Comment on The new Chinese owner of the popular Polyfill JS project injects malware into more than 100 thousand sites

<- View Parent
9point6@lemmy.world ⁨3⁩ ⁨months⁩ ago

Not a solution. Much of the modern web is reliant on JavaScript to function.

Noscript made sense when the web was pages with superfluous scripts that enhanced what was already there.

Much of the modern web is web apps that fundamentally break without JS. And picking and choosing unfortunately won’t generally protect from this because it’s common practice to use a bundler such as webpack to keep your page weight down. This will have been pulled in as a dependency in many projects and the site either works or does not based on the presence of the bundle.

Not saying this is a great situation or anything, but suggesting noscript as a solution is increasingly anachronistic.

source
Sort:hotnewtop