Microsoft on GitHub
microsoft.github.io
microsoft.github.io
http://benpowell.org/https-and-http-the-protocol-less-or-pro...
wf_segoe-ui_normal,"Segoe UI",Segoe,"Segoe WP",Tahoma,Verdana,Arial,sans-serifSending javascript over HTTP does technically allow for MitM attacks. Not to mention we know how great even Chrome's loudly bragged about sandbox is (it isn't is my point).
If you are loading the patch in https, all connections should be in https.
I wonder if they're gonna let their employees push atomic commits to this repository, or if it will be more like one big monolithic commit dump from time to time.
Generally for accessibility purposes websites should be designed so that basic text and links appear and are functional with JS disabled, and even CSS disabled. If the website is some sort of dynamic application with moving widgets than I can understand that JS might be needed, but not for a basic list of project Microsoft has put on Github.
Even if JS is used for templates, it is preferable to use semantic HTML that can be enhanced rather than using a template for the entire page and show "{tags}" all over the page when JS is disabled.
TLDR: A page with a basic list of projects shouldn't need JS. Web applications: yes, basic lists: no.
This will not give you malware. It might temporarily bog down your system though.
Mind you I indiscriminately clicked on known "bad" advertisements in the process of doing this. Don't believe me? Try it for yourself. It is actually very easy to get malware if you click around foolishly.
Also, I have written multiple web crawlers, and have collected a large variety of JS based malware that can and does break modern browser security just in the process of fetching domain homepages. ( JS code embedded directly in index.html on domains )
OK
Or, you know, maybe they aren't wasting a 0day on "obviously bad advertisements".