• 1 Post
  • 10 Comments
Joined 3 years ago
cake
Cake day: April 1st, 2022

help-circle
  • It was released (read: forcibly shoved down our throats) by Google and came out of nowhere when there were zero problems with the decades old and extremely well researched incumbent image/video formats that the web was already using (i.e. jpg, png, gif, mp4, etc)

    I don’t agree with this. There are many things wrong with those file formats. GIF, for example, is over 35 years old and has a 256 color pallete. Now, if it’s good enough for your purposes and it “ain’t broke” for that, fine, but compare these formats to JPEG-XL and it’s clear that they deserve to be surpassed. WebM/WebP, despite my many issues with it (WebP and AVIF are bullshit formats), they did serve a legitimate purpose, and quite frankly you can even say it was good for the environment due to lowering filesizes at an actually meaningful scale.

    In fact, if I’m reading Mitre correctly, there are libjpeg vulns still being found since WebP was launched. I’m not saying this to equivocate the two from a security standpoint, hell no, but to critisize the common view I see online claiming the older formats are unbackable.







  • Thanks for the detailed reply :)

    I agree with all your points, it is misleading and potentially harmful to use a strong term like spyware to refer to all of those things, without further context. I guess I’m still used to a couple of tech circles where people would jokingly throw ‘spyware’ around to describe anything and everything, so I didn’t realize how misleading it really is. Especially when it’s applied to things like automatic updates, which only the most extreme security models consider more of a risk than a security feature.




  • That website is […] full of verifiably false information

    Could you please provide and example or two? I wish to verify it, since I didn’t notice any last time I checked the site.

    they act as if any and all [unprompted] connections a browser makes are automatically bad and “spying”.

    They’re very clear that this is their approach (bold text on the home page). Even if you disagree with their definition, that doesn’t make the site bad. And there are many valid situations where a threat model should be this strict, consider anti-government activists in any country.

    They even claim that Tor Browser is a “spyware”.

    It says “Not Spyware”. https://spyware.neocities.org/articles/tor