9 ms·
Can't wait for DOM interop and get away from JS on frontend. Seriously JS should not be the lingua franca of the web :)
by holydude 9y ago
Can't wait for DOM interop and get away from JS on frontend.
Seriously JS should not be the lingua franca of the web :)
- phkahler 9y ago>> Seriously JS should not be the lingua franca of the web But neither should this. Really, keep your code off my computer as much as possible.
- jazoom 9y agoBut what is a computer for if not running other people's code? I can't imagine there are many people in this world who have a computer with more than even 1% their own code running on it.
- phkahler 9y agoRed herring. People install or explicitly download code they want to run. The general public doesn't even realize that most web pages are full of code (js not html) and most developers have gotten so used to it they feel entitled. The goal should be to try harder to use less code, not enable native execution. I understand, engineers like to think about what is possible (wouldn't it be cool if..!) but sometime they need to check their ego and consider context.
- jazoom 9y ago99%+ of people don't think like you and don't care about the distinction between code on the browser and code on the OS. "A red herring is something that misleads or distracts from a relevant or important issue. It may be either a logical fallacy or a literary device that leads readers or audiences towards a false conclusion." I don't see how my comment is a red herring. Computers are for running code. That's what they do. You said you don't want other people's code running on your computer. Bad news for you, that's all your computer does.
- scaryclam 9y agoComputers are for running code as much as cars are for consuming fuel. They both need them to function in the manner that we currently use them, but that's not what they are for. Both computers and cars exist to perform tasks that enable humans to do other things. It's possible to have a useful car that does not consume fuel and it's possible to have a useful computer that runs no code (hint: hardware's not just for mounting those pretty lights in your computer case).
- notheguyouthink 9y agoI definitely don't disagree with your statements, but I think OP meant more akin to "the web is not for running other peoples code". Ie, the web is for content, not applications. This may not be what OP meant.. but it's something I can agree with to a degree. I love web apps, don't get me wrong, but I wish we had meaningful fallbacks for those who want content without features.
- goatlover 9y ago> Ie, the web is for content, not applications. Ideally yes, but that horse left the barn years ago. The browser becomes more capable, chalk full of more APIs over time, not less.
- z3t4 9y agoThe more capable the browser gets the more people will turn off these capabilities. I love JS and the web, yet I have JS off by default! Mostly because it gets rid of a lot of crap, but I also don't trust every single web site I visit.
- hdhzy 9y agoIs this relevant what the people are aware of? If you drive a car do you need to be aware of its internals? WebAssembly looks like a safe, portable, intermediate bytecode. What's wrong with giving people more options (e.g. running native applications in their browsers)?
- adventured 9y ago> If you drive a car do you need to be aware of its internals? You walked yourself into an obvious answer there: yes, to a limited extent you do. That includes understanding a bare minimum about tires, the engine (what noises are normal, what noises aren't normal), oil changing (why, when), windshield washer fluid, basic indications of electric problems, basics about the need to change brakes (indications of brakes going bad, why they need changed), the basics of the parking brake (and not to drive with it engaged and why), the usefulness of different types of tires (for example snow tires), why you shouldn't needlessly over-rev an engine frequently (or do stupid things like over-rev it for an hour while parked), how turn signals work and the need to make sure the lights on your vehicle are functioning, how high beams work (or at least how to use them), how gear shifting works and why it's important not to thrash your transmission (what abnormal shifting sounds like, why that matters), this list keeps going and I've really only covered primitive things that most or all drivers should know within the first year or so of driving.
- zaarn 9y agoMost drivers don't concern themselves with the alloy composition of their catalysator or the exact air-to-fuel ratio in their cylinder headers or the necessary pressure in the breakheads during an emergency halt. Or the composition of the road below them in exact ratios of chemical components.
