• helpImTrappedOnline@lemmy.world
    link
    fedilink
    English
    arrow-up
    19
    ·
    edit-2
    1 day ago

    There may be genuine use cases to run a script, or whatever the attacker used. The problem is the browsers will auto-run stuff, the user isn’t aware and there’s no way to stop it. All ublock (and others) do is provide the missing security layer called “don’t auto run shit from the web”.

      • helpImTrappedOnline@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 hours ago

        Yeah, you’re right. I guess a better way to put it would have been “don’t load 3rd party shit that I didn’t tell you to load”.

        Adblockers aren’t total security, nothing is, but it’s no doubt they are a massive improvement.

      • ∃∀λ@programming.dev
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 hours ago

        The NoScript extension will properly do this. The extension blocks domains from running scripts except those you’ve whitelisted. There’s a drop down that displays a list of domains from which the page wishes to run scripts. It makes much of the web a pain to use, though. I sometimes have to go through a loop of whitelisting a subset of domains which want to run followed by a page refresh until the page works. Javascript is often not optional. If you had to live like Richard Stallman professes you should, you’d probably have to join the Amish.