Comments

Bad .js • September 24, 2026 8:17 AM

What I’m stating below is what I basically realized after reading the linked article in Bruce’s topic above, so it’s an on-topic response as well as a rant if you will, of sorts.

javascript is being incorporated almost everywhere, and it angers me that it’s even being shoved down everyone’s throat even where it’s not needed at all. Many, very many sites, apps, systems, operating systems, files – could do/function just fine without the pest called .js which is worse than what we had with the nasty flashplayer a while ago.

On top of that, although I am trying as much as possibly permitted to utilize FOSS – I am still longing and hoping for that day to come, where the dependencies nightmare gets taken care of, so that one does not end up breaking a system while attempting to completely remove CUPS for example, and there are many more cases where one simply cannot remove unwanted software because it uses the same dependencies as some or bunch of other “critical” system components. A nightmare. Plus there’s more and more instances where many FOSS “players” are accepting “donations” or grants from Microsoft in order to quietly return the favor by incorporating some or many of MS “ideas” or concepts into their packages while developing new concepts or “improving” the old ones. It’s truly disgusting what money buys. These things are getting worse by the day. Can’t even trust the FOSS guys anymore.

Hardcore Criminals in ID Government • September 24, 2026 8:59 AM

I’ve told these toddlers here in ID that I know all about their bugs and stingrays even those in our home allowing them to spy on our family 24/7 in real time. I do not care. And yet, you have this one toddler, constantly coming right here to this blog, knowing that I read this blog every single day, posting the “observations” witnessed in our residence in real time such as our f@rt$, burps, rants – and that is ALL YOU’RE EVER GONNA GET ya toddler.

YOU WILL NEVER EVER CATCH THIS SPY. YA JUST AIN’T QUALIFIED. NOT YOU, AND NOT ANYONE ELSE IN THIS $HT-H013 MY FAMILY AND I (SADLY) CHOSE TO CALL OUR HOME ALMOST 30 YEARS AGO BECAUSE WHAT DID WE GET IN RETURN FOR BEING DECENT PEOPLE?

DESTRUCTION.

YOU HAVE DESTROYED AN INNOCENT AND DECENT FAMILY, AND YOU WILL NEVER ADMIT IT, ACK IT, OR APOLOGIZE FOR IT BECAUSE YOU ARE MONSTERS LEECHING ON THE TAXPAYERS’ MONEYS AND YOU DO NOT WANT THE PEOPLE WHO ELECTED YOU TO REPRESENT THEM TO EVER FIND OUT ABOUT IT – AND I AM SUPPOSED TO BE THE BAD GUY FOR TELLIN’ IT ALL. YOU CAN ONLY COME HERE TO PROVOKE ME BUT YOU WILL NEVER EVER HAVE ANYTHING ON ME. EVER.

God bless Israel – YOUR BOSS – whether ya like it or not – TRUTH HURTS.
FACTS HURT.

Here’s them facts and the TRUTH. READ AND WEEP.
short url.at/Qntuk

Clive Robinson • September 24, 2026 11:33 AM

@ Bruce, ALL,

From the article,

“Developers are advised not to rely on install-time scanning alone, and to also employ runtime behavioral analysis.”

I pointed out some years ago as part of “Castles-v-Prisons”[1] that malware could not hide it’s runtime signature or the changes it made to the legitimate softwares signiture especially when you had a hypervisor looking for such changes using “probabilistic” methods.

Today they call part of it “runtime behavioural analysis” but they miss a lot of security the use of “prisons” and “probabilistic security” gives over the “castle” environment.

I described various bits of “Castles-v-Prisons” here back more than a decade ago…

As @Thoth found a certain graduate of the UK Cambridge Computer labs who moved to “University College London” stole the work and set up a company to try and sell it…

So there might be something behind the idea 😉

And for those who read the conversations and remember them, it just shows how,

“You can read about it here first on this blog”.

[1] @Wael did not like using the full name so he shortened it via “C-v-P” to “CvP”.

Clive Robinson • September 24, 2026 11:57 AM

@ Bad .js,

With regards,

“javascript is being incorporated almost everywhere, and it angers me that it’s even being shoved down everyone’s throat even where it’s not needed at all. Many, very many sites, apps, systems, operating systems, files – could do/function just fine without the pest called .js which is worse than what we had with the nasty flashplayer a while ago.”

Yup I pointed out that both JavaScript were bad news security wise many years ago on the pages of this blog.

And you would not believe the amount of grief I got because of it… (and never an apology from any of them).

Especially when I said people should turn JavaScript off in the browser and uninstall it and flash from their computers…

Well Flash went first as people quickly realised what bad news it actually was. Javascript is unfortunately still with us even though it’s worse security wise. The only saving grace is lots of people have made the defences against javaScript more significant than they used to be.

But the truth is I’ve yet to find a server that runs javascript on a clients computer that is actually worth bothering with…

The really annoying thing though is the clowns and crooks in the W3C… that insist that they must be able to run code on a client computer thus keep shoving such nonsense into Web Client specifications.

Every time they have forced some client side executable into Web Standards it has become a major security fault…

You would have thought they would have learnt by now… But apparently not…

Bad .js • September 24, 2026 1:28 PM

@Clive Robinson,
a question for you:

if I could convince you that by trying very hard, for decades, to protect as much as I can, on my end, the privacy of myself and my family while online (which is extremely hard, nearly impossible) by doing so I have drawn so much attention from my government that they have destroyed me and my family for just ASSUMING that the reason I’ve been doing so – “he must be hiding something” to the point where my entire family suffers this eavesdropping and being spied upon for many years now, to the point that the HICKS here in ID aren’t even allowing me to retain a lawyer, in a situation where I nearly got taken out but was convicted a felon because my government wanted this conviction so badly that they’ve gone as far as to cover up the attempt on my life, so that they could get the “GUILTY” verdict – no matter what, hence the WARRANTLESS SURVEILLANCE 24/7/365 as warrants aren’t needed for felons.

I hate my own country which prides itself for being a place where EQUAL JUSTICE FOR ALL and The Rule of Law are supposed to be a thing.
I HATE my country because I AM HUMILIATED TO THIS POINT OF HAVING TO BEG FOR JUSTICE. ONLY AFTER THE SAME PEOPLE IN MY GOVERNMENT HAVE COVERED UP THE ATTEMPT ON MY LIFE. I AM BEGGING THE SAME MONSTERS FOR JUSTICE.

I MUST BE EFFIN INSANE.

As a matter of fact, my shrink Thad Koontz told me that the most likely reason I’ve been diagnosed as DELUSIONAL was because I TRUSTED THE PUBLIC DEFENDER assigned to me, as well as BELIEVING IN THE EFFIN NON-EXISTENT “rule of law” AND EQUAL JUSTICE for all in “murky ‘murca” – because justice is only if you’re connected to obamas, bidens, trumps, and all others who will pardon you for a lot of money under the table and through the back channels – kind of money I DO NOT HAVE.

SCREW A COUNTRY WHERE I HAVE TO BEG FOR JUSTICE.

short url.at/Qntuk

I just want as many people as humanly possible to know how dangerous some humans are when REAL POWER OF PERSECUTION IS ENTRUSTED TO THEM.

This is NOT THE AMERICA I DREAMED OF as a European teenager over 40 years ago. I guess I should have been a female from Slovenia with a severely broken English – in which case, I would have made it – BIGLY!
Now, that kind of immigrant “workers” ID MAGA LOVES, I am sure of it.

Yes, the first post is mine, as is the second, and this one as well.

Celos • September 24, 2026 4:57 PM

Does not sound that impressive to me. More like what I would expect from a competent expert. I am pretty sure I have had the occasional student that could do this, no nation state needed.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.