>The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.
>The Safest security level of Tor Browser is not affected because JavaScript is disabled at this security level.
That’s hilarious given the founder of Brave (Brendan Eich) literally invented JavaScript.
Its a tool with a time and place for proper usage.
Tor is a niche use case, and not running JS is a cost that comes with the increased anonymity. I'm not using Tor to watch my "How to cook rice" videos or funny cat videos.
But I'm not really keeping track, honestly. If I come across a website that isn't working with JS, I make the decision "is this worth allowing JS?". Sometimes the answer is yes, sometimes it is no. Often it means enabling the first-party domain to run JS but no others.
Conveniently, some of the paywalls on various news sites don't work with JS, but you can still read the article. So that'd be some of them that arguably work better without JS.
I don't use Tor for everyday browsing, only for the times I need/want it. In those cases, the equation always equals "no JS" -- that's the reason Im using Tor in the first place.
It's a balancing act, as all security always is.
wc -l yt-dlp/*/*/*porn*
75 yt-dlp/yt_dlp/extractor/alphaporno.py
127 yt-dlp/yt_dlp/extractor/eporner.py
73 yt-dlp/yt_dlp/extractor/hellporno.py
33 yt-dlp/yt_dlp/extractor/lovehomeporn.py
60 yt-dlp/yt_dlp/extractor/porn91.py
101 yt-dlp/yt_dlp/extractor/porncom.py
41 yt-dlp/yt_dlp/extractor/pornez.py
78 yt-dlp/yt_dlp/extractor/pornflip.py
117 yt-dlp/yt_dlp/extractor/pornhd.py
814 yt-dlp/yt_dlp/extractor/pornhub.py
83 yt-dlp/yt_dlp/extractor/pornotube.py
103 yt-dlp/yt_dlp/extractor/pornovoisines.py
54 yt-dlp/yt_dlp/extractor/pornoxo.py
76 yt-dlp/yt_dlp/extractor/sunporno.py
65 yt-dlp/yt_dlp/extractor/watchindianporn.py
182 yt-dlp/yt_dlp/extractor/youporn.py
65 yt-dlp/yt_dlp/extractor/yourporn.py
That appears to be a thing on yt-dlp [1]But what one could do is somewhat reduce the risk by only running JavaScript from the actual domain and it's subdomains by default, with something like µMatrix[1]. Most sites are already useable that way, and it's often obvious (to most people on this site) what domains have to be whitelisted to make it fully functual if they aren't. Or actually whitelist the domain for every website on the first visit. Tedious, but you only need to do it once per site.
Doing so at least protects a bit against malicious iframes or injected scripts from 3rd party domains, doesn't it? :)
Nonsense. I use w3m for browsing and much more than 90 percent of the web works fine. Fully 100 percemt of "the internet" works fine, because that has nothing to do with JavaScript. Please stop over-dramatising and catastrophising as a way to throw cold water on what is a very good security practice. More than one medium security environment I've worked in recently don't allow js (although admittedly the sites we are allowed to access from there are limited).
I just read the top 100 website list and went to some of the top 20, like Yahoo, YouTube, Twitter, Instagram, Amazon, and Live.com (Microsoft).
YouTube, Twitter and Instagram don't work at all. Live.com wouldn't let me log in without JS. Amazon worked until checkout. Yahoo worked until login.
I think you are incorrect with your "nonsense" judgement, as this top-10 sampling is pretty sensible.
EDIT: `ewzimm` makes a good criticism of my analysis: these aren't necessarily the top sites used by Tor. However, how many Tor users (in authoritarian countries or just regular users) don't use it to visit the banned sites on the Top-100 list?
I also prefer w3m and find most of the web much better as text only, switching over to another browser when I want video or some other JS feature. Or I can use something like youtube-dl to fetch a video. And there’s much more out there than the top 100 websites.
No, but the reponse is more like: I only listen to Indie, Billboard isn't music.
