Being spied on by the makers of Pegasus, then lured them into a trap
darknetdiaries.com
darknetdiaries.com
[0] https://darknetdiaries.com/episode/86/
Darknet Diaries is entertainment first and foremost. It's also a for-profit podcast where it's advertising becomes a problem.
I say this disappointingly, as I like good technical podcasts, but I have found very few in the security space which work well for me.
The information density is low. There's a whole lot of unnecessary back-and-forth banter between hosts and the the typical kind of old-school AM radio type bullshittery. A 30 minute segment often based on a four paragraph blog post.
The other big problem I have with the show is that the advertisement model has a whole lot of dark patterns. It's been sometimes difficult to tell which segments are "sponsored" (paid adverts) and which is attempted-NEWS/info. In fact, most of the shows are just one advert after another, and the guest speakers are often sleazy and leave out important information. That makes Darknet Diaries a misinformation source for me. I stopped trusting what I was hearing after awhile.
Not affiliated, just thought I'd mention it if anyone's concerned they have malware on their device.
So pegasus operators probably have some sort of licensing data that gets sent. Either way this is no different than them selling guns to terrorists and then being like, "but they said they were going to use the guns to FIGHT terrorism. No way we could have predicted that. Whoopsie-daisy!"
And then we sit and wonder how NSO Group is able to compromise all these machines with ease, and yes, they had/have browser exploits.
And if this % is very tiny, does it make sense for devs to devote time developing an experience for this rare edge case?
Surely you don't need it to just display text?
None of that applies to this page, nor `99.${"9".repeat(n)}%` of articles posted including this one.
It is a podcast with a JavaScript audio-player being the main purpose of the page...
Because before we had local desktop applications that were substantially less secure, with far greater default access rights (even root/admin in many cases).
Webapps that execute in a silo-ed virtual machine with only access to their own data (without express permissions), is a substantial security improvement (and also doesn't require the user to install anything).
To be honest the people who want to visit a website, for free, and then insist on how that website is delivered are super entitled. If you don't want to execute a site's code in a browser's secure context then don't, but you cannot whine about it like they owe you.
No, the site owner is usually gaining money from his users (through ads, tracking, etc). This is an incredibly dishonest statement.
Which you're purposely trying to avoid by disabling JavaScript, thus mooching and demanding that they design the site around your niche desires.
NoJs users are negative revenue users. They cost the same as a revenue user but block revenue streams. Then feel like more resources should be spent on just them.
You're then asking businesses to pay to place ads that you cannot assure them were actually viewed by anyone. It can work, but companies will pay more for ads that can prove they were even rendered let alone uniquely.
Many business models don't work with reduced revenues, thus you can embed ads in content, take the lower revenue, but then need to structure your business around the lower total revenue.
Typically, when businesses have goals like these they end up instead just doing a membership model wherein it is ad-less but the users/audience is paying them directly for content production.
This is a very poor argumnet - stealing data is a crime.
Why should people accept being victims of robbery just because they are in a free library or music concert?
Secondly, many websites have a paid plan - OneDrive, Xero, Flikr, LinkedIn, YouTube, etc. This is a terrible attitude: "I gave you candy for free, so don't complain if it's poisoned"
That (in your analogy) everyone giving candy on Halloween provides a potential threat vector for a serial killer to occasional slip one in is them taking advantage of an ecosystem that everyone desires, not a malicious act from everyone giving out candy.
Sorry, for the author, but I'm not going to enable google-apis and other google spyware scripts to load on my browser just to see what they're up to in this blog post.
As someone who supposedly wrote an article about fighting spyware, they should know better that to require loading google scripts in order to see a simple page.
Those aren't relevant questions for this case, however. The page isn't failing to render without JS, it's failing to render without third party JS. For a group whose nominal message is bragging about their hax0r skills, it's pretty clumsy to build in a single point of fail dependency on code they don't control, then require their users to run it.
Whether it's due to capabilities of a browser or extra security measures a user would like to practice graceful degradation allows content to be shared with more people than not.
https://www.w3.org/wiki/Graceful_degradation_versus_progress...
As an example, for the past ten years I have had to browse with a tablet that crashed every time JS was enabled (luckily I could recently justify the expense of a new one, so that won't be the case any more when it arrives)
I find it ironic. For a site that discusses privacy/cybercrime/surveillance you would expect it works with JS turned off. I imagine many of their visitors visit the site with the Tor Browser Bundle. And I'd say roughly 33% of those have the 'safety slider' set to 'safest' which blocks JS globally.