banks are something that’s forced onto us, that you actually just can’t live without in the current system. I also tried fighting it for a bit but the bank I’m with is trying to eliminate ATMs and making it really difficult to do online banking the old school way. And afaik, other banks are trying to do the same now. Just a matter of time before a vanilla smartphone is as much of a requirement as a bank account itself.

              I spent a long time typing that last paragraph and debating about whether or not to include it in this comment

              Yeah I was honestly just making a joke about the chic thing. It’s definitely not even close to mainstream. I really love your passion for this though lol. And I agree with the cause. Glad you stuck it out.

              • keiko@fedia.ioOP
                link
                fedilink
                arrow-up
                2
                ·
                23 hours ago

                Just a matter of time before a vanilla smartphone is as much of a requirement as a bank account itself.

                That’s a really sad thing for a people to allow to be done to them. Like, idk about other people, but I’m never buying another apple or google product for the rest of my life. I think it’d be really weird if that became a death sentence, in which people like me could no longer access their own money to pay for necessities like food.

                Yeah I was honestly just making a joke about the chic thing.

                Oh I know. I liked that it gave me an excuse to say that stuff in response though, and I was uncertain if I should make such a serious response to a joke. But I went for it cuz why not, lol.

                I really love your passion for this though lol. And I agree with the cause. Glad you stuck it out.

                tyvm for the appreciation 🩷

          • PotatoesFall@discuss.tchncs.de
            link
            fedilink
            arrow-up
            3
            ·
            2 days ago

            My impression was that the OP was about disabling javascript. I’ve also had issues with banking apps on CalyxOS and iodéOS, but overall could be worse

        • zane@infosec.pub
          link
          fedilink
          arrow-up
          2
          arrow-down
          1
          ·
          2 days ago

          Yeah I’ve been running graphene for years. I can understand how the technically illiterate might have problems on rare occasion. Multiple stores can get confusing. Launchers are a thing. Nevertheless its nothing over the frustration I had previously carrying something I couldn’t trust in my pocket.

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      15
      ·
      3 days ago

      Bottom left is a super-convenient built-in feature of Qubes OS, via qubes-whonix. I just click a button and a new disposable whonix qube is generated from the template, and it only takes seconds to boot. When I’m done with it, I close the window, and the disposable qube is automatically deleted.

      Bottom right is my default, since I don’t like broken sites.

      • TrickDacy@lemmy.world
        link
        fedilink
        arrow-up
        12
        ·
        3 days ago

        Okay I just did some cursory research and it doesn’t sound simple. Is it just installing qubes-whonix and creating a template (I’m guessing a yaml config or similar)?

        As far as sites with JavaScript being “broken”, that one puzzles me. I have tried turning off JavaScript in the past and probably 70% of websites became fully non functional. That shouldn’t be the case, but it often is, and my impression has been that this has gotten worse, not better. I’m a web developer and no one talks about progressive enhancement anymore and frankly my coworkers have mostly thought it’s silly to even try to support users who turn off JavaScript.

        • keiko@fedia.ioOP
          link
          fedilink
          arrow-up
          10
          ·
          3 days ago

          Okay I just did some cursory research and it doesn’t sound simple. Is it just installing qubes-whonix and creating a template (I’m guessing a yaml config or similar)?

          During the installation of Qubes OS, you can select a checkbox to have Whonix templates and qubes automatically installed. After installation, you can simply click a launcher to start an app like Tor browser in a new disposable whonix qube from the disposable whonix template. It really is that simple. Installing Qubes OS does take a while though.

          As far as sites with JavaScript being “broken”, that one puzzles me. I have tried turning off JavaScript in the past and probably 70% of websites became fully non functional.

          Yes, those sites which become non-functional without javascripts are very much broken.

          That shouldn’t be the case, but it often is, and my impression has been that this has gotten worse, not better.

          Yes, much of the web is broken. On a related note, much of the web is infested with malicious ads and trackers.

          I’m a web developer and no one talks about progressive enhancement anymore and frankly my coworkers have mostly thought it’s silly to even try to support users who turn off JavaScript.

          That’s a shame. And yeah, those are basically just dead sites. If they’re non-functional then there’s really no point for them to exist.

          As the web continues to devolve, with a growing graveyard of dead sites (and an increasing prevalence of malicious scripts), I hope that more people wake up to the reality that this is bad. It’s similar to the dead-end that is google’s android. Eventually they’ll pull it away and leave a lot of people scrambling for their next option. I think the modern web will go through a similar transformation one day. I hope so.

