Post AZfz6VFuIj3j0XeLbc by potatogunkelly@infosec.exchange
 (DIR) More posts by potatogunkelly@infosec.exchange
 (DIR) Post #AZflsSw8pJp0MFNf9s by malwaretech@infosec.exchange
       2023-09-11T19:40:19Z
       
       3 likes, 6 repeats
       
       Translations: "our ad business is dying so we're forcing you to put more and unskippable ads on your videos so we can boost our earnings for the quarterly report"
       
 (DIR) Post #AZfz6VFuIj3j0XeLbc by potatogunkelly@infosec.exchange
       2023-09-11T19:46:14Z
       
       0 likes, 0 repeats
       
       @malwaretech vinegar is great! what equivalents are there for non safari browsers? anyone know? #youtube #enshittification
       
 (DIR) Post #AZfz6bnnxbjtJPYVH6 by f00fc7c8@0w0.is
       2023-09-11T19:48:15.034243Z
       
       1 likes, 0 repeats
       
       @potatogunkelly @malwaretech uBlock Origin on Firefox blocks all YouTube ads for me. (and most other ads)
       
 (DIR) Post #AZfz6dTJkkXWURzAcS by strypey@mastodon.nzoss.nz
       2023-09-12T01:54:01Z
       
       1 likes, 0 repeats
       
       @f00fc7c8> uBlock Origin on Firefox blocks all YouTube ads for meI use this as a backup. My primary digital prophylactic is NoScript, which gives me full control over which domain names websites can pull JavaScript from to run in my browser:https://noscript.net/usage/#NoScript #TrackingBlockers@malwaretech @potatogunkelly
       
 (DIR) Post #AZg3gXHCfFeLW7h2VU by f00fc7c8@0w0.is
       2023-09-12T01:55:27.057664Z
       
       0 likes, 0 repeats
       
       @strypey  @potatogunkelly tbh, given how overly dependent most websites are on JS, I’d prefer to have JS work by default, and block advertising and tracking scripts.
       
 (DIR) Post #AZg3gY4Ti345ywkOJM by strypey@mastodon.nzoss.nz
       2023-09-12T02:45:23Z
       
       0 likes, 0 repeats
       
       @f00fc7c8 > given how overly dependent most websites are on JS, I’d prefer to have JS work by defaultMost of the third-party JS sites load isn't needed, and most of that is DataFarming you and/or serving you ads. With NS you can set domains you visit regularly to 'trusted'.@potatogunkelly
       
 (DIR) Post #AZg3mOMOjAUdbLuoV6 by strypey@mastodon.nzoss.nz
       2023-09-12T02:46:28Z
       
       0 likes, 0 repeats
       
       @f00fc7c8> given how overly dependent most websites are on JS, I’d prefer to have JS work by defaultMost of the third-party JS sites load isn't needed, and most of that is DataFarming you and/or serving you ads. With NoScript you can set domains you visit regularly to 'trusted'.YMMV but before I discovered NS my browser used to regularly crash my OS right down to the kernel, requiring a hard shutdown. Presumably due to the chronic memory leaks created by shoddy, amateur JS.@potatogunkelly
       
 (DIR) Post #AZgYHq90TTYzNFYzmi by newt@stereophonic.space
       2023-09-12T08:27:46.647486Z
       
       1 likes, 0 repeats
       
       @malwaretech youtube has ads?
       
 (DIR) Post #AZgZESGQu6lMOczEsy by romin@shitposter.club
       2023-09-12T08:38:58.438650Z
       
       1 likes, 0 repeats
       
       @malwaretech looks like a 'not my problem' problem for us ytdlpchads.
       
 (DIR) Post #AZgbMw6s1PjFBbgaMy by Ariovistus@poa.st
       2023-09-12T09:02:55.115437Z
       
       0 likes, 0 repeats
       
       @malwaretech Wait, there are ads on YouTube??
       
