[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Gorhill on suicide watch

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 52
Thread images: 3

Javascript execution exploit even with everything blocked! https://github.com/gorhill/uMatrix/issues/775


Gorshill and his army of cucks flooded this board with "uninstall NoScript, these extensions developed by a shady hobbyist are enough" threads here non-stop for the last two years. Now it's judgment day for the sheep who listened to them.


Giorgio Maone has your back and will welcome you with open arms: https://addons.mozilla.org/firefox/addon/noscript/
>>
PoC won't load for me so looks like the creator of it ended up getting rekt himself
>>
>>60314984
It's fucking nothing but somehow /g/tards here will manage to fuck something up with it.
>>
>>60314984
>Giorgio Maone has your back and will welcome you with open arms: https://addons.mozilla.org/firefox/addon/noscript/

Does this mean I have to use Firefox again? I switched to Chromium because Firefox was terribly laggy on my PC and froze at some of the simplest things that Chromium easily slides through with no problem.

No thanks.
>>
>>60314984
If you read your own link you would realize that NoScript doesn't block it either.
>>
>>60315705
Firefox has got better with 53, noticeably smooth. Regardless, anything is better than google's dick in your ass.
>>
>>60315705
>>60315774
It's always been possible to make firefox not suck, it just takes some work in the configs because it comes 100% shitty performance enabled
>>
>>60315705
>>60315801
what are you talking about?
I've never had any kind of problem with firefox performance
>>
>>60315874
its entirely based on them blocking when writing to disk, which is constant. Firefox is the SSD murderer.
>>
>>60315874
>works on my machine, so everyone who has a different experience must be lying :^)
>>
>>60315898
I'm just curious
>>
>>60315874
Firefox often uses up more than 25% CPU on my machine and then freezes for nearly an entire minute. Sometimes this is through playing videos or javascript-heavy pages.

Firefox is only limited to one core and all tabs share the same process, so it will freeze the entire browser.
>>
>>60315934
Well they don't have to be limited to single process anymore, but javascript is unrelated to the browser's performance issues. Their javascript engine is the fastest.
>>
>>60315705
> Does this mean I have to use Firefox again?

Chrome 60 prevents navigating from a http(s):// context to a data: context, meaning it is not susceptible to this bypass by design. Firefox apparantly fares much worse, because it will happily both fetch and execute the data uri for you.

If this exploit has you worried; rather than start using Firefox, you should update to Chrome 60+.
>>
>>60315894
>its entirely based on them blocking when writing to disk, which is constant. Firefox is the SSD murderer.
Firefox never killed an ssd, stop spreading FUD.
>>
>>60314984
https://github.com/gorhill/uMatrix/issues/775#issuecomment-298238995
>>
>>60316216
Firefox does implement some awful criminally horrible things. Writing to disk negligently is one of them but it's easily fixed with configs. Plebs can get their disks wrecked though for real.
>>
>https://github.com/gorhill/uMatrix/issues/775

Can (((YOU))) even read?

>uninstall NoScript, these extensions developed by a shady hobbyist are enough

None told so anywhere on the wiki

>https://addons.mozilla.org/firefox/addon/noscript/

I use both, (((YOU))) gay sack of jewish shilling shit
>>
>>60317241
Disks are made to be written to dumbfag
>>
>>60317300

