← Back to context

Comment by socalgal2

6 hours ago

This has been around since 2011 when WebGL shipped. It's documented in the spec. It's a self correcting problem. You go to a site, it freezes your machine, you never visit the site again.

No data is stolen, no privacy is lost. All that happens is the perp loses any audience.

Turning off WebGL = no more Figma, no more Canva, no more Google Maps. A few self correcting sites seem acceptable. Evidence, it's been 15 years since this was possible and the world didn't end and the whole internet isn't freezing your machine.

Also, this is arguably a MacOS bug. Window and Linux have had GPU monitors that power cycle the GPU if a command takes too long. Windows since before WebGL shipped. Linux a few years after. Macs still don't recover from excessive GPU use.

Do you think a regular user knows how to block a specific website or never click a link leading to it again? And what about the ads people, adding such a thing if you don't load their ads?

I think this point of view is making it a bit too easy.

  • Ad impressions typically cost money, so there's a case to be made that this is sort of self-correcting too.

    That being said, IMO no website should be able to freeze your machine. This is a bug. Steps should be taken to fix it.

  • As someone who supports some bottom of the barrel "regular users".. they aren't monkeys. They have brains that function enough to process "oh, I shouldn't do that again".

  • A user doesn't need to know anything other than "when I go to site XYZ.com my computer freezes. Guess I won't go there again"

    > I think this point of view is making it a bit too easy.

    It's been 15 years since this was possible. How many times have you heard of this being an issue? Again, it's self correcting. Site freezes machine, user stops going to site. There's zero incentive to do this and tons of incentive to not do it. Even an ad, your ads would get banned, not good for you, no incentive.

    • An average user will not know that the site caused the issue. The first time after force turning off the computer, it will restart and reopen all windows causing the computer to crash again. The next time, they might click on the button to prevent reopening all windows and everything will be fine until they opens safari which will cause the same issue. At that point, they'll call whoever is their computer expert user to help them out.

    • I think a lot of HN commenters are way too disconnected from the average person. You're making a big assumption that a user will even connect the dots until the same thing happens multiple times, if even then. The average computer user is extremely bad at connecting cause and effect on their computer. Think of how many times you hear "my computer is broken!" when actually it's something like the printer was unplugged/turned off and they were just having trouble printing a document (or, if you are so disconnected from average users/people, the answer is _this happens a lot_). Even what we think of as simple stuff completely befuddles them.

      1 reply →

    • > A user doesn't need to know anything other than "when I go to site XYZ.com my computer freezes.

      Not true, given any unknown link or button press can redirect/go to such a site.

> It's a self correcting problem. You go to a site, it freezes your machine, you never visit the site again.

What do regular users do about a malicious ad that runs on thousands of different sites?

> Turning off WebGL = no more Figma, no more Canva, no more Google Maps

Which is why you should probably rather turn off the actual vulnerable API, i.e. WebGPU, not WebGL.

  • It really ought to be something you can enable or disable per site. I was surprised to find its not.

  • I just don’t think people are doing malicious ads like that. Like I’m sure it exists but like what’s the point? If you are the malicious person you pay money for ads to freeze someone’s computer and that’s it? It’s not even like you would gain anything from it