93
submitted 8 months ago by nix@merv.news to c/piracy@lemmy.dbzer0.com

I've never seen any website cause a firewall permission request

you are viewing a single comment's thread
view the rest of the comments
[-] notfromhere@lemmy.one 98 points 8 months ago* (last edited 8 months ago)

Word of caution, if you have been browsing successfully until now, it could be a malicious javascript app or malware loaded from that website that is attempting to scan your network or do other things. In other words if this is a new firewall request above and beyond the standard one librewolf needs to function, proceed with cation.

[-] Slovene@feddit.nl 12 points 8 months ago

Could you also proceed with anion?

[-] PeWu@lemmy.ml 6 points 8 months ago
[-] waigl@lemmy.world 7 points 8 months ago

In theory, that shouldn't even be possible with JavaScript. There's such a thing as same-origin policy for that exact reason...

[-] Cinner@lemmy.world 8 points 8 months ago

Have you really never heard of malware from JavaScript? Buffer overflows and sandbox escapes are almost all JavaScript, still, hasn't changed in the last decade. Sometimes it's a random font parser library or something, but almost always it's JavaScript. And now that browsers are auto-updating and they have fully staffed security teams behind them that get word of a vulnerability being secretly exploited before the general public, most people don't get hit just because they browsed to a random website. But it's still possible, and especially likely that a shady torrent site could be hosting malware or get ""hacked"".

[-] notfromhere@lemmy.one 4 points 8 months ago* (last edited 8 months ago)

Malicious javascript seeks to bypass security controls. It’s one of the reasons NoScript is a thing. It could be a malware loaded from an ad. Biggest reason for adblockers imo.

Check out this link for learning about this stuff.

https://heimdalsecurity.com/blog/javascript-malware-explained/

[-] waigl@lemmy.world 7 points 8 months ago

I've read that article. It is complete garbage and doesn't explain anything at all. It's just standard cookie cutter fear mongering to sell some random antivirus software.

[-] notfromhere@lemmy.one 4 points 8 months ago

That article is for lay-persons and really an awareness article I surmise. If you’re technical you are likely already aware of the security concerns with jacascript.

[-] nix@merv.news 3 points 8 months ago

That’s what I’m thinking, it happened when i tried to load their streaming player for the first time which historically have pop unders on streaming websites

this post was submitted on 12 Dec 2023
93 points (87.2% liked)

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ

53024 readers
561 users here now

⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don't request invites, trade, sell, or self-promote

3. Don't request or link to specific pirated titles, including DMs

4. Don't submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder


💰 Please help cover server costs.

Ko-FiLiberapay


founded 1 year ago
MODERATORS