          • TrickDacy@lemmy.world
            link
            fedilink
            arrow-up
            6
            ·
            3 days ago

            I will give qubes-whonix a shot, you have convinced me!

            There are certain functionalities that cannot be done without JavaScript. In my perfect world either no one would abuse JavaScript with ads and other shitty design choices, or at least I’d have an easier time with toggling it off/on. For now I’m leaving JavaScript on because it’s simply far too inconvenient otherwise. Browsers are pretty good about preventing actual harm if you have UBO installed though.

            Out of curiosity, what harm are you concerned about JavaScript doing with an ad blocker and while loading sites within a container? That seems extreme to me.

            • keiko@fedia.ioOP
              link
              fedilink
              arrow-up
              3
              ·
              3 days ago

              I will give qubes-whonix a shot, you have convinced me!

              You definitely shouldn’t rush into Qubes OS. If you’re seriously interested, I’d recommend checking out videos and reading about it so you can understand it a little deeper.

              Out of curiosity, what harm are you concerned about JavaScript doing with an ad blocker and while loading sites within a container? That seems extreme to me.

              Besides that fact that javascripts can be used to track and profile users, they also make the user experience of sites worse. I love static pages. Sites that require javascripts are the polar opposite of that. Useless blur effects and other “features” can cause pages to be significantly slower than static pages, and I absolutely hate it. I should be able to scroll smoothly and click buttons once the page has loaded, and I should be able to keep pages cached indefinitely. With javascripts, scrolling can often be laggy, buttons can appear and disappear in odd ways, and pages can be automatically reloaded without my consent, causing lots of frustrations. I cannot understand how anyone prefers browsing the web with javascripts. They are a fucking cancer, like 99% of the time.

              • TrickDacy@lemmy.world
                link
                fedilink
                arrow-up
                2
                ·
                3 days ago

                I hear you on qubes.

                RE: js, you’re talking about the web as if it should only ever be what it was first conceived of: documents. In reality now it’s used for full on software applications. It’s not just used for animations and polish (and the shitty things you mention specifically), it’s also used for dynamically updating the UI. A world you speak of would mean much worse order forms, paperwork for doctors, etc. I mean you do you, but you can’t just not acknowledge that dynamic updates of a UI are better than filling out a long form then getting back “invalid data, you selected this and entered that, start over”. It’s literally useful.

                The tracking concerns are mostly mitigated by vpns, ad blockers, and private browser features. I understand there are many flaws and issues I’m glossing over, but for the most part, the average person can just use those things, then opt to close the tab of a horrible website like you’re describing.

                tldr; you may prefer static documents, but modern society is built on forms and other types of vital apps, which would inevitably be worse without javascript.

                • Individual Orchid@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  3
                  ·
                  3 days ago

                  I did web Dev when that was how sites worked, and they worked fine. No, it was never live updating, but the errors could be corrected and resubmitted just fine. I don’t use QubeOS but this post has me intrigued.

                • keiko@fedia.ioOP
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  3 days ago

                  In reality now it’s used for full on software applications.

                  I think software applications are better made as actual applications instead of browser-based web-apps.

                  it’s also used for dynamically updating the UI.

                  It might seem useful on the surface but is prone to the same sorts of breakage and annoyances I was talking about.

                  A world you speak of would mean much worse order forms, paperwork for doctors, etc. I mean you do you, but you can’t just not acknowledge that dynamic updates of a UI are better than filling out a long form then getting back “invalid data, you selected this and entered that, start over”.

                  That’s an interesting example, because that’s happened to both of my parents within the past few months from two different healthcare-related sites. The javascript elements frustrated them more than me, since they didn’t understand why certain things weren’t working, and I had to figure it out for them. And there were a few times when we had to start over due to the sites being poorly made.

                  That’s really what I see in this reliance on javascripts, corner-cutting which causes problems. Properly-configured sites work better, and the ones reliant on javascript tend not to be.

                  I would prefer static order forms so that I can have the entire form and fill it out before submitting, while retaining a copy so that if there were issues I could more quickly and efficiently resubmit with the corrections.

                  Some people might prefer the dynamically updating UI stuff, but except for live chats I can’t see a good use for it that static pages can’t do better. And I think live chats are better in non-web apps which support end-to-end encryption anyway.

