Salta al contenuto principale



"The announcement was 782 words, followed by a nervous clarification of 731 words. The page featured 48,320 words of comments in just 24 hours" Here's a new one for @crikey.com.au trying to figure out why the presence of backlash to "AI" is so weirdly uneven -> www.crikey.com.au/2025/06/23/i...


Your regular reminder that Robert Reich opposed building affordable housing in his rich Berkeley neighborhood. He talks a good game about helping low income people. Unless they intend to live anywhere near him. www.reddit.com/r/berkeley/c...
RE: bsky.app/profile/did:plc:p3yen…

Robert Reich writes in opposit...



Is there a way to block browser JavaScript from executing commands that retrieve sensitive information from my local machine, while still allowing JavaScript that is only used for rendering web pages?


As a security-conscious user, I've used NoScript since Firefox's early days, but its restrictive nature has become frustrating. I'm often forced to go unprotected just to access websites with multiple scripts running on different domains, which defeats the purpose of using NoScript and balances security and usability that it once provided.

Is there a way to block browser JavaScript from executing commands that retrieve sensitive information from my local machine, while still allowing JavaScript that is only used for rendering web pages?

by sensitive information I'm referring to
- local machine time
- local machine ram
- local machine operating system + version
- local machine hardware
- Serial Number
- Hardware ID
- UUID
- Windows Device ID
- Windows Product ID
- ...

greatly appreciate any insight


EDIT:

could be possible solution

discuss.grapheneos.org/d/16025…
- ~~LibreJS: GNU LibreJS aims to address the JavaScript problem described in Richard Stallman's article The JavaScript Trap.~~
- JShelter: Mitigates potential threats from JavaScript, including fingerprinting, tracking, and data collection. Slightly modifies the results of API calls, differently on different domains, so that the cross-site fingerprint is not stable. Applies security counter-measures that are likely not to break web pages. Allows fine-grained control over the restrictions and counter-measures applied to each domain.


@bjoern_tantau@swg-empire.de

Most of those things cannot be collected through JavaScript.

Local time can.

RAM can only be approximated to protect user privacy. Edit: And it’s not available on Firefox.

OS+version are already in your browser’s user-agent string that is sent out with every request you make.

Machine hardware cannot be enumerated. JavaScript can try to guess your GPU based on what it can do with WebGL.

There is no way to get a serial number or similar.


To spoof timezone/OS+version/browser+version ... and disable WebGL, use sereneblue.github.io/chameleon…
- lemmy.world/post/31885153

Questa voce è stata modificata (2 mesi fa)
in reply to Holeheadou92984

Harsh question: Do you have a real need to prevent this data from being collected, or are you investigating just for ~~funsies~~ best practice advice? There are a lot of posts like this where people overestimate the threat model they have and insist on needing to block things that are nearly impossible to, or at least have significant tradeoffs like you are dealing with now.

Javascript is also not the only source that sites can use for these pieces of info from your machine. Local time in particular can be estimated by looking up the rough location of your IP address then matching to a time zone.


Anyway.

I would assume you could technically fork localCDN (replaces remote javascript libraries with local copies) and then manually edit the local javascript library copies to remove the calls you are concerned about.

There's also options like uBlock Origin's methods of only whitelisting specific scripts. Much more flexible than NoScript. You can block scripts that are third party and only allow site specific ones fairly easily, without digging deep into the settings.

Bear in mind that your specific combination of installed extensions can also be a unique identifier though.

in reply to wizardbeard

Do you have a real need to prevent this data from being collected


maybe

or are you investigating just for best practice advice?


yes

There are a lot of posts like this where people overestimate the threat model they have and insist on needing to block things that are nearly impossible to, or at least have significant tradeoffs like you are dealing with now


could you explain why it is nealy impossible from only blocking javascript from attaining "local machine operating system + version
"? I don't think this kind of information is relevant for webpage displaying. I dont think webpage will break if we ban js from doing so

I would assume you could technically fork localCDN (replaces remote javascript libraries with local copies) and then manually edit the local javascript library copies to remove the calls you are concerned about.


that could work I guess when I have enough js knowledge

There’s also options like uBlock Origin’s methods of only whitelisting specific scripts. Much more flexible than NoScript. You can block scripts that are third party and only allow site specific ones fairly easily, without digging deep into the settings.


is it possible to adjust uBlock Origin whitelisting and disallow js that retrieve "local machine operating system + version
" from running?

