<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dw="https://www.dreamwidth.org">
  <id>tag:dreamwidth.org,2010-05-25:518129</id>
  <title>Rick Scott</title>
  <subtitle>Testing, hacking, and Open Source</subtitle>
  <author>
    <name>Rick Scott</name>
  </author>
  <link rel="alternate" type="text/html" href="https://rickscott.dreamwidth.org/"/>
  <link rel="self" type="text/xml" href="https://rickscott.dreamwidth.org/data/atom"/>
  <updated>2010-05-25T17:02:43Z</updated>
  <dw:journal username="rickscott" type="personal"/>
  <entry>
    <id>tag:dreamwidth.org,2010-05-25:518129:1512</id>
    <link rel="alternate" type="text/html" href="https://rickscott.dreamwidth.org/1512.html"/>
    <link rel="self" type="text/xml" href="https://rickscott.dreamwidth.org/data/atom/?itemid=1512"/>
    <title>Quick Hit: I just don't get it...</title>
    <published>2010-05-25T17:02:43Z</published>
    <updated>2010-05-25T17:02:43Z</updated>
    <category term="www"/>
    <category term="noscript"/>
    <category term="quick hit"/>
    <category term="javascript"/>
    <category term="wtf"/>
    <category term="security"/>
    <dw:security>public</dw:security>
    <dw:reply-count>0</dw:reply-count>
    <content type="html">&lt;p&gt;I admit, I'm not super-knowledgeable about security.  I know some of the fundamentals, but not a great deal beyond that.&lt;/p&gt;
&lt;p&gt;Still, in my early days on the 'net I got the distinct impression that &lt;strong&gt;allowing random people to execute arbitrary code on your computer is bad&lt;/strong&gt;. I mean, that's somebody else using your computer to do stuff without your knowledge or consent, right? That's why attacks like this  really, really make me shake my head (NSFW, offensive, &lt;em&gt;turn off javascript before following&lt;/em&gt;):&lt;/p&gt;
&lt;pre&gt;hxxp://encyclopediadramatica.com/Firefox_XPS_IRC_Attack &lt;/pre&gt;
&lt;p&gt;Despite all this, somehow today's ordinary browsing experience consists of downloading pages full of arbitrary javascript written by any random person who controls a website, then blithely running them on your machine.&lt;/p&gt;
&lt;p&gt;I don't get it.  Where did we go wrong?&lt;/p&gt;
&lt;p&gt;(PS. Firefox users: &lt;a href="http://noscript.net/"&gt;NoScript&lt;/a&gt; is your  friend. =)&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="https://www.dreamwidth.org/tools/commentcount?user=rickscott&amp;ditemid=1512" width="30" height="12" alt="comment count unavailable" style="vertical-align: middle;"/&gt; comments</content>
  </entry>
</feed>