                  The tracking concerns are mostly mitigated by vpns, ad blockers, and private browser features.

                  The most useful and efficient private browsing feature is the ability to disable javascripts. Using vpns and ad-blockers protects against very specific vectors of surveillance, while javascripts allow a diverse set of surveillance capabilities, so blocking them protects against several forms of surveillance. And with more people disabling javascripts, we all blend together better.

                  you may prefer static documents, but modern society is built on forms and other types of vital apps, which would inevitably be worse without javascript.

                  Modern society is also built on ignorance, conformity, and exploitation, all of which make javascript-based sites more dangerous and prone to issues. It’s the easy answer thrown at every problem, like “a.i.” and is similarly dangerous.

          • Kangae_Hishiryo@scribe.disroot.org
            link
            fedilink
            arrow-up
            3
            ·
            3 days ago

            Wasm seems like a good step towards a better web, and still is something really niche AFAIK.

            I hope that it becomes standard, because is way more secure, and of course more performant than JS.

            I do even think that the HTML+CSS+JS triad (and its single components, too) are a historical bad design decision, a HUGE one, and should’ve superseded.

            • rumschlumpel@feddit.org
              link
              fedilink
              arrow-up
              6
              arrow-down
              1
              ·
              3 days ago

              What makes WASM more secure than JavaScript? I’d think that the main issue with JS is that it’s a programming language that’s running on the client-side, not that it’s specifically JS.

              • Kangae_Hishiryo@scribe.disroot.org
                link
                fedilink
                arrow-up
                3
                ·
                3 days ago

                The fact that WASM is NOT a programmimg language, and that WASM is intrinsically sandboxed and has really granular permissions (through WASI).

                Also, how do you expect that, for example, a videoconference site (let’s say, Jitsi Meet) will work if you don’t execute any client-side code? And I’m not saying that all client-side code is permisible, justified or good, but rather that not all the client-side code is unpermisible, unjustified or bad, as you seem to imply.

                And if you do use FLOSS, that’s really paranoid, even if FLOSS isn’t perfect.

                • rumschlumpel@feddit.org
                  link
                  fedilink
                  arrow-up
                  3
                  ·
                  edit-2
                  2 days ago

                  Also, how do you expect that, for example, a videoconference site (let’s say, Jitsi Meet) will work if you don’t execute any client-side code?

                  I never said that you should never run client-side code. Even OP doesn’t say that (which is why they’re running some sites in Whonix, they just really don’t like it), and they’re way more extreme about not allowing JS than I am.

                  The fact that WASM is NOT a programmimg language, and that WASM is intrinsically sandboxed and has really granular permissions (through WASI).

                  Interesting. Are the actual implementations of it sufficiently secure so far?

  • axh@lemmy.world
    link
    fedilink
    arrow-up
    25
    ·
    3 days ago

    I can’t convince my wife to even use an add blocker, because it makes some (terrible) websites unusable (and you need an entire one additional click to disable it, it’s too much effort), blocking JS would make the entire internet unusable for normies.

    • W98BSoD@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      13
      ·
      3 days ago

      I can’t convince my wife to even use an add blocker…

      Can you convince her to use a subtraction blocker?

      • mirshafie@europe.pub
        link
        fedilink
        arrow-up
        6
        ·
        3 days ago

        A subraction facilitator. It enables the surgical excision of unwanted, harmful and stupefying noise.

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        4
        ·
        3 days ago

        Pi-hole is a great project for network-wide dns-based blocking, yes. I was going to link to the official site, but it seems to be broken now, so I linked to the official github repo.

          • ReluctantMuskrat@lemmy.world
            link
            fedilink
            arrow-up
            5
            ·
            3 days ago

            My wife loves our pihole setup so much I was forced to setup VPN access to the home network so she could block ads while traveling. Now our oldest daughter wants me to setup pihole for her house.

          • keiko@fedia.ioOP
            link
            fedilink
            arrow-up
            4
            ·
            3 days ago

            One thing that’s really nice about pi-hole is that it gives a window into your network, allowing you to easily see dns requests as they happen, while also organizing them into useful charts and graphs.

      • rumschlumpel@feddit.org
        link
        fedilink
        arrow-up
        3
        ·
        3 days ago

        AFAIK some sites are so terrible that they won’t work even if you use DNS-based adblocking instead of browser extension-based adblocking …

        Definitely worth trying, though.

