Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I didn't read the whole thing, but I think the actual motivation is to prevent self-XSS which is in the first line.

http://stackoverflow.com/questions/21692646/how-does-faceboo...

Anyhow, I will just quickly dismiss this has anything to do with NSA. If I may, be an ignorant once, called this pastebin a bullshit.



Yeah I'm not sure about Netflix's motivation, but Facebook's was purely to prevent self-XSS, and you can easily opt out of it.


Correct, for Facebook.

Details: https://www.facebook.com/selfxss

Note that they have a checkbox on the above page where you agree to the downside, and the console is turned back on (and it appears to work just fine)


Wow, I can't even modify my post. Which unfair HN mod locked my post? How on earth could anyone connect this to NSA?


> I didn't read the whole thing

May I suggest you read the whole thing next time? You can certainly disagree with the author's assertion that companies and governments abuse "for your security" to do awful things (or that it's what happened here), but it's far from ridiculous. I think you just misunderstood the point about the NSA--not reading will do that to you--and it makes you look silly.


I did understand the point he was trying to make, but to me that's a poor analogy. This self-XSS prevention is a temporary solution. Facebook probably thought they had enough of people reporting dev console self-XSS so they took the initiative.

Netflix is not abusing "for your security" to do awful things. How? I just don't see it. I see that as an accusation, putting Netflix and Facebook's temporary solution in the same category as NSA's excuse is bad. I might be unfair to the author for not reading the entire post (well technically I read most of it, except Crockford and afterward I gave a quick glance), I will admit that's my failure, but that argument doesn't appeal to me at all.


The poster did not "connect this to the NSA". She/he argues that blindly acquiescing to removal of rights in the name of security is a bad idea, using the NSA phone tapping deal as a point of comparison.


But access to a dev console isn't a right - it's just a feature modern browsers happen to include.

I agree that disabling it is pointless and futile but it's hardly violating anyone's rights.


Calling it a "right" instead of a permission doesn't change much. "Digital Rights Management" doesn't manage rights under your definition (unless pause or fastforward is a right).


Yup, that is a completely legitimate argument to raise.


Comments are only editable for a limited time after you post them.


It was 2 minutes. In less than 10 seconds I was downvoted and then comment disabled.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: