If it weren't for this triumvirate of evil, as a user I wouldn't have a problem with Javascript at all.
If it weren't for this triumvirate of evil, as a user I wouldn't have a problem with Javascript at all.
I encourage folks to try it even for a little while, because it's shocking how much more quickly many sites will load and how much more responsive they are to things like scrolling or text searches. News articles and arbitrary google-results especially.
Even worse, the difference seems to be getting worse and worse. It's a pretty regular experience for me these days to end up on a website that barely works on iOS: ridiculously slow, stuttering scroll behavior, inability to scroll because there's an ad in the way, inability to close popups, fixed position elements taking at least a third of the screen, and so on. You know the drill.
There's one website that, if I don't use the 'add to instapaper' button within the first few seconds of loading, completely blocks safari.
Now I can understand how a website becomes bloated and shitty while still being somewhat usable; users either might put up with it, or it might be difficult to measure the negative impact of these 'thousand cuts'.
But it baffles me how websites can exist that don't work at all on mobile/iOS when it's relatively easy to fix (enough to make it shitty usable). Does nobody look at bounce rates?
They do so because of the economics of the web. No-one pays for content, but basic advertising is low revenue. So user experience is squeezed instead, with video ads and popups.
There are other factors too, of course. Businesses have strange priorities and can be quite myopic when they compare the value of a new feature with the value of leaving the site uncluttered. But the main reason scripting is slow is advertising.
i) the people who push features don't actually use them;
ii) people overestimate the pain users will go through to reach their services;
iii) in a lot of businesses it's actually really _hard_ to advocate doing nothing - no new features, no further investment, no changes. So something is done because something seems better than nothing, and thuse the product slowly accumulates cruft.
So how do you pay for your content, if not for ads?
Do you expect people to give it to you for free? Do you do work for free?
Bottom line: I just don't want to have to worry about this shit, so try to avoid Javascript like the plague.
[1] - https://news.ycombinator.com/item?id=13831906
[2] - https://news.ycombinator.com/item?id=13649178
2 - this is a hardware vulnerability that you could take advantage of in multiple languages.
3 - this is a Tor + windows exploit that just happens to use JS.
4 - this is a Firefox vulnerability, not a JS vulnerability
There is nothing inherently wrong with JS from a security perspective and in many ways it is a much more secure system than most, since it is constantly exposed to the internet.
But like any large ecosystem with multiple implementations and lots of inexperienced devs, there will be vulnerabilities out there.
I do respect your decision to turn of JS, but I don't agree that JS is somehow special in how insecure it is. You should also avoid running any apps written in any language at all with that logic. I'd posit that JavaScript apps are more secure than c++ apps, since the runtime itself is hardened.
2 - See 1 above.
3 - See 1 above.
4 - It's a vulnerability in a part of Firefox that's written in Javascript.
"I don't agree that JS is somehow special in how insecure it is"
I never claimed that JS was any more insecure than any other language (though fans of "safe" languages and ones whose programs and compilers can be proven correct might in fact make that argument).
Javascript has the special distinction of being the only programming language in the web browser (if you exclude HTML). If it wasn't, then the argument of whether JS was or was more insecure than the other language(s) in the web browser would relevant. But that's not the case.
"I'd posit that JavaScript apps are more secure than c++ apps"
Completely irrelevant since I don't have the choice to run C++ in my web browser.