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      27
      ·
      3 days ago

      I have never heard the bottom left take anywhere before, though.

      ✨️ until now ✨️

      • Multiplexer@discuss.tchncs.de
        link
        fedilink
        arrow-up
        6
        ·
        3 days ago

        Had a look into the ublock settings.
        The one I found seems to be more of a nuke-grade total disabling, as opposed to the fine-grained approach of the noscript extension.

        • rumschlumpel@feddit.org
          link
          fedilink
          arrow-up
          6
          ·
          3 days ago

          UBlock’s approach is that you disable it for every site in the settings and then whitelist per site. Seems sensible enough to me. How does noscript do it?

          • keiko@fedia.ioOP
            link
            fedilink
            arrow-up
            3
            ·
            3 days ago

            That is certainly a valid approach to using ublock origin, but the wiki outlines a few other blocking modes available.

          • Multiplexer@discuss.tchncs.de
            link
            fedilink
            arrow-up
            2
            ·
            3 days ago

            I guess I prefer the Unix philosophy of doing things:
            Have a bunch of combinable small programs each being dedicated to a single function and doing that well instead of large complex monoliths.

            • keiko@fedia.ioOP
              link
              fedilink
              arrow-up
              3
              ·
              3 days ago

              When it comes to browser addons, it is generally recommended to have as few as possible in order to reduce attack surface, since a higher number increases the chance of having one that becomes compromised. It’s especially relevant with browser addons because they tend to have lots of capabilities/permissions and can therefore do lots of damage.

  • PinkiePieYay2707@pawb.social
    link
    fedilink
    English
    arrow-up
    9
    ·
    3 days ago

    I’m currently testing just outright blocking all scripts through uBO, and to be honest it is not usable. I will use it for a little longer, then for sure disable it. A lot of websites just refuse to load (thanks, SPAs), and those that do often have little interactions that break, thus making the pages hard to use or even outright unusable.

    To give some examples for those that haven’t tried this: images may refuse to load (js based lazy load implementation), dropdown menus almost never work, search option usually doesn’t work (and if it does it’s only because it goes to a different page, which is fair), comments probably won’t show up, pretty much anything “live” won’t work. Oh and let’s not forget the captchas and all the proof-of-work blockers.

    For me the only really interesting part about this experience is that imgur refuses to load, even if you have a direct link to an image.

    • tempest@lemmy.ca
      link
      fedilink
      arrow-up
      5
      ·
      3 days ago

      The company I worked for used to use SSR which was fine but the web scraping was relentless and the “free” thing we offered was relatively computationally expensive. Eventually we moved to SPA and bought into the CloudFlare protection racket. This didn’t stop it of course but it made the low effort scrapers have to use a browser and hopefully bumped their costs us The advent of the LLM crawlers has made everything worse as well.

      We got a bunch of complaints when we moved to the JS only site saying we were ruining the Internet and while I didn’t disagree the practicalities make it a requirement.

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        4
        ·
        3 days ago

        We got a bunch of complaints when we moved to the JS only site saying we were ruining the Internet

        From my perspective, sites which move to javascript-only cease to be publicly accessible and essentially remove themselves from the internet. I do understand the necessity to do something about the scrapers, but going javascript-only is basically death of the site.

        • tempest@lemmy.ca
          link
          fedilink
          arrow-up
          1
          ·
          3 days ago

          It’s also just practicalities of the industry. You can write interactive elements on a site with minimal JS and some guys blog which could just be an MD file shouldn’t need 10mb bundles of JS. However when you do need to shift more in to the application on the web side of things and you need front-end developers it’s far cheaper and easier to source spa devs, there is just more of them.

    • keiko@fedia.ioOP
      link
      fedilink
      arrow-up
      3
      ·
      3 days ago

      To give some examples for those that haven’t tried this: images may refuse to load (js based lazy load implementation), dropdown menus almost never work, search option usually doesn’t work (and if it does it’s only because it goes to a different page, which is fair), comments probably won’t show up, pretty much anything “live” won’t work.

      All of those things work perfectly on non-broken sites like mbin instances. As far as captchas, I refuse to do them, as I don’t consent to being used like that.

      For me the only really interesting part about this experience is that imgur refuses to load, even if you have a direct link to an image.

      imgur.com/something -> farside.link/rimgo/something

      Not all of the rimgo instances work, but some do.

      Edit: Well apparently farside has been shut down.