4 ms·
Browsers are supposed to browse that's all. More and more stuff like this will come up with HTML5/JavaScript and people will begin to wonder why the world is ju
by jebblue 11y ago
Browsers are supposed to browse that's all. More and more stuff like this will come up with HTML5/JavaScript and people will begin to wonder why the world is jumping through all the JavaScript hoops to build a web app that is essentially a rich client app when they could use tools that are designed for that. Are they more or less secure, neither, once you can touch the user's filesystem the risk is the same which is why it still baffles me that developers actually want to code in JavaScript and dozens of one off libs when they could use first class tools which are far better designed. Browsers are supposed to browse, that is all they are supposed to do.
- thisjustinm 11y agoHow do you define browse? To me browsing would include all the JS stuff we have now plus all kinds of things we haven't dreamed up yet. Call me old fashioned but I'm all for continuing to move the web forward. There will be vulnerabilities in native apps, there will be vulnerabilities in web apps or, put more simply, there will be vulnerabilities. Patch 'em up and charge ahead.
- syncsynchalt 11y agoThe only viable rich client app frameworks I'm thinking of that are sandboxed are Flash, Java applets, and the OS X app store. The first two are at different stages of being universally disabled for security reasons, and the latter hasn't taken off and is not portable like the first two. Mobile is a different story of course, but also not portable. In short I'm not sure what you're suggesting.
- halosghost 11y agoOnce upon a time, the Internet was supposed to just be a network of interconnected hypertext documents. But as soon as we decided that the Web should be a platform[1], and Netscape Navigator packaged JS, we started down a road where it's quite hard to return. I know it's an unpopular opinion, but I actually miss the days where webpages were static and did not need JS to load basic functionality. With the rise of the IoT, security is only going to be more and more difficult (e.g., all the automanufacturers' issues as of late); here's hoping we can figure out a way to make security mainstream… [1]: https://www.youtube.com/watch?v=r38al1w-h4k https://www.youtube.com/watch?v=r38al1w-h4k
- andrepd 11y agoWhat is browsing, then? Read-only? Are forums browsing, or interactive apps? Where do you draw the line? I'm all for less bloat, and I can't figure why would a browser double as a PDF reader, for instance, when a native app is invariably faster, more feature-rich, more customisable and more secure. However, it's difficult to draw a concrete line between plain browsing and web apps.
- TazeTSchnitzel 11y ago> I can't figure why would a browser double as a PDF reader, for instance, when a native app is invariably faster, more feature-rich, more customisable and more secure. A native app is less secure. They're all written in memory-unsafe languages, are not guaranteed to be up-to-date, and do not run sandboxed. Integrating a JS PDF viewer into the browser hurts performance, but it's more convenient (no separate app to open, can start reading before it finishes downloading), and much less likely to be a security risk.
- jebblue 11y ago>> A native app is less secure. They're all written in memory-unsafe languages, are not guaranteed to be up-to-date, and do not run sandboxed. So how can we even trust the browser if native apps are always less secure according to you? The exploit ran despite the sandbox if I understood it right.
- pcwalton 11y agoI don't understand the reasoning here at all. Are you arguing that because sandboxes sometimes have holes in them that they aren't worthwhile?
- pachydermic 11y ago> Browsers are supposed to browse, that is all they are supposed to do. Try telling that to people who want them to do more. No one wants to download and install your desktop app - it's too much work and people are too concerned about security. Mobile app stores are much better at minimizing that friction which is why native applications are so popular on that platform... but there's still friction. The web is awesome because it's so easily accessible. And people want to do sophisticated things easily - they don't want to mess with downloading and installing stuff. The fact that the web started off a certain way and browsers are called "browsers" has literally zero impact on what people demand from their technology. What they want now is for their browsers to solve problems. So that's what people make.
- hiou 11y agoUgh here we go again... no idea what the constant complaining about adding features and functionality to web browsers or the web in general really accomplishes at this point. The ship sailed more than 5 years ago. The likelihood of browsers returning to light html document readers is exactly zero. Time to move on to more productive complaints.
- JoBrad 11y agoSo I shouldn't be upvoting your comment?
- jebblue 11y agoIt was more a nostalgic sentiment I expressed, your point is valid though on a much smaller scale than a full PDF reader.