sent from a disposable whonix qube

  • keiko@fedia.ioOP
    link
    fedilink
    arrow-up
    9
    ·
    1 day ago

    Okay I just did some cursory research and it doesn’t sound simple. Is it just installing qubes-whonix and creating a template (I’m guessing a yaml config or similar)?

    During the installation of Qubes OS, you can select a checkbox to have Whonix templates and qubes automatically installed. After installation, you can simply click a launcher to start an app like Tor browser in a new disposable whonix qube from the disposable whonix template. It really is that simple. Installing Qubes OS does take a while though.

    As far as sites with JavaScript being “broken”, that one puzzles me. I have tried turning off JavaScript in the past and probably 70% of websites became fully non functional.

    Yes, those sites which become non-functional without javascripts are very much broken.

    That shouldn’t be the case, but it often is, and my impression has been that this has gotten worse, not better.

    Yes, much of the web is broken. On a related note, much of the web is infested with malicious ads and trackers.

    I’m a web developer and no one talks about progressive enhancement anymore and frankly my coworkers have mostly thought it’s silly to even try to support users who turn off JavaScript.

    That’s a shame. And yeah, those are basically just dead sites. If they’re non-functional then there’s really no point for them to exist.

    As the web continues to devolve, with a growing graveyard of dead sites (and an increasing prevalence of malicious scripts), I hope that more people wake up to the reality that this is bad. It’s similar to the dead-end that is google’s android. Eventually they’ll pull it away and leave a lot of people scrambling for their next option. I think the modern web will go through a similar transformation one day. I hope so.

    • TrickDacy@lemmy.world
      link
      fedilink
      arrow-up
      6
      ·
      1 day ago

      I will give qubes-whonix a shot, you have convinced me!

      There are certain functionalities that cannot be done without JavaScript. In my perfect world either no one would abuse JavaScript with ads and other shitty design choices, or at least I’d have an easier time with toggling it off/on. For now I’m leaving JavaScript on because it’s simply far too inconvenient otherwise. Browsers are pretty good about preventing actual harm if you have UBO installed though.

      Out of curiosity, what harm are you concerned about JavaScript doing with an ad blocker and while loading sites within a container? That seems extreme to me.

      • keiko@fedia.ioOP
        link
        fedilink
        arrow-up
        3
        ·
        1 day ago

        I will give qubes-whonix a shot, you have convinced me!

        You definitely shouldn’t rush into Qubes OS. If you’re seriously interested, I’d recommend checking out videos and reading about it so you can understand it a little deeper.

        Out of curiosity, what harm are you concerned about JavaScript doing with an ad blocker and while loading sites within a container? That seems extreme to me.

        Besides that fact that javascripts can be used to track and profile users, they also make the user experience of sites worse. I love static pages. Sites that require javascripts are the polar opposite of that. Useless blur effects and other “features” can cause pages to be significantly slower than static pages, and I absolutely hate it. I should be able to scroll smoothly and click buttons once the page has loaded, and I should be able to keep pages cached indefinitely. With javascripts, scrolling can often be laggy, buttons can appear and disappear in odd ways, and pages can be automatically reloaded without my consent, causing lots of frustrations. I cannot understand how anyone prefers browsing the web with javascripts. They are a fucking cancer, like 99% of the time.

        • TrickDacy@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          1 day ago

          I hear you on qubes.

          RE: js, you’re talking about the web as if it should only ever be what it was first conceived of: documents. In reality now it’s used for full on software applications. It’s not just used for animations and polish (and the shitty things you mention specifically), it’s also used for dynamically updating the UI. A world you speak of would mean much worse order forms, paperwork for doctors, etc. I mean you do you, but you can’t just not acknowledge that dynamic updates of a UI are better than filling out a long form then getting back “invalid data, you selected this and entered that, start over”. It’s literally useful.

          The tracking concerns are mostly mitigated by vpns, ad blockers, and private browser features. I understand there are many flaws and issues I’m glossing over, but for the most part, the average person can just use those things, then opt to close the tab of a horrible website like you’re describing.

          tldr; you may prefer static documents, but modern society is built on forms and other types of vital apps, which would inevitably be worse without javascript.

          • Individual Orchid@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            3
            ·
            23 hours ago

            I did web Dev when that was how sites worked, and they worked fine. No, it was never live updating, but the errors could be corrected and resubmitted just fine. I don’t use QubeOS but this post has me intrigued.

          • keiko@fedia.ioOP
            link
            fedilink
            arrow-up
            2
            ·
            23 hours ago

            In reality now it’s used for full on software applications.

            I think software applications are better made as actual applications instead of browser-based web-apps.

            it’s also used for dynamically updating the UI.

            It might seem useful on the surface but is prone to the same sorts of breakage and annoyances I was talking about.

            A world you speak of would mean much worse order forms, paperwork for doctors, etc. I mean you do you, but you can’t just not acknowledge that dynamic updates of a UI are better than filling out a long form then getting back “invalid data, you selected this and entered that, start over”.