you can browse with RAM if you aren't a gullible goy

JEWgle tracks your cache
>>
>>60317300
Software shouldn't be designed to write to disk constantly because it's fucking slow. Mostly relating to its crash recovery, which in my experiences firefox crashes are super fucking rare but firefox fucking up due to writes are fucking constant. Clear solution, fix the bullshit.
>>
>>60317440
In my experience firefox does not write to disk any more than any other browser and I'm not inconvenienced by the crash recovery thing.
>>
>>60317300
yes, can't wait to blow through my ssd, thanks modern browsers!>>60317300
>>
>>60314984
>NoScript 5.0.3 will also not block the data: URI on Nightly.
So?
>>
>>60317241
chrome does the same and cant be turned off in configs
>>
>>60317530
well the default write timer is like 5-15 seconds and it's awful. I don't know about other browsers but awful is awful, especially when all the network/disk/etc stuff is on the same main process and blocks hard. Massive performance hit.
>>
>>60317646
You can disable disk caching on chrome as well, it's not in flags though, but in launch parameters.
>>
File: 1448129747465.jpg (185KB, 800x569px) Image search: [Google]
1448129747465.jpg
185KB, 800x569px
>look up forum thread about browsers killing SSDs
>nothing but "but it werks fer me :^)" replies
>>
>>60315801
No it's not. Firecucks is just fucking garbage. Keep thinking your magical about configs tweaks do shit. Protip: they don't
You only realize how shit firecucks is once you switch to browser that is not shit.
>>
>>60317719
I've spent a lot of time configuring shit over the years, there is none more performance that can exist. Network time is the only noticable performance issue.
>>
>>60317707
>>60317608
>>60317241
>>60315894

STFU and learn 2 wear-leveling. Every SSD can sustain a fuckton of writes because they evenly distribute the writes across the cells and they also typically have "backup" cells that are set aside to be used when those cells wear out. SSDs aren't going to die because firefox or chrome are writing like 10s of GB a day, even after a year of that they'll still have 100s if not 1000s of TBs left in their lifetime

http://www.zdnet.com/article/worried-about-ssd-wear-you-probably-dont-need-to-be/
>>
>>60317772
Yeah, but 10s of GBs a day of writes are awful and slow anyway.
>>
>>60317772
>1000s
is that why only 75 TB is covered by warranty?
>>
>>60317772

ok but you're still a fag
>>
>>60317802
The manufacturers probably make assumptions based on how much data the average person writes daily and only cover that much X <magic number> but the actual disk can be capable of quite a lot more apparently.
>>
>>60317772
>>60317898
And sometimes there's defects that use up a bunch of the backup cells without writes, too. Not some sort of magic solution, SSDs are great for reads and mediocre for writes.
>>
>>60315774
tfw i'm still running ff 48
should i switch anons?
>>
>>60317748
How much time did you spend on using browsers other than firefox?
>>
>>60317241
>Writing to disk negligently
It's all caching, at least on Linux. This is completely normal behavior. The problem is that any given site has 40 different thumbnails and banners that need to be downloaded, and are cached if caching is enabled. Plus if you enable session restore, your active tabs have to be periodically cached as well.
>>
>>60318403
I've used them all, instant is instant whatever you're on.
>>60318443
If the period is shorter than the write time maybe, if firefox just let linux do the fsyncing on its own damn time it would be less harmful. Ramdisking the profile makes everything great though.
>>
Simply displaying javascript in text format was enough to trigger it you retard
>>
fuck off giorgio, you're a cunt.
>>
>>60318443
Damn, I've not used disk caching for years and notice nothing (setting private browsing enabled all the time disables that cache, I figure they will make it default in a year or so).

Ramdisk is good too, sandbox with its location set to a ramdisk is great.
>>
>>60318374
There was an exploit maybe half a year ago that affected all firefox versions up to like 50ish, though if I remember right it required javascript to work, so if you block javascript on suspicious sites you're probably good.
>>
>noscript
>working with webext
Next time you are gonna tell me to use pale meme.
>>
>>60314984
>links to issue
>Its severity is minimal
>only on chrome due to the limitation of chrome's API, NoScript can't do shit about it
Are you retarded?
>>
>>60315705
anon i have bad news 4u
i use firefox on a pentium III and it works fine
>>
>>60316017
only the UI is separated to a new thread now, does not mean the content engine will process on multiple threads tho.
>>
>>60317241
>>60318443
I am saddened by the fact I cannot have a large cache in FF.
>>
File: re-023.jpg (6KB, 136x211px) Image search: [Google]
re-023.jpg
6KB, 136x211px
>>60324266
Did the dev give up trying to convert it? I thought he was optimistic about webext.
>>
>>60314984
>As expected, it does not work with uMatrix with default settings of default-deny all active 3rd-party content, because no external resource can be 1st-party to a data: URI:
At least read your own fucking links.
>>
>Install UO
>Update the ad block lists
>Site no longer works
Thread posts: 52
Thread images: 3


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.