Avoid the Pitfalls of the JavaScript Trap on Gmail
fsf.org
fsf.org
"Further, we've recently seen companies such as Research In Motion (makers of the Blackberry) advising customers to entirely disable JavaScript in the WebKit browser on its devices because of a security problem that was discovered. While free software JavaScript can have security problems too, this example illustrates that we have a real need to be able to see what the code we're running on our computers is actually doing, and change it."
I think the author doesn't understand how client side javascript works. If on the other hand they're referring to server side Javascript, that has nothing to do with the web browser over say, PHP. You don't necessarily get the source to a PHP-based web app when you use it. Why so much Javascript hate?
You may not be aware of the dangers of JavaScript — a problem we've deemed The JavaScript Trap — proprietary software running on your computer, inside your web browser.
Danger! Your very soul is at risk!
This page is even worse: http://www.gnu.org/philosophy/javascript-trap.html
Silently loading and running nonfree programs is one among several issues raised by "web applications". The term "web application" was designed to disregard the fundamental distinction between software delivered to users and software running on the server.
Beware, dear reader. They may be starting with this fundamental distinction... but your children will be next!
the tagline in the link reads like a scary movie trailer: >You may be running nonfree programs on your computer every day without realizing it--through your web browser.
Not to mention that should it be licensed under a free model, those security concerns don't just magically vanish. I agree with you summation their stance can be radical and preachy at times much like the Vegan community.
What the FSF doesn't get is that its actually much easier to change proprietary JavaScript than it is to modify a binary running on your system.
Yea, exactly.
“The GNU Affero General Public License is a modified version of the ordinary GNU GPL version 3. It has one added requirement: if you run the program on a server and let other users communicate with it there, your server must also allow them to download the source code corresponding to the program that it's running. If what's running there is your modified version of the program, the server's users must get the source code as you modified it.…” — http://www.gnu.org/licenses/why-affero-gpl.html
presumably they dont want the back end of gmail being proprietary either but its not the point of the article?
JavaScript is not different from HTML and CSS, all of these are generated by a sometimes proprietary service and executed in the browser.
This article is completely stupid because it not only misses the point of JavaScript, it even contradicts itself:
- if the UI is plain HTML/CSS and is generated server side and then fed to your browser, you will never even have a clue how it works
- if the UI is done with JavaScript on the client you can always de-obfuscate it
> Further, we've recently seen companies such as Research In Motion (makers of the Blackberry) advising customers to entirely disable JavaScript in the WebKit browser on its devices because of a security problem that was discovered.
It seems the FSF wants to build a reputation by taking things out of context and leaving out important bits. The security was probably found in the browser and not in JavaScript, this is the same as advising someone to unplug the computer because of a computer virus.
I am really disappointed by this short sighted article, the FSF should be better than this.
JavaScript may be the most flexible language which web browsers natively understand, but HTML has long included forms (now with support for validation) and CSS lets authors program complex, interactive rules for presentation.
Even without JavaScript, websites like Gmail are undeniably applications (in this case, a mail reader, manager, and composer), some part of which are downloaded to and rendered by your own computer.
(P.S. I believe I've heard about more security vulnerabilities in browsers' handling of images than in their JavaScript engines. Also, CSS is turning complete: https://github.com/elitheeli/oddities/blob/master/rule110-gr...)
If there was a open source release of the gmail client code, it would force google into maintaining an API for that code for the foreseeable future, which would require additional effort.
The closest to this request that seems remotely likely is a client side API for gmail, so that browser plugins or third party services could extend it. I see a lot of cost to Google to actually release the code, and not a ton of benefit.
http://code.google.com/closure/
You can look at the (compiled version) of the code by looking at the scripts tab of the chrome web inspecter. They're there :)
For GWT normally you have to import the libraries, and then you get a lot of gibberish that looks like its been run through an obfuscator. Then in the body you have a section where you basically say 'insert stuff here', and that is where all your controls get inserted (by the magic javascript). Gmail doesn't have either of those that I can see.
I had a look at the source of gmail, and it looks like a normal page (lots of standard html controls (which you wouldn't expect to see in GWT) plus some weird ass timezone javascript at the end of it. Which does look kind of obfuscated, but probably was just run through a variable-name-shortener.
What I don't see, is any other script or onclick= stuff. And that is kind of suspicious. There's a blank script tag in the header, maybe they have a javascript that runs (to add all that junk dynamically) and then somehow erases itself (a neat trick?) or they have some other way of hiding the javascript?
We released this all some time ago under apache 2.