Feeds

Stallman warns open-sourcers on Javascript-browser trap

Seductive charm of AJAX

Providing a secure and efficient Helpdesk

Free-software activist Richard Stallman has warned the open-source community against falling into the trap of downloading Javascript code that's not "free".

Stallman said the spread of AJAX-based web services like Google Docs means you many be running Javascript code on your machine that's not free without realizing it. He pointed to Google Docs that downloads a half-megabyte Javascript program to your machine as an example.

"Even in the free software community most users are not aware of this issue; the browsers' silence tends to conceal it," Stallman has written.

The warning echoes a similar call by Stallman in 2004 to beware of inadvertently downloading Sun Microsystems’ Java, before Java was open-sourced.

Stallman, who formulated the Gnu General Public License (GPL) and founded the Free Software Foundation (FSF), has proposed a system whereby browsers would identify "non-trivial" Javascript code that's not free and then allow the browser to run a modified version of the code instead of the original.

For Stallman, the crux of the issue is what counts as "free". Echoing his GPL, Stallman would like to see Javascript code for web services distributed with its original source code, which can then be modified by the end user.

The problem for Stallman is that while free browsers - Internet Explorer, Firefox, Opera, and Chrome - warn the user about the presence of "non-trivial" Javascript code - such as a banner ad - and can disable it, they don't alert the user to the presence of hidden Javascript in web services.

Stallman has proposed a plan of action. First is to define what's meant as a "non-trivial" Javascript program, which he thinks should be something that: "Defines methods and either loads an external script or is loaded as one, or if it makes an AJAX request."

Then, the browsers themselves need to change to let users detect such code and specify which Javascript code they'd like to run - the original or a modified form. He also recommended wording of a license for applications that authors are willing to let users modify.

"We will be able to reject and even replace the non-free, non-trivial Javascript programs, just as we reject and replace non-free packages that are offered for installation in the usual way," Stallman said.

On a related note, Stallman has challenged Adobe Systems' Flash and Microsoft's Silverlight, and suggested that the open-source Moonlight implementation of Silverlight goes against his notion of free. Stallman called Flash an "extended variant" of Javascript, although further study is needed.

Stallman criticized Silverlight for distributing non-free codecs and - by implication - the Novell-backed Moonlight, which is also licensed to use those codecs. The media codecs are closed, and have been licensed by Microsoft over the years from the media industry to play audio and video on Windows. Microsoft has extended the codec patent licensing to Moonlight.

"A free replacement for Silverlight would hardly be of use in the free world without free replacement codecs," Stallman said. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
Microsoft WINDOWS 10: Seven ATE Nine. Or Eight did really
Windows NEIN skipped, tech preview due out on Wednesday
Business is back, baby! Hasta la VISTA, Win 8... Oh, yeah, Windows 9
Forget touchscreen millennials, Microsoft goes for mouse crowd
Apple: SO sorry for the iOS 8.0.1 UPDATE BUNGLE HORROR
Apple kills 'upgrade'. Hey, Microsoft. You sure you want to be like these guys?
ARM gives Internet of Things a piece of its mind – the Cortex-M7
32-bit core packs some DSP for VIP IoT CPU LOL
Microsoft on the Threshold of a new name for Windows next week
Rebranded OS reportedly set to be flung open by Redmond
Lotus Notes inventor Ozzie invents app to talk to people on your phone
Imagine that. Startup floats with voice collab app for Win iPhone
'Google is NOT the gatekeeper to the web, as some claim'
Plus: 'Pretty sure iOS 8.0.2 will just turn the iPhone into a fax machine'
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.