- hdhzy 9y agoContinuing the comparison that means people need to understand not to cold power off the computer, not the specifics of CSS, JS and HTML. Note that cars are also going to be more and more abstracted away with automatic gear shifting (now I don't need to understand how gear shifting works). Do people really need to understand how CPU work to do their banking?
- tomxor 9y ago> People install or explicitly download code they want to run Not really, explicit installation are not the real difference: you ask for one package in some package manager and you will commonly implicitly get a bunch of other dependencies installed, you will likely never be able to feasibly personally audit all those implicitly installed packages if we are talking about e.g OS repositories... The real differences are: 1. Trust of the authority that maintains a collection of repositories. 2. Execution permissions. i.e The package manager for your OS can install code that can run with root privileges if it wants, but you have trust in the authority that maintains the package lists. With the web there isn't any curation of package lists, but the code is sandboxed.
- wang_li 9y agoThe last time that a package I installed proceeded to install code that the vendor didn't know about was never. The last time a web page caused my browser to download and run js that the page owner didn't know about was five minutes ago.
- seangrogg 9y agoSo every package author understands each of their dependencies and all of their respective sub-dependencies, recursively on down? This is probably the best bit of programming humor I've read all morning.
- wang_li 9y ago>So every package author understands each of their dependencies and all of their respective sub-dependencies, recursively on down? Have they personally audited every dependency? Probably not. Is the list of dependencies known? Yes. Is the list fixed? Yes. On the webpage side: Does the content provider know what will be served by their ad network? No. Does the ad network provided content change? Yes, constantly. Does the content provider even know who ultimately will be putting crap on their web page via the ads? No.
- 9y ago
- bengillies 9y ago> The goal should be to try harder to use less code The goal is to deliver content and experiences that people actually want, it has nothing to do with the amount of code at all. At best, using less code might be a performance optimisation (though not always).
- tzahola 9y ago>The goal is to deliver content and experiences that people actually want Wrong. 99% of the time the goal is to sell ads. The tricky stuff is to bundle it with something that people actually want (or think they want).
- bengillies 9y agoSo we're both agreed then that the goal isn't to "use less code"? I get your point though, so I'll rephrase: > The goal should be to try harder to use less code Why is this the goal? At best it's a performance optimisation that some (probably most) sites could use to speed up time to render. But at the same time, there are many other sites where this doesn't make sense or for which the purpose isn't the traditional document based web that is sped up by removing JS. Why should sites that actually benefit from something like WebAssembly be limited just because other sites will use it and (continue to) be slow bug ridden monsters?
- ZenoArrow 9y ago> "Red herring. People install or explicitly download code they want to run." When you visit a website, and you have given your browser permission to run JS, you're giving your permission to run JS. If you want to block scripts by default, use an extension like uMatrix: https://addons.mozilla.org/en-GB/firefox/addon/umatrix/ https://addons.mozilla.org/en-GB/firefox/addon/umatrix/
- phkahler 9y ago>> When you visit a website, and you have given your browser permission to run JS My browser never asked me about JS. Even if it did, browser developers would switch the preference rather than annoy the user with a prompt every time a site wanted to run some JS. The end result is that whatever is common practice, the users will end up accepting by default. In such cases it is the responsibility of the people setting standards to keep the users safety in mind. The responses in this thread really make my point. So many making excuses for running excess code and even advocating more APIs.
- ZenoArrow 9y agoTake some personal responsibility for the tools you use and how you use them. If a tool has some behaviour I don't like, but makes it easy to change it to something I do, there's no point in moaning that the option exists.
- zanny 9y agoWeb pages have included code in them since 1996. Less than 1% of browser users have ever experienced an Internet without code included in the pages they visit (or run NoScript). While there is issue with how ill informed the general public is in general on how web browsers / http / html operate in the first place, there is no disinformation campaign here - users don't think the browser does or doesn't run code because they don't understand how any of the system they are interacting with operates at all. The average extent of knowledge when it comes to computers is that the Chrome has the Facebook and you need the Wifi logo lit up for it to work, and even that last one is often way beyond the knowledge scope of your average Internet user.