Bear in mind that your specific combination of installed extensions can also be a unique identifier though.


Does this mean website can see all the extensions I installed?

in reply to Holeheadou92984

Some browsers have built in fingerprint resistance techniques you can enable:

support.mozilla.org/en-US/kb/r…

I wouldn't entirely trust it, but enabling this feature in strict mode would tick a few of your listed boxes.



act.350.org/sign/jun-25-em-pet…

US citizens: call on JPMorgan Chase to stop bankrolling fossil fuel exploration in the Amazon.





We will end this war, Iran warns ‘gambler’ Trump dawn.com/news/1919362/we-will-…


Just added a full article to the VEX.blue BETA site!

I wrote it during the 2.2 redesign; when I rebuilt the coding the site from scratch (half a year ago), figuring out design, RSS, and even future plans for tutorials like "How to join the Fediverse?"

Oh and it now supports Fediverse comments! (Just reply to this post)

Reply via your timeline 🌀
new.vex.blue/articles/2024/09/…

#VEXblue #Fediverse #OpenWeb #IndieWeb #Blogging #WebDev #RSS #StaticSite #DevJournal #Mastodon

Questa voce è stata modificata (2 mesi fa)
in reply to Break3 Studios

It's so good to see this actually working, I've come a long way since v2.2, and hopefully v4.0 will be on our main site soon.
in reply to Break3 Studios

This is one of the best things. Love seeing it in action.
Questa voce è stata modificata (2 mesi fa)




TikTok Shop é confiável? 5 coisas que você precisa saber sobre a loja
https://www.techtudo.com.br/guia/2025/06/tiktok-shop-e-confiavel-5-coisas-que-voce-precisa-saber-sobre-a-loja-edapps.ghtml?utm_source=flipboard&utm_medium=activitypub




Organizei minha alimentação com o ChatGPT — 5 prompts para usar agora
https://www.techtudo.com.br/listas/2025/06/organizei-minha-alimentacao-com-o-chatgpt-5-prompts-para-usar-agora-edsoftwares.ghtml?utm_source=flipboard&utm_medium=activitypub



la bellesa d'una merda

Eye reshared this.

in reply to Amkiel

I did not know Common Blue butterflies are attracted to poo!

I wonder what they do with it 🤔



DHL, UPS, FedEx, and Walmart are using robots to boost warehouse efficiency and cut costs, including automating the physically demanding task of loading trucks (Esther Fung/Wall Street Journal)

wsj.com/business/logistics/the…
techmeme.com/250623/p10#a25062…



Le radici del conflitto tra Armenia e Azerbaigian. Le guerre degli ultimi trent’anni, l’esodo degli armeni e il futuro della regione. Un reportage storico per capire una delle crisi più intricate della nostra epoca: intern.az/1Nm2

Zeppe reshared this.




in reply to KOMATSUDIARA Seiichi

白い皿に、白米、炒めたキャベツ、サラダ、サクサクの衣付きの揚げ物、半熟の卵、ソーセージが盛り付けられています。皿の右側には、深みのある赤色の飲み物が入ったグラスが置かれています。皿は、ピンクと白のチェック柄のテーブルクロスの上に置かれています。全体的に、家庭的な雰囲気の食事のシーンです。

@altbot によって提供され、Ovis2-8B を使用してローカルでプライベートに生成されました

🌱 エネルギー使用量: 0.141 Wh



in reply to Korallenherz

Das Bild zeigt eine Gruppe von sechs Militärs in Uniform, die an einem langen, rechteckigen Tisch sitzen. Sie befinden sich in einem Konferenzraum, der mit einer großen Weltkarte an der Wand hinter ihnen geschmückt ist. Die Uniformen der Militärs sind mit verschiedenen Abzeichen und Orden verziert, was auf ihre Ränge und Rollen hinweist. Links und rechts der Weltkarte hängen Porträts von Personen, die wahrscheinlich wichtige Persönlichkeiten sind. Die Flagge des Iran ist an der linken Wand sichtbar. Auf dem Tisch befinden sich Mikrofone und Dokumente, was auf eine formelle Besprechung hinweist. Im unteren Bereich des Bildes ist ein Text zu sehen, der auf Deutsch lautet: "tagesschau - vor 'Zyklus der Zerstörung' im Nahen Osten - Krieg gegen die Ukraine: Ukraine meldet mehrere Tote in Kiew durch russische Aktionen." Die Uhrzeit in der oberen linken Ecke zeigt 14:03 an.

