User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt Embeds FTW
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1w
@tael @matt Heck no! If a link dies I can check archive.org. If an imbed dies I can’t. And if the website I imbedded from becomes malicious, Now all my readers were exposed to it. My personal rule is that my blog should never ask the browser to load a resource I don’t directly control.
1
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt Then you are not solving the problem discussed in the OP; having to click a link and load a page is not the same as attaching a screenshot. An embed is hypertext and can be cached (see: Discord embeds, where I have rescued many posts and images after they were deleted) and archived. Attaching a screenshot is just a lossy way of embedding the web page.
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1w
@tael @matt Yes, but readers should click through to read someone else’s content. Copying it on to your own website is just theft, and autoloading it is a security incident waiting to happen, and a privacy violation. There’s a reason email clients don’t display images by default anymore.
1
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt Embedding is not theft, it is provided by the source website, lol
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1w
@tael @matt Until the source website ads malicious JavaScript to the imbed.
1
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt Embeds don't have source JavaScript. They are defined by meta head attributes. You may be thinking of iframes.
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1w
@tael @matt But they’ll load whatever the page your imbedding has, including JavaScript won’t they?
1
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt No. "Embedding a link" usually means loading a preview of the embedded page as a card based on the OpenGraph meta tags. I'm not sure how Mastodon does post embeds but OpenGraph was made for allowing posts to display without needing to be screenshot. These links should get embedded when you load the post for example:
myog.social/articles/og-meta-tags-guide
ogp.me
1
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt And here is an example (screenshot) of a Mastodon post embedded in Discord:
2
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt The same post looks like this embedded in Mastodon: plush.city/@mynameistillian/117095421988861864
2
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt (But Mastodon counts embedded posts as quotes.) As you can see, alt text is lost in the Discord embed, which isn't great, but preserved in the Mastodon embed. This is better than a screenshot of tillian's post, which would never have any alt text, and a plain link, which would require me to click through to look at the post.
2
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1w
@tael @matt Clicking through is a far better solution. Browsers shouldn’t even agree to load resources from anything other than your current domain without you having to click.
1
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt Clicking through is not a solution to screenshots of web pages, the expectation is that the content is displayed on the page

I think you have some outmoded beliefs about browser security but I respect them. I assume you have noscript set up to block JavaScript from any cross-site resources as well?
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1w
@tael @matt I certainly do.
1
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt Then I imagine a lot of websites just straight-up don't work for you. More power to you but I wouldn't expect more than a small group of people to willingly use the web that way.
2
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1w
@tael @matt You can also host a lot of the popular js libraries locally and repoint the cdns like jsdeliver with local dns. Getting to 99 percent actual functionality is much easier that way than managing an endless stream of dns blocklists.
1
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt I do do that! But it's not really how the web is built anymore. And even if you block external JS, most websites are probably made with React now and importing tons of packages from the Node Package Manager, introducing actually serious security vulnerabilities that you have no control over at all. Backend JavaScript, baby. ;)
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1w
@tael @matt I mean “don’t visit websites you don’t trust” still has to be part of security.
1
0
0
0
User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt By your standards, isn't that almost all of them barring the ones you made yourself?
1
0
0
0
User avatar
🇨🇦Samuel Proulx🇨🇦 @fastfinge@interfree.ca
1w
@tael @matt Theoretically yes. But practically no.
1
0
0
0

User avatar
Tael 🔜 AC26 @tael@yiff.life
1w
@fastfinge @matt How do you even know if a website is pulling potentially malicious, hijackable code from a package manager?
0
0
0
0