93
submitted 1 year ago by nix@merv.news to c/piracy@lemmy.dbzer0.com

I've never seen any website cause a firewall permission request

you are viewing a single comment's thread
view the rest of the comments
[-] notfromhere@lemmy.one 98 points 1 year ago* (last edited 1 year ago)

Word of caution, if you have been browsing successfully until now, it could be a malicious javascript app or malware loaded from that website that is attempting to scan your network or do other things. In other words if this is a new firewall request above and beyond the standard one librewolf needs to function, proceed with cation.

[-] Slovene@feddit.nl 12 points 1 year ago

Could you also proceed with anion?

[-] PeWu@lemmy.ml 6 points 1 year ago
[-] waigl@lemmy.world 7 points 1 year ago

In theory, that shouldn't even be possible with JavaScript. There's such a thing as same-origin policy for that exact reason...

[-] Cinner@lemmy.world 8 points 1 year ago

Have you really never heard of malware from JavaScript? Buffer overflows and sandbox escapes are almost all JavaScript, still, hasn't changed in the last decade. Sometimes it's a random font parser library or something, but almost always it's JavaScript. And now that browsers are auto-updating and they have fully staffed security teams behind them that get word of a vulnerability being secretly exploited before the general public, most people don't get hit just because they browsed to a random website. But it's still possible, and especially likely that a shady torrent site could be hosting malware or get ""hacked"".

[-] notfromhere@lemmy.one 4 points 1 year ago* (last edited 1 year ago)

Malicious javascript seeks to bypass security controls. It’s one of the reasons NoScript is a thing. It could be a malware loaded from an ad. Biggest reason for adblockers imo.

Check out this link for learning about this stuff.

https://heimdalsecurity.com/blog/javascript-malware-explained/

[-] waigl@lemmy.world 7 points 1 year ago

I've read that article. It is complete garbage and doesn't explain anything at all. It's just standard cookie cutter fear mongering to sell some random antivirus software.

[-] notfromhere@lemmy.one 4 points 1 year ago

That article is for lay-persons and really an awareness article I surmise. If you’re technical you are likely already aware of the security concerns with jacascript.

[-] nix@merv.news 3 points 1 year ago

That’s what I’m thinking, it happened when i tried to load their streaming player for the first time which historically have pop unders on streaming websites

this post was submitted on 12 Dec 2023
93 points (87.2% liked)

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ

60994 readers
765 users here now

⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don't request invites, trade, sell, or self-promote

3. Don't request or link to specific pirated titles, including DMs

4. Don't submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder

📜 c/Piracy Wiki (Community Edition):

🏴‍☠️ Other communities

FUCK ADOBE!

Torrenting/P2P:

Gaming:


💰 Please help cover server costs.

Ko-Fi Liberapay
Ko-fi Liberapay

founded 2 years ago
MODERATORS