Skip to content

Comment on Copy & paste some text from this article. Notice anything funny?parent

Comments

How quaint.

NoScript is a whitelisting system, not a "I never use JavaScript" system. You load a page and if it doesn't work, then you enable its JavaScript content through a convenient menu. (It even bolds the scripts that are likely to cause problems when not enabled.)

In this case, the site works fine without the clipboard-hacking JavaScript running, so it just stays disabled and the OP doesn't get random data from a website written to his clipboard. If he wants that functionality, though, it's one click away.

What's quaint is trusting websites to run arbitrary code on your machine, as your regular user.

You often can't tell when you're missing out on a feature due to JS being disabled. It isn't always visually obvious. Am I missing something or is there a trust system to this whole VM thing?

Edit: To put it better perhaps, are you worried that they can execute arbitrary code on your CPU as your user on your OS? Or are you just worried that they might paste a link into your clipboard?

Are you running NoScript? May I assume not? If so, then may I point out that you are hypothesizing what using NoScript is like to a user of NoScript while you have no direct experience? This is a structurally-unsound argumentative position for you to be in.

(No, any experience you may have shutting it off entirely does not count. NoScript is smarter than that and does not work that way.)

I do use it. It is two to three times less common for me to be surprised by secret JavaScript functionality on a site than for me to be surprised going into the comment sections of HN or reddit and seeing people complain about some bad thing that I didn't experience. That is a serious estimate. And the thing I missed out on is rarely important. (The most common exception to that is when you need JS to go to the next page. Frequently I decide I don't care enough anyhow.)

Malicious Javascript can do some weird and nasty things, but mostly I run it because it makes the web less annoying. That it tends to prevent exploits from working is just gravy. (Exploits often fail against a 64 bit gentoo-based Firefox anyhow, but still, careful is good.)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.