- nmg 9y agoI think it's darkly humorous that I have to install browser plugins to stop sites from mining monero in my browser. It's like websites are those creepy spider things in the Matrix, except instead of sticking humans in pods to harvest their biochemical energy, they're just running up our home electricity bills by maxing our CPUs.
- meshy 9y agoWhat plugins do you recommend for this?
- simias 9y agoublock has a list to prevent "resource abuse", I believe it's enabled by default (it blocks things like coinhive & friends).
- etatoby 9y agouBlock Origin with the default choice of lists plus "Fanboy's Annoyance" makes the web 100s of times faster. It's now a default install on every browser of every computer I touch. Even on Firefox on Android, which works really well btw.
- Feniks 9y agoYeah web designers will hate me for this but at least 15% of every site is crap that I block. I'm on a 5Gb data plan for mobile and even on the excellent 4G networks we have here sites are still too slow and unresponsive.
- baybal2 9y ago>maxing our CPUs. And GPU too, I recently saw that I do get frequent crashes on certain pages, it appears that somebody is putting empty ads that do SHAsum in the background with WebGL using vec4 and shaders!
- api 9y agoLet's just move all those 80s cyberpunk novels to the nonfiction section and be done with it.
- grondilu 9y agoI don't understand this. What are you afraid of? Are you like Richard Stallman, only downloading webpages from email clients or something? Do you have filters that strip all javascript from the web pages you browse? If you're not one of these guys that refuse to execute any binary code that you have not compiled yourself, you should welcome the possibility of running binary code from a sandboxed web environment. I, for one, wish I could run all my proprietary software on the web, and restrict all my native applications to FOSS. That's a prospect WASM enables.
- marcosdumay 9y agoSo, fell free to lock both JS and WebASM on it.
- vbezhenar 9y agoHTML, CSS, SVG and other things your browser will interpret might be more complex than JavaScript and surely their implementation contains bugs and exploits. Hell, I recently learned about CSV injection (comma separated values). You can't realistically discard JavaScript and think that you're safe. The world is full of complex data formats ready to be exploited. Proper solution is to embrace sandboxes and put many walls around it, so inevitable bugs won't be exploited.
- baybal2 9y agoThis is wrong. The focus will simply switch to sandbox escapes. On x86, the only real "sandbox" you have is what your MMU gives you. For as long as executable has access to browser's address space, it can do anything a browser can, including reading your webcam, mic, sensors, GPS, etc
- phkahler 9y ago>> This is wrong. The focus will simply switch to sandbox escapes. Thank you. We have a winner here! And the people trying to escape them will have the full capability of native code running on your CPU. In the mean time, permissions will be granted for ever increasing parts of the system. Users will not be prompted to "allow" for every site they visit because that will be tedious so browsers will start the enable permissions by default. But either way, we now have the browser acting as the keeper of permissions that our OSes are not able to enforce at the granularity we need for such things. We've been continually migrating the browser to the role of an OS. It's just insane.
- Rusky 9y agoHow is it insane? It does a lot of things better than our current OSes. As long as we go into it knowing that's what we're doing it's an inherently better application and security model in a lot of ways.
- dundercoder 9y agoWhen DOM access comes, all my js will hit the round file.
- api 9y agoI dunno... React and React Native are nice. I would prefer to use those for UI but do everything else in C++14 or some other real language. The web stuff could just be the view.
- felipellrocha 9y agoSure. But it would be nice to be able to cheese between go and python for the UI, as well.
- api 9y agoI always cheese my UI. Mobile is the foot rub.