            That’s an interesting example, because that’s happened to both of my parents within the past few months from two different healthcare-related sites. The javascript elements frustrated them more than me, since they didn’t understand why certain things weren’t working, and I had to figure it out for them. And there were a few times when we had to start over due to the sites being poorly made.

            That’s really what I see in this reliance on javascripts, corner-cutting which causes problems. Properly-configured sites work better, and the ones reliant on javascript tend not to be.

            I would prefer static order forms so that I can have the entire form and fill it out before submitting, while retaining a copy so that if there were issues I could more quickly and efficiently resubmit with the corrections.

            Some people might prefer the dynamically updating UI stuff, but except for live chats I can’t see a good use for it that static pages can’t do better. And I think live chats are better in non-web apps which support end-to-end encryption anyway.

            The tracking concerns are mostly mitigated by vpns, ad blockers, and private browser features.

            The most useful and efficient private browsing feature is the ability to disable javascripts. Using vpns and ad-blockers protects against very specific vectors of surveillance, while javascripts allow a diverse set of surveillance capabilities, so blocking them protects against several forms of surveillance. And with more people disabling javascripts, we all blend together better.

            you may prefer static documents, but modern society is built on forms and other types of vital apps, which would inevitably be worse without javascript.

            Modern society is also built on ignorance, conformity, and exploitation, all of which make javascript-based sites more dangerous and prone to issues. It’s the easy answer thrown at every problem, like “a.i.” and is similarly dangerous.

            • TrickDacy@lemmy.world
              link
              fedilink
              arrow-up
              2
              ·
              23 hours ago

              So you’re saying all of this as though “on the surface” is all I’ve ever considered and have never tried to do what you claim to be the only acceptable way to do things. It is only your opinion that dynamic UI elements aren’t worth it. They particularly help with forms. Conditional data in forms aren’t something I just made up, it’s a legit use case. Again I’ve tried your way and I lasted less than a day. Very poor experience.

              • keiko@fedia.ioOP
                link
                fedilink
                arrow-up
                2
                ·
                23 hours ago

                I was talking about my own experiences. We can agree to disagree on what is a better user experience, as it’s inherently subjective. I can’t think of a site I’ve come across that was made better by javascripts, from my own perspective and experiences. I have always been let down and frustrated by such sites and always relieved to find static sites.

                It is only your opinion that dynamic UI elements aren’t worth it.

                Yes. And for all of the reasons I’ve given, I stand by my opinions on javascripts. You’re free to disagree. I wasn’t trying to convince anyone, just sharing my experiences and opinions on them.

                Sorry if I came across as dismissive of your experiences and opinions.

                • TrickDacy@lemmy.world
                  link
                  fedilink
                  arrow-up
                  3
                  ·
                  22 hours ago

                  I understand, I just felt you were stating things as if they’re objectively true. Maybe I missed something. Have a good rest of your day.

    • Kangae_Hishiryo@scribe.disroot.org
      link
      fedilink
      arrow-up
      3
      ·
      1 day ago

      Wasm seems like a good step towards a better web, and still is something really niche AFAIK.

      I hope that it becomes standard, because is way more secure, and of course more performant than JS.

      I do even think that the HTML+CSS+JS triad (and its single components, too) are a historical bad design decision, a HUGE one, and should’ve superseded.

      • rumschlumpel@feddit.org
        link
        fedilink
        arrow-up
        6
        ·
        23 hours ago

        What makes WASM more secure than JavaScript? I’d think that the main issue with JS is that it’s a programming language that’s running on the client-side, not that it’s specifically JS.

        • Kangae_Hishiryo@scribe.disroot.org
          link
          fedilink
          arrow-up
          3
          ·
          19 hours ago

          The fact that WASM is NOT a programmimg language, and that WASM is intrinsically sandboxed and has really granular permissions (through WASI).

          Also, how do you expect that, for example, a videoconference site (let’s say, Jitsi Meet) will work if you don’t execute any client-side code? And I’m not saying that all client-side code is permisible, justified or good, but rather that not all the client-side code is unpermisible, unjustified or bad, as you seem to imply.

          And if you do use FLOSS, that’s really paranoid, even if FLOSS isn’t perfect.

          • rumschlumpel@feddit.org
            link
            fedilink
            arrow-up
            1
            ·
            edit-2
            7 hours ago

            Also, how do you expect that, for example, a videoconference site (let’s say, Jitsi Meet) will work if you don’t execute any client-side code?

            I never said that you should never run client-side code. Even OP doesn’t say that (which is why they’re running some sites in Whonix, they just really don’t want to), and they’re way more extreme about not allowing JS than I am.

            The fact that WASM is NOT a programmimg language, and that WASM is intrinsically sandboxed and has really granular permissions (through WASI).

            Interesting. Are the actual implementations of it sufficiently secure so far?