The vast majority of internet traffic, e.g., the most popular sites, mostly require JS. If you only visit obscure indie-rock sites, then fine, but we're talking about the masses, not the small niche exceptions.
If you’re using Tor to do your Amazon shopping - I wouldn’t recommend using the same environment to do anything where your anonymity being compromised could put you in danger since you just gave Amazon your credit card and mailing address.
We clearly have very different lifestyles and values. For me that's the dank basement of the internet,
It however does not matter for the large majority of people who use those top 100 or even top 100,000 websites or even top 1,000,000 websites, and do not have the education, skill or time to learn about all the alternatives, if there are even any. It doesn't matter for the people living under repressive regimes who want to inform themselves on foreign news sites, access foreign NGO sites, or even watch things on youtube or look and/or participate in social media. And so on...
A large part of the web is not functional without js, and just because you chose to not use that part of the web (much) doesn't invalidate that point.
So I'd politely suggest you may tone it down a little when it comes to calling "nonsense".
With respect, this is hacker news. When I converse with people here I do so with a different expectation of intellect and curiosity. There are voices here who excuse technological abuses by appeal to the ignorance of "the masses" - completely missing that there is a different spirit going on in the sub-text of innovation and entrepreneurialism here. If, as you claim, the majority are using defective technologies, then that is a bigger problem, not something to be celebrated. They deserve better and it's our job to help them get that.
The fact that there are a handful of very frequently used websites that use JS doesn't make it impossible or overly burdensome to take sensible steps to limit which scripts you allow.
I use amazon in firefox with NoScript without issue, and while amazon gets to run some scripts, none of the JS at amazon-adsystem.com ever runs in my browser.
Youtube wants to load JS from over a dozen different places, but you only need to allow a couple to get videos to play (I personally prefer to just download yt videos to disk and watch them in VLC avoiding that issue entirely)
So I did.
Most of the web works fine.
That's incorrect, especially the last part. Dark services work very hard to design their websites to work without JS, due to these exact vulnerabilities. Nobody on the dark web trusts JS, at all.
Now how much would you pay? :)
Nope. I do, and I'm not lying. I started because it was required for my work and I just got used to it and now do it everywhere. The internet with NoScript is the best way to browse 90% of the time.
Even today, the vast majority of the sites I visit (including the one linked to in this post) work just fine (for what I want) without JS. That means the text I clicked to read is displayed and is readable, the images I clicked to view are displayed, etc. Other parts of the site may not work (menus for example), but if I'm just following a link to an article I want to read and I can read it without javascript why do I care if the menus on the site are broken or if i can't leave a comment?
For the sites I regularly visit that really do need JS I enable only the JS files needed to accomplish the things that I want and that's only necessary to do one time for each site. NoScript remembers my preferences on each domain.
For those rare occasions I actually need to enable JS to get the functionality I want on a site I'm visiting only once I can just temp allow only the scripts I need to get the content I want and the next time I close my browser (or clear those temp permissions by hand) that site is no longer allowed to use JS. Ill admit that for some random sites I wasn't that interested in in the first place, there are times where I'll still just close the tab and move on.
I really don't understand why people think it's so hard to use the web with NoScript. Overall, websites load much faster and look cleaner without JS and I'm much much more secure. Most of the time, it's really not a problem.
I will say, I do have an add-on called NukeAnything that lets you right click and remove whatever you want from webpages (only until the page is reloaded) and that occasionally does help fix some issues for sites that don't handle the lack of JS gracefully. If somebody's poorly designed JS heavy menu is spewed all over the page and covering the content I want to see, I can just right click and remove it. Same with obnoxious "we use cookies" banners that I refuse to interact with.
Honesty it's the other things I've done to harden the browser (disabling redirects, service workers, WebGL, WebRTC, Wasm, location sharing, DRM, plugins, cookies, web storage, etc.) that cause the most problems with sites, and I do keep another unhardened browser around (brave atm) to handle the sites I absolutely need to access that depend on that junk.