- ashark 9y agoAs much as I dislike JS, my experiences with React Native (JS but largely native UI elements) and Electron (JS with some native elements, but largely HTML+CSS) has convinced me that that HTML+CSS is my real (performance and battery life) enemy, with JS a significant but distant second. I look forward to better UI kits that just draw to a Canvas-like surface or something, ideally without needing an HTML+CSS engine at all. I'm not thrilled with that because I really like the old-school lightly-styled-HTML web, but I have to admit it's really really bad at "app" style layouts and interactivity, so if we must do that with the web (and apparently we must) it's gotta go, or it's gonna continue to suck.
- TheAceOfHearts 9y agoWhat do you consider a better alternative? A lot of people love to hate on HTM+CSS, but it's actually fairly powerful. I've been trying out a lot of native UI toolkits, and they're all as quirky and confusing as web tech. I'd agree that there's tons of room for improvement, but any UI tookit will need to make certain tradeoffs and deal with complex layouts and compositions. Flexbox and grid help a lot with app-style layout.
- flanbiscuit 9y agoFor now, couldn't someone build a js<-->wasm bridge so that you could have DOM access? This[1] seems to suggest it's possible [1] https://github.com/WebAssembly/design/issues/126 https://github.com/WebAssembly/design/issues/126
- tyingq 9y agoYou can, it's just very slow. See this issue, for example: https://github.com/rust-webplatform/rust-webplatform/issues/20 https://github.com/rust-webplatform/rust-webplatform/issues/...
- flanbiscuit 9y agoAre they writing their own DOM parser in Rust though? I should clarify what I meant. I was thinking more the way Cordova works where the JS side handles the DOM but the wasm side handles computations and they talk to each other via a "bridge". So maybe React can offload its heavier computations (diff-ing and what not) to a C lib compiled to wasm and it just returns data back to it.
- greenhouse_gas 9y agoAlternate universe: JVM was more secure and had better DOM interaction, so Applets won against JavaScript. The world goes around in circles.
- Rusky 9y agoIMO we would still need WebAssembly in such a world, because the JVM still enforces a heavyweight object model and GC. The "wasm is just the JVM all over again" meme needs to die.
- austincheney 9y agoCurrently DOM interop is a distant wishlist, so I wouldn't hold my breath. JavaScript isn't a perfect language, but it does have native lexical scope, which makes it a good fit for the architecture of web technologies. > Seriously JS should not be the lingua franca of the web What would you recommend for a replacement? When I typically see this it is from people can't figure out JavaScript as opposed to any rational technological reasoning. I cringe at the idea that people would offer forth really bad things that don't fit well merely to satisfy their own insecurities.
- askvictor 9y agoJS is not particularly accessible to beginners and makes it easy to write bad/dangerous code. A good programmer can write in anything, but it's the not-so-good programmers that you have to worry about.
- austincheney 9y agoAgreed. To be a strong candidate for a web scripting language you need three things: * native lexical scope. This is how all web technologies work. * Minimal reliance on white space as syntax. The language needs to be portable. Overloading white space as syntax makes a language more brittle, particularly in distribution. * Immediate interpretation without a prior static compile step. This keeps the code open to examination and minimizes compile time delays. Find another language that doesn't have all the stupid crap that JavaScript has and yet still excels in those three points and I will agree upon a replacement.
- askvictor 9y agoWhile I don't agree with your second point, which seems to be there purely to exclude Python, I'll run with it so as not to devolve into religious war territory. How about Lua?
- austincheney 9y agoA line terminator on *nix isn't a line terminator on Windows, which is a big deal if line termination ends a statement, and that assumes the file isn't modified in transit.
- ams6110 9y ago> get away from JS on frontend Yes, it's just about time for another generation to be old enough to think that we need to rewrite everything in a new language.
- krapp 9y agoBut now we get to rewrite everything in every language. Everybody wins!
- eighthnate 9y agoPeople have been saying that forever. But it's so entrenched now that it'll take a gargantuan effort to get rid of it.
- untog 9y agoI beg to differ. The DOM is the problem, not JavaScript. Once other languages can interface with the DOM everyone will finally realise this.