It is an interesting thought experiment to wonder what chrome would be like if it were more independent, but I think it is wrong to assume that the developers are deliberately malicious or uncaring about users’ interests.
It is an interesting thought experiment to wonder what chrome would be like if it were more independent, but I think it is wrong to assume that the developers are deliberately malicious or uncaring about users’ interests.
there was a simpler example on hn within the last week or two, but for example, json-rules-engine demonstrates how json might be a dynamic program, without ever needing to call eval or Function dynamic code: https://github.com/CacheControl/json-rules-engine
this would need to be extended with some html constructs. which is certainly possible.
or take evaljs and preload in some html functions!
> You might be working in a JavaScript environment where eval() isn't allowed (and you have a genuinely good reason why you want to use it). Maybe this'll slip under the radar.
https://github.com/marten-de-vries/evaljs
surely the people pitching these so called security measures grok just how many dump trucks of nonsense these so called protections they offer us are. about a week ago maybe even it would have sounded ok. but since that time, we've had a big announcement that wizer can now run spidermonkey js engine in webassembly. there's industrial grade js machinery we can run, free from these constraints, nested inside the web platform. with that, this v3 announcement is a week too late to hold even a drop of water. https://news.ycombinator.com/item?id=27370138
I believe they want to do something good too. but they are ineffectual & doing amazing amounts of damage in their grasp to give us this pretend fake security.
[1] https://github.com/Tampermonkey/tampermonkey/issues/644#issu...
While it's possible to build an interpreter in JS, doing so in an extension is an unambiguous violation of the Chrome Web Store Developer Program Policy. The goal isn't to make abuse impossible so much as to limit potential attack vectors in order to make enforcement more tractable.
But thank you for sharing. I'll try to find this policy. I guess I wouldn't be surprised.
you also call our concern misinformation, but your words in that thread seem to come as a surprise to everyone, to the tampermonkey folks, to myself, & there seem to be no public indicators that there is more to this story than the clampdown this headline & post indicate.
I hope the future is indeed not so frakked as you say it might be. I am very very worried, and have seen few positive signs, hitherto your post, which is an unknown small hope against this grimness.
They are not 'uncaring' for users interests, they are just more caring to their company's interests than to those of their users.
Firefox? Brave?