4 ms·
While I rarely looked at the code behind a browser (mostly webkit, to debug some weird stuff with capybara-webkit), it is highly uncomfortable to me to use a no
by timonovici 9y ago
While I rarely looked at the code behind a browser (mostly webkit, to debug some weird stuff with capybara-webkit), it is highly uncomfortable to me to use a non-free browser... Does it track my behavior, do they sell that information - I don't have time to mess around with Wireshark and see what it does;
On the "history" upgrade idea - that's a really cool one; It's quite often that I'm looking for that page I accessed last year, or that youtube video somebody sent me a few months ago, and I forgot it's name - hopefully chromium/firefox steal this idea and improve upon it;
- JoshTriplett 9y agoAgreed. This is an interesting approach, and I look forward to seeing something like it in a browser I can trust.
- z3t4 9y agoThere's a middle ground between FOSS and closed source, like having the source code open, and let power users compile it themselves, while keeping the copy-rights. Most code on the web works like this, as you can just right click and "view source", and easily debug and inspect. Does anyone have any experience with open sourcing, but with a restrictive (all rights reserved) license ? And would this be enough for people like the parent poster to run such a software ?
- pasta 9y agoYour argument about the closed source is weak. Messing around with Wireshark is probably quicker than reading thousands of locs. I understand the value of open source. But I'm still not sure if it matters. A lot of people think that open source software does not track personal data. But how do they know? Have they read all the code? Do they even understand all code? It's much easier to run Wireshark to check what the program does. That's how the world found out about what Windows 10 is sending to MS. In the end it's about trust.
- vanviegen 9y agoI don't believe wireshark will tell you that much since everything is encrypted with forward secrecy nowadays. So the browser would need to be able to output negotiated keys for data tracking connections. That seems unlikely, especially if what's being tracked is a bit shady.
- Sylos 9y agoOpen-source doesn't just mean that you can view the source code. It also means that anyone can take the source code, make changes to it and distribute their new version. This means that if an open-source project does nefarious things, there's a good chance that a fork will come along and that people will start using that fork instead. So, you yourself don't have to read every single line of code for it to be relatively certain that an open-source project does not do bad things. There are of course exceptions to this. For example there are a lot of things that a lot of people are not fond of with Chromium. There are forks which try to address this (for example [0]), but Google has so much development workforce behind Chromium that such a fork has a hard time keeping up with merging security patches and updates in general. But even in that case, open-source offers protection without you reading every line of code. Because there's people out there who earn their daily bread by uncovering these sort of things: Journalists. Due to the source code being available, they have definitive proof and can slap these kind of stories on the front page. I mean, heck, Heart Bleed came on national TV in my country. If that vulnerability had been in closed-source software, they could have only ever reported about rumors. [0]: https://github.com/Eloston/ungoogled-chromium https://github.com/Eloston/ungoogled-chromium
- JustSomeNobody 9y agoI think the difference is that with open source there's a chance that one could find out about tracking, fix it, then continue to use the product. With a closed source solution, this is almost impossible.
- dzek69 9y agoVivaldi is Open Source, they just doesn't have github repo and they aren't "crowd-based open source" (I don't know how to call it). https://vivaldi.com/source https://vivaldi.com/source
- Sylos 9y agoOpen-source means more than just allowing others to view the source code: https://opensource.org/osd https://opensource.org/osd Besides that, as far as I remember that link only discloses their changes to Chromium, not everything that's part of Vivaldi. From what I've heard, the rest can apparently be extracted from the Vivaldi binary, but I have yet to see a demonstration of someone actually compiling Vivaldi from that.
- bruce_one 9y agoThis repo implies the Vivaldi source can be compiled: https://github.com/ograycode/vivaldi-source https://github.com/ograycode/vivaldi-source