10 ms·
History of the browser user-agent string (2008)
- barce 9y agoNow, I know hacker news is just full of retards from Reddit. I got down voted 4 points for posting merely that the URL-Agent is a string that can be filled with any value. Here's a server log for proof, and down vote away, retards! 210.14.78.91 - - [09/Mar/2018:12:44:16 +0000] "GET / HTTP/1.1" 200 572 "-" "Mozilla/5.0 zgrab/0.x" 189.50.144.240 - - [09/Mar/2018:12:51:15 +0000] "GET / HTTP/1.0" 200 850 "-" "muhstik/1.0" 189.50.144.240 - - [09/Mar/2018:12:51:19 +0000] "GET /webdav HTTP/1.0" 404 1564 "-" "muhstik-scan/1.0" 172.104.164.143 - - [09/Mar/2018:13:36:14 +0000] "HEAD /.git/index HTTP/1.1" 404 0 "-" "Go-http-client/1.1"
- sctb 9y agoOoof. Please don't do this. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- VohuMana 9y agoThanks for the history lesson
- nasso 9y agoWow. What a mess! Super interesting read though! :)
- BillinghamJ 9y agoI'm guessing that today, in the current age of the modern web, user agents strings are no longer so relevant, and can be basically set to anything?
- joemi 9y agoSome servers feed different pages depending on whether they think a request is coming from a browser or a bot based on user agent string. Sure it's easy enough for a bot to pretend to be anything, but some servers are still set up to consider the user agent string.
- tyingq 9y agoStill useful, because of stark differences like “flash works” or “css grid works”.
- rahimnathwani 9y agoThe last time I tried browsing The Economist web site with lynx, it refused to work unless I changed the user agent string. Gibberish was OK, but apparently lynx wasn't.
- notatoad 9y agonope, user agent sniffing is alive and well. Google is especially guilty, but lots of sites do it. Try changing your user agent and see how many things break.
- cbr 9y agoWhen I was working on mod_pagespeed I wrote some about how we decided to parse the UA: https://www.jefftk.com/p/why-parse-the-user-agent https://www.jefftk.com/p/why-parse-the-user-agent (Summary: feature detection requires more round trips, and slows down pages.)
- smsm42 9y agoI've set up an extension that randomized my user agent string, to see what would happen, and some major sites were severely broken. Some gave me degraded mode (google did that several times). Also many sites use user agent for things like OS detection, so if you want correct downloads, must have at least partially correct UA. One can argue that yes, in 2018, there should be APIs that allow to detect all this stuff in a much better way than parsing random mess of legacy markers that is a common user agent. But in reality, parsing UA string is still the case and unfortunately keeps being the case, including very major and technically advanced sites.
- BHSPitMonkey 9y agoIt would be great if one of the major vendors made this the default behavior. Sites would start having cause to clean up this mess.
- minikomi 9y agoI've definitely tried browsing with a random User agent - many, many sites are broken. Give it a go!
- omarforgotpwd 9y agoGreat history lesson for people my age who might not have known this back story (I was born in the 90s).
- biesnecker 9y agoI need to bookmark this for the next time I hear “oh let’s just encode the params as a string” from a coworker.
- csours 9y agoSurely, THIS TIME, it