 (DIR) Post #AZiB18oHuenniErQ4e by BiggusDiccus@poa.st
       2023-09-13T01:30:40.986872Z
       
       1 likes, 0 repeats
       
       @AriovistusWouldn't know. Newpipe ftw.@malwaretech
       
 (DIR) Post #AZkY6PNARnvJn3Zkno by aurelia@chaos.social
       2023-09-14T04:38:46Z
       
       0 likes, 0 repeats
       
       @SiteRelEnby @strypey @f00fc7c8 @potatogunkelly threat models in the 90s were wild. reminds me of an old SSL authenticity talk by m0xie where he finds the authors of the original X.5xx draft and gets “ohhh that authenticity thing, we just kind of threw that in at the end”
       
 (DIR) Post #AZkY6QK0v0zkjZ6kWe by strypey@mastodon.nzoss.nz
       2023-09-14T06:45:02Z
       
       0 likes, 0 repeats
       
       @aurelia > threat models in the 90s were wildYou've got to remember that in the 1980-90s, when engineers were tinkering with the chassis that everything in the modern internet is built on, only a tiny and *very* weird fraction of humanity  (like me) were interested in "cyberspace". Nobody anticipated that within a decade or two, pocket supercomputers with wireless networking would make the net appealing to huge chunks of the population.@SiteRelEnby @f00fc7c8 @potatogunkelly
       
 (DIR) Post #AZo9KmjyJp3DJQivEO by scunneen@mastodon.social
       2023-09-15T12:34:42Z
       
       0 likes, 0 repeats
       
       @SiteRelEnby @strypey @f00fc7c8 @potatogunkelly I dunno, I'm no security expert, but if javascript didn't exist websites could still track you using cookies and your ip address, meanwhile you'd have to download native apps for things like if you want your social media feed to refresh without you manually hitting reload.
       
 (DIR) Post #AZo9KnaRAl1Bw9Gp0a by strypey@mastodon.nzoss.nz
       2023-09-16T00:26:22Z
       
       0 likes, 0 repeats
       
       @scunneen> if javascript didn't exist websites could still track you using cookies and your ip addressOnly if you accept third-party cookies and don't use IP-obfuscation tools like TOR or a VPN.> you'd have to download native apps for things like if you want your social media feed to refresh without you manually hitting reloadSounds great! Infinite scroll turned out to be a bad idea. All digital wellness advice includes disabling it, where possible.@SiteRelEnby @f00fc7c8 @potatogunkelly
       
 (DIR) Post #AZoHGlmoiufwpPeP2m by scunneen@mastodon.social
       2023-09-16T01:55:15Z
       
       0 likes, 0 repeats
       
       @strypey @SiteRelEnby @f00fc7c8 @potatogunkelly Well, true, you can block 3rd-party cookies and use a VPN, but you can also disable javascript. Websites can refuse to work for users without javascript, but they can also refuse to work for people who disable cookies or use VPNs.
       
 (DIR) Post #AZoHdF3IauYVxv4jdA by scunneen@mastodon.social
       2023-09-16T01:59:20Z
       
       0 likes, 0 repeats
       
       @strypey @SiteRelEnby @f00fc7c8 @potatogunkelly I guess an ideal world might be if Javascript had been a feature that was off by default, that websites have to ask to enable, the same as they have to ask to use your camera and microphone. But I think in a world without Javascript, people would be installing a lot more native apps-- and native apps by default have the permission to read every file on your hard drive, so there's plenty more potential for spying there.
       
 (DIR) Post #AZq2IB94oZGYlsCDXk by strypey@mastodon.nzoss.nz
       2023-09-16T22:16:53Z
       
       0 likes, 0 repeats
       
       @scunneen> they can also refuse to work for people who disable cookies [third-party] or use VPNsI've yet to come across one.@SiteRelEnby @f00fc7c8 @potatogunkelly
       
 (DIR) Post #AZq39e57xcp1raqN7o by strypey@mastodon.nzoss.nz
       2023-09-16T22:26:31Z
       
       0 likes, 0 repeats
       
       @scunneen> native apps by default have the permission to read every file on your hard driveMaybe on Windows. Definitely not on Android. Don't know (or care) about iThings.@SiteRelEnby @f00fc7c8 @potatogunkelly