Register ICMag Forum Menu Features
You are viewing our:
in:
Forums > IC Magazine > Website Support > ICMag, SB and Javascript

Thread Title Search
Click to Visit Mars Hydro for Growroom Lights and Tents
Post Reply
ICMag, SB and Javascript Thread Tools
Old 10-16-2006, 09:15 PM #1
TheGreenMachine
Member

TheGreenMachine's Avatar

Join Date: Oct 2006
Posts: 59
TheGreenMachine is on a distinguished road
ICMag, SB and Javascript

I searched but could not find anything on this.

As much as everyone speaks about security and anonimity here, I am somewhat shocked that no one has posted about the use of Javascript within these sites and how it can circumvent the security posters have taken. Javascript can make calls that bypass proxy services and reveal your true IP. I realize that the operators here have made it known that all IPs are stored only momenterily during login, but what about SB? I ask, because in order to change currencies you have to have Javascript enabled. I see that alone as an overlooked security flaw for the aforementioned reason. I have not attempted to order online, but what about the order process and what happens to sensitive data once the transaction is complete and the session terminated?
TheGreenMachine is offline Quote


Old 10-21-2006, 07:11 PM #2
TheGreenMachine
Member

TheGreenMachine's Avatar

Join Date: Oct 2006
Posts: 59
TheGreenMachine is on a distinguished road
Wow. I figured this would have a response already.

Perhaps I should re-post this in the Security forum?
TheGreenMachine is offline Quote


Old 10-21-2006, 10:38 PM #3
oldpink
Retired

oldpink's Avatar

Join Date: Apr 2004
Location: sowing the seeds of love
Posts: 5,952
oldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant future
perhaps you should check your facts
__________________
Fly On My Sweet Angel
Williamina Queen, 26.5.43 - 22.3.06

shine on 11/07/06

"Like Rick, I don't find it easy to express my feelings in words, but I loved him and will miss him enormously".David Gilmour Monday 15th September 2008

Gypsy is finally Free
oldpink is offline Quote


Old 10-21-2006, 11:28 PM #4
Guest
Guest

Posts: n/a
Quote


Old 10-22-2006, 02:14 AM #5
TheGreenMachine
Member

TheGreenMachine's Avatar

Join Date: Oct 2006
Posts: 59
TheGreenMachine is on a distinguished road
Quote:
Originally Posted by oldpink
perhaps you should check your facts
Care to enlighten me then? If it isn't an issue, then tell me why.

I use TOR and have read specifically that Javascript calls can return your real IP address.

Last edited by TheGreenMachine; 10-22-2006 at 02:15 AM..
TheGreenMachine is offline Quote


Old 10-23-2006, 03:53 PM #6
ballast
i has a soldering iron

ballast's Avatar

Join Date: Jun 2006
Location: mars
Posts: 76
ballast is on a distinguished road
Java can do what you are describing, but Javascript on a trustworthy site is little to worry about. the Tor docs cover this concern. if you are using Firefox you might want to get the NoScript extension, very handy for whitelisting which sites to allow javascript on. hope it helps.
__________________
LED is the lighting future
ballast is offline Quote


Old 10-23-2006, 06:58 PM #7
TheGreenMachine
Member

TheGreenMachine's Avatar

Join Date: Oct 2006
Posts: 59
TheGreenMachine is on a distinguished road
Quote:
Originally Posted by ballast
Java can do what you are describing, but Javascript on a trustworthy site is little to worry about. the Tor docs cover this concern. if you are using Firefox you might want to get the NoScript extension, very handy for whitelisting which sites to allow javascript on. hope it helps.
I do use NoScript as FF is the only browser I would use to hit "questionable" sites. However, as I stated, this site and SeedBoo require JS for certain functions (like accessing user settings, or changing currencies).

After what happened with OG (I was away when it all went down), I am more cautious than ever. TOR has proven to solve half the issue, JS was the other. You have at least laid my concerns with these two particular sites to rest as I have heard pretty much nothing but good over the years about GN and the way he runs his business. I am assuming Sbay is kosher as well?

Thanks, ballast.
TheGreenMachine is offline Quote


Old 10-24-2006, 11:28 AM #8
ballast
i has a soldering iron

ballast's Avatar

Join Date: Jun 2006
Location: mars
Posts: 76
ballast is on a distinguished road
yeah TheGreenMachine, Sbay excellent too from all i've heard. had the same sorts of questions when i registered here, after a while you learn whats what. check the security forum, lotsa good stuff in there.

the thing about javascript is the source code is viewable in the browser, so if there were anything funny going on here we'd hear about it.

grow safe
__________________
LED is the lighting future

Last edited by ballast; 10-24-2006 at 11:34 AM..
ballast is offline Quote


Old 10-25-2006, 12:55 AM #9
oldpink
Retired

oldpink's Avatar

Join Date: Apr 2004
Location: sowing the seeds of love
Posts: 5,952
oldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant futureoldpink has a brilliant future
Quote:
the thing about javascript is the source code is viewable in the browser, so if there were anything funny going on here we'd hear about it
also it depends on what settings you have in your browser or what browser you use
personally I always recomend firefox if your worried, set to max security
__________________
Fly On My Sweet Angel
Williamina Queen, 26.5.43 - 22.3.06

shine on 11/07/06

"Like Rick, I don't find it easy to express my feelings in words, but I loved him and will miss him enormously".David Gilmour Monday 15th September 2008

Gypsy is finally Free
oldpink is offline Quote


Old 10-28-2006, 01:31 PM #10
ballast
i has a soldering iron

ballast's Avatar

Join Date: Jun 2006
Location: mars
Posts: 76
ballast is on a distinguished road
Quote:
Originally Posted by oldpink
also it depends on what settings you have in your browser or what browser you use
personally I always recomend firefox if your worried, set to max security
Open-source Firefox all the way man, no telling what secret backdoors the proprietary browsers might have nowdays. switching from IE was quite painless.
__________________
LED is the lighting future
ballast is offline Quote


Post Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT +2. The time now is 01:40 PM.


Click to visit Twilight Labs


This site is for educational and entertainment purposes only.
You must be of legal age to view ICmag and participate here.
All postings are the responsibility of their authors.
Powered by: vBulletin Copyright ©2000 - 2018, Jelsoft Enterprises Ltd.