Bereitgestellt von @altbot, privat und lokal generiert mit Ovis2-8B

🌱 Energieverbrauch: 0.258 Wh






"At their heart, these technologies infringe human rights."

Last week @sianberry tabled an amendment to the UK Crime and Policing Bill that would prohibit the use and deployment of dangerous 'crime-predicting' police tech.

These systems will subject overpoliced communities to more surveillance. More discrimination. More injustice.

Sign the petition to BAN it ➡️ you.38degrees.org.uk/petitions…

#SafetyNotSurveillance #surveillance #precrime #predictivepolicing #police #policing #ukpolitics #ukpol

Cory Doctorow reshared this.

in reply to Open Rights Group

"takes no shit" -Pigsucking mayor sucking shit right from the pigpen

Lol @ that profile trying to sound tough

in reply to Open Rights Group

"Crime prediction". Didn't we already have a movie about pre-crime? Oh yes. Why don't we try some sort of prediction based on assembling, say, a profile of likely criminals. We could use physical descriptors, like...ooh...race? Hey, racial profiling, that has a ring to it...



Freut Ihr Euch auch so, dass Union, FDP, KKR-Newsletter und Sahra Wagenknecht Hunderttausende überzeugt haben, sich schnell noch eine neue Öl- oder Gasheizung einzubauen?

#Hormus #Iran #Hormuz

Questa voce è stata modificata (2 mesi fa)

reshared this



Castiñeiro en flor

non se ve na foto, pero soaba como un examio 🐝 🐝 de tantos insectos que había ao pole




Have your say and help shape the future of tourism in the EU.

We are working on a new tourism strategy and are inviting citizens, travellers, and tourism professionals to weigh in.

Share your thoughts on:
🌱 Sustainability
🌐 Digitalisation
🌈 Inclusivity
🚀 Innovation

Help us shape a tourism sector that’s fairer, greener, and more resilient – for people, places, and the planet. 🌍

Contribute to our public consultation by 12 September 2025 👉 europa.eu/!cgFnQj

in reply to European Commission

Stop those unlawful boarder controls in Germany, these are not welcoming.
Stop facism, because facism is not welcoming.
Work on integration and welcome diversity!
Fix public transport.
in reply to European Commission

In Finland, we need the more direct rail connection with Poland (and onwards) via the Baltic countries i.e. Rail Baltica. Please tell us it's going to be built without further delays: we should be able to start in Helsinki in the morning and reach e.g. Czechia in the evening (unlike on the third day with the current trains). info.railbaltica.org/en/in-bri…


Non è una foto fatta con qualche intelligenza artificiale. Bill Gates e Linus Torvalds si sono incontrati pubblicamente per la prima volta ad una cena informale dopo decenni di attività nel settore tecnologico... Mi piacerebbe sapere cosa si son detti 🤓

Qualcuno ha qualche info a riguardo?

in reply to Foffo Schenker

ammetto l'ignoranza di non conoscere i due personaggi agli estremi.

E comunque quant'è ingrassato Bill... :/







Report: Apple to announce ‘some’ App Store changes in the EU to avoid additional DMA fines
https://9to5mac.com/2025/06/23/app-store-changes-eu-dma-fines/?utm_source=flipboard&utm_medium=activitypub

Posted into All Stories @all-stories-9to5mac



Which airports are closed and where flights are cancelled amid Israel–Iran conflict?
https://flipboard.com/video/euronews/48fde0a3fe?utm_source=flipboard&utm_medium=activitypub

Posted into Travel Videos @travel-videos-euronews



Highlights from Milan Fashion Week: Dolce & Gabbana, Prada, and Armani steal the spotlight
https://flipboard.com/video/euronews/cec83c5a7a?utm_source=flipboard&utm_medium=activitypub

Posted into Culture Videos @culture-videos-euronews