5 ms·
>But why are we using web in the first place? >Because of hype and stupid sysadmins that blocked everything but HTTP protocol (Deep Packet Inspection might blo
by skeeterbug 11y ago
>But why are we using web in the first place?
>Because of hype and stupid sysadmins that blocked everything but HTTP protocol (Deep Packet Inspection might block TCP:80 because people are scared it could be an SSH server with tunneling enabled on the other side).
So we are required to install an app locally for everything and give access to our entire system? No thanks.
- js8 11y ago> So we are required to install an app locally for everything and give access to our entire system? And why not? https://xkcd.com/1200/ https://xkcd.com/1200/ The truth is, for systems with just one typical user, it doesn't matter that much whether applications have root access or not. Look at Android or iOS applications - they install locally yet can access the internet without much hassle. There is no excuse this cannot be done on the desktop, too. The only real obstacle to that is insistence of various companies to own the platform.
- tosseraccount 11y agoGood point. Microsoft, Google and Apple have little incentive to support a truly portable programming methodology.
- petra 11y ago>> is insistence of various companies to own the platform. Well , not everything in tech is 100% determined by powerful companies. For example python don't owe it's success to powerful friends. It was mostly bottoms-up. So maybe there's a strategy that could succseed in creating a better app platform , just using developer support ?
- adrusi 11y agoWeb applications get a lot less access than desktop applications do. Desktop apps get user privleges, so they can read all your files. Web apps are fully sandboxed. They can, now, access your files, but only after you click a scary banner that people are not used to seeing.
- SFjulie1 11y agoYour session in your OS is already protected by credentials (passwords, tokens). The illusion of security given by inputing and multiplying passwords might not beat having a central point of authentication handled by the OS. EDIT: and you have system accountability for free. User sessions and applications are to be already limited by the OS why redo it? And like it or not a browser is a millions sloc application that have access to everything potentially. You just trust mozilla, google, apple to not access everything. But have you audited their codebase?
- mixmastamyk 11y ago> give access to our entire system? If your OS is not a toy that should not happen.
- viraptor 11y agoDepends on your system. Linux had SELinux / AppArmor / general LSM for years. Android uses different user for each app. Windows is just starting to catch up with sandboxes in the latest version.
- kevin_thibedeau 11y agoSince this is about Tcl, there is a SafeTcl subset that was specifically designed for running untrusted code when there was hope that it might become a standard web scripting language. It eliminates all commands that can alter system resources and is a truly safe sandbox. You can still use it today by creating isolated sub-interpreters with an option to use the safe subset.
- na85 11y agoYou can turn it around easily. You mean instead of being able to download and run something natively at my convenience, I have to run it on (barf) JavaScript in the browser? I have to submit to being tracked everywhere I go online, and send my data to a central "cloud" where advertisers can profit from it freely without paying me royalties? No fucking thanks.
- wallacoloo 11y agoThat's not the point. 90%+ of the webpages I visit are essentially static documents. They can easily be treated as data, not code; even the UI description could be omitted and reasonably reconstructed from the actual page content. This webpage? It consists of a title and a link to an article, followed by a series of comment objects. Each comment contains some text, an associated author, a timestamp, and possibly a set of child comments. This exact arrangement of data can be found all across the web. If you take any blog article, it consists of this same layout, only instead of a link to the article, you have a bunch of text and/or pictures. It arguably took more work to design a product (the web browser) that can parse html, apply CSS styling, parse and execute Javascript, and tie all those pieces together with the DOM than it would have been to just have webservers pass a loosely annotated version of the page contents to the browser and let the browser decide how to render and interact with the content on its own accord. The point is, running an "app" on the web is largely BS. If you think your blog, news site, or forum is sufficiently different from the thousands of others out there that it warrants an entirely new application (as opposed to just different styling), then you're full of yourself. And if we had taken that simpler route, I wouldn't have to spend days designing a trivial blog site. Websites wouldn't all be so jarringly different (which they largely are, and unnecessarily so). I could get straight to writing my content, because browser defaults would actually be sane enough to do the dirty work for me. And the resulting UI would be more accomodating to the user than anything I could whip up with "modern" web technologies because the browser has access to the user's [language, color, contrast, font-size] preferences. Not to mention how much more accessible it would be to the visually (or otherwise) impaired.
- mchahn 11y agoYou are simply asking to go back to the web in the 90's. Time travel is not the answer. Improvements in the present time are needed to fix present problems.
- ArkyBeagle 11y agoOr you might be using the presentism fallacy. After all, we keep reinventing LISP and it is from the 1950s. "Put it in the browser" is a strange thing to do. A browser isn't really a VM for running applications; it's a document renderer. Coupling a browser with an operating system is also a strange thing to do. Yet these all occupied people's minds for a long time. Roughly only 40% of my computer use is on the Web at all. And much of that in on fora that could use a transport other than HTTP. Applications are not really documents.