Top
Best
New

Posted by kevincox 2 hours ago

Web security is too hard(textslashplain.com)
124 points | 51 commentspage 2
LocalH 1 hour ago||
Web security wasn't hard before we started trying to make the web a platform for full executable software.

I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).

JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.

Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.

OkayPhysicist 1 hour ago||
None of this required Javascript. At all. The same potential attack could have been done with good ol' forms. Sure, you think you're signing into "BigBensSuperStore.com", but you're actually handing your credentials right over to "BigBensSuperStore.net".
LocalH 1 hour ago||
JavaScript (and other forms of executing logic within the browser) have made the situation worse, though.

To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.

saghm 23 minutes ago||
If a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.
applfanboysbgon 1 hour ago||
> "The web" was never designed to be an application platform. It was only designed to be a document platform.

And then it expanded to serve the needs of billions of people instead of the needs of a few researchers. Womp, womp. Get over it, use a JS-free browser to browse your documents, and accept that the world has moved on. Or don't, and rant at clouds, I guess.

TZubiri 1 hour ago||
this from a company whose main product is (was) security.

I feel there's a generalized decrease in quality in software in general.

iryndin 1 hour ago||
[dead]
thataccount 2 hours ago||
Cloudflare is your favorite company and they are geniuses?

Dear Diary,

Today my fanboy bubble was burst.

Signed,

Author

ericlaw 1 hour ago|
Note that I said: "One of my", and Cloudflare has hired a HUGE percentage of the best networking talent I've encountered.
thataccount 1 hour ago||
Another company named Cisco used to do that. They built the Great Firewall of China. Hiring talent does not equal good company.
Panino 1 hour ago||
I hadn't read that so I looked it up to verify, and it appears true:

https://www.eff.org/deeplinks/2016/04/ciscos-latest-attempt-...

Cisco looks to have made money from repression and torture.

Meanwhile a large fraction of neo-nazis, credit card thieves, and DDoS-for-hire sites are on Cloudflare. It takes serious talent (not morals) to attack humanity at scale.

sghiassy 2 hours ago||
Just use LLMs. They can apparently doing everything and all the things
wackget 1 hour ago|
1. Why is this website blocked when I try browsing it using Brave?

2. Why on earth would you want a financial product from a WAF?content delivery company?

aDyslecticCrow 59 minutes ago|
You didn't read the whole article; it's not a scam, it's a new official cloud-flare product.