Perhaps only enables js when user clicks something.
Perhaps only enables js when user clicks something.
setTimeout(() => {
// fuck up all future javascripts
setTimeout = setInterval = requestAnimationFrame = () => {};
Element.prototype.appendChild = () => { throw new Error("Blocked"); };
document.addEventListener = () => {};
window.addEventListener = () => {};
Object.defineProperty(document, "readyState", { get: () => { throw new Error("No JS"); } });
document.write = () => {};
// fuck up canvas
if(window.HTMLCanvasElement) HTMLCanvasElement.prototype.getContext=()=>null;
// fuck up webgl
if(window.WebGLRenderingContext) window.WebGLRenderingContext.prototype.getParameter=function(){e=>{throw new Error("Blocked")}};
// fuck up webgl2
if(window.WebGL2RenderingContext) window.WebGL2RenderingContext.prototype.getParameter=function(){e=>{throw new Error("Blocked")}};
// fuck up websockets
window.WebSocket=function(){e=>{throw new Error("Blocked")}}; window.EventSource=function(){e=>{throw new Error("Blocked")}};
// fuck up popups
window.open=()=>null;
// ...
}, 500); const iframe = document.createElement("iframe");
document.body.append(iframe);
iframe.contentWindow... javascript:(function () {
const rm = () => document.querySelectorAll('iframe')
.forEach(f => f.remove());
let timeout;
const debouncedRm = () => {
clearTimeout(timeout);
timeout = setTimeout(rm, 100);
};
rm();
new MutationObserver(debouncedRm)
.observe(document.body, {
childList: true, subtree: true
});
})();By farbling I mean making the data look like it's the most common Windows configuration, for example.
You will have messed up layouts and unneeded quirks. Moreover, banks are using fingerprinting to detect fraud so you will have a hard time on those websites as well.
And more importantly.
Of course I wouldn't farble on my bank's website, that would be pretty stupid.
But by default I would want trackers to get the farbled data, and only allowlist the websites I trust. Same trust concept as with uBlock Origin, NoScript and others.
I have been thinking about some kind of render proxy that runs all the JS for you somewhere else in a sandbox and sends you the screenshot or rendered HTML instead. Or maybe we could leverage an LLM to turn the Bloated JS garbage into the actual information you are looking for.
Nah, this is just straight up false. Many pages work fine with NoScript blocking all scripts. For those that don't, you usually only have to allowlist the root domain, but you can still leave the other 32 domains they are importing blocked. It's actually surprisingly common for blocking JS to result in a better experience than leaving it enabled (eg no popups, no videos, getting rid of fade-ins and other stupid animations).
I won't argue if you think that is too much work, and I definitely wouldn't recommend it for a non-technical user, but it's not nearly as bad as you described.
I wasn't clear, but this is about my experience. Maybe you are in a different bubble. But I'm not able to book a hotel, browse GitHub, file my taxes, make a bank transfer or even look up the menu of a restaurant.
The only exceptions for me are HN and a handful of news websites.