Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Web security wasn't hard before we started trying to make the web a platform for full executable software.

I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).

JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.

Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.

 help



None of this required Javascript. At all. The same potential attack could have been done with good ol' forms. Sure, you think you're signing into "BigBensSuperStore.com", but you're actually handing your credentials right over to "BigBensSuperStore.net".

JavaScript (and other forms of executing logic within the browser) have made the situation worse, though.

To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.


If a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.

Bad actors have been social engineering passwords for years even before a single line of JS was written. Restricting the backend is a way of heavily reducing the attack surface. The expansion of hardware access to browsers is the largest scam enabler of the 21st century. The only reason it's happening in the long term is because companies like Google (DoubleClick) wish to use hardware attestation to tie people to hardware for advertisement purposes, and that requires complete vertical attestation.

We're losing general-purpose computing like frogs in a slow cooker, and millions of people don't even notice. Fuck TPM, fuck hardware attestation, no internet company should get a single bit from me that I don't authorize. Any site that requires hardware attestation will be a hard "no" for me to ever visit again.

I maintain this all started when commerce was introduced to the internet. Things were better before money was transferred digitally. Allowing that was a major fuckup.


> "The web" was never designed to be an application platform. It was only designed to be a document platform.

And then it expanded to serve the needs of billions of people instead of the needs of a few researchers. Womp, womp. Get over it, use a JS-free browser to browse your documents, and accept that the world has moved on. Or don't, and rant at clouds, I guess.


You realize the same argument applies to Word macros.

I think someone should ask Vint Cerf whether he ever intended the web to run executable code, and enforce that answer on the existing web.

I bet the world would crumble. Good.


This is base stupidity. Suppose you used your web-dictator powers to strip JS from the web based on historical decisions made 50 years ago. Then everyone other than you would use Web2 and ignore you. Indeed Web 2.0 is already a term recognising that the web has changed since it was first conceived; I guess it would make you feel better if we formalised it and formally created a new Web that's exactly like the current Web except with nobody who can claim things about how it was "supposed" to work in the 1970s?

Clearly you have a vested interest in the status quo of today, instead of understanding why the whole network was created in the first place.

Your viewpoint enables billions of dollars of fraud every year, worldwide. Mine doesn't.

Email has similarly been destroyed by HTML email, at least partially.

It's like there is a coordinated effort to destroy every single legacy protocol and replace it with something centrally controlled. No fucking thank you.


"The whole network was created in the first place" to serve the needs of a tiny number of academic and military researchers. This legacy is completely irrelevant to why it exists today. Again, we can kill Web1 if it makes you happy, so we can get rid of your tired appeal to "but the 1970s design!!!". If we kill it, then people will just create some new network that serves the actual use cases of billions of people, because there will still be demand for software that does more useful things than sharing documents. And when that new network is created, it will be exactly the same as the current one, but it will have been made in the 2020s, so you can finally STFU about the 1970s. Would engaging in that farce make you happier?

> Your viewpoint enables billions of dollars of fraud every year, worldwide.

Yep. Having knives in every kitchen enables people to be stabbed, too. As a society we choose to allow useful things to exist rather than locking everyone in a straitjacket, even though the latter would be more safe and prevent all kinds of crime and tragedy. It's funny that you complain about centralizing control at the same time as making this argument that nobody should have tools because tools can be misused.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: