sent from a disposable whonix qube

4-panel meme using the "You guys are getting paid?" template from "We're the Millers" * Person 1: "I thought it was enough to just install Firefox" * Person 2: "You're not blocking ads to protect your pc?" * Person 3: "Y'all are allowing sites to run scripts on non-virtualized systems?" * Person 4: "Y'all are allowing scripts?"
you are viewing a single comment's thread
view the rest of the comments
[–] 5 points 1 month ago (3 children)

What makes WASM more secure than JavaScript? I'd think that the main issue with JS is that it's a programming language that's running on the client-side, not that it's specifically JS.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 3 points 1 month ago (2 children)

    The fact that WASM is NOT a programmimg language, and that WASM is intrinsically sandboxed and has really granular permissions (through WASI).

    Also, how do you expect that, for example, a videoconference site (let's say, Jitsi Meet) will work if you don't execute any client-side code? And I'm not saying that all client-side code is permisible, justified or good, but rather that not all the client-side code is unpermisible, unjustified or bad, as you seem to imply.

    And if you do use FLOSS, that's really paranoid, even if FLOSS isn't perfect.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 1 month ago* (last edited 1 month ago) (1 child)

    Also, how do you expect that, for example, a videoconference site (let’s say, Jitsi Meet) will work if you don’t execute any client-side code?

    I never said that you should never run client-side code. Even OP doesn't say that (which is why they're running some sites in Whonix, they just really don't like it), and they're way more extreme about not allowing JS than I am.

    The fact that WASM is NOT a programmimg language, and that WASM is intrinsically sandboxed and has really granular permissions (through WASI).

    Interesting. Are the actual implementations of it sufficiently secure so far?

  • source
  • parent
  • hideshow 1 child comment
  • I never said that you should never run client-side code. Even OP doesn't say that (which is why they're running some sites in Whonix, they just really don't like it), and they're way more extreme about not allowing JS than I am.

    I have to admit that I may have exaggerated a bit, but I think the point is still clear.

    Interesting. Are the actual implementations of it sufficiently secure so far?

    Yeah, at this point it's quite mature, and especially the implementations in languages like Rust, Zig, or Nim are particularly secure, although the classic ones in C or C++ are too, and there are great implementations for JS, TS, and other subsets of ECMAScript.

  • source
  • parent