Posted by kevincox 2 hours ago
I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).
JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.
Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.
To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.
And then it expanded to serve the needs of billions of people instead of the needs of a few researchers. Womp, womp. Get over it, use a JS-free browser to browse your documents, and accept that the world has moved on. Or don't, and rant at clouds, I guess.
I feel there's a generalized decrease in quality in software in general.
Dear Diary,
Today my fanboy bubble was burst.
Signed,
Author
https://www.eff.org/deeplinks/2016/04/ciscos-latest-attempt-...
Cisco looks to have made money from repression and torture.
Meanwhile a large fraction of neo-nazis, credit card thieves, and DDoS-for-hire sites are on Cloudflare. It takes serious talent (not morals) to attack humanity at scale.
2. Why on earth would you want a financial product from a WAF?content delivery company?