Oh ActiveX was definitely worse, I should know since I was using the internet plenty when it was prominent. My point is, though, that malicious actors still basically control the web. They may not be executing native code without any controls, but that doesn't mean that the modern web isn't still their playground.
It’s not as bad currently, but 10 years ago it wasn’t that unusual to find things like government and bank websites using freaking ActiveX.
These days I would imagine it means things like not publishing videos with (only) proprietary codecs, or using some sort of non-standard non-open 2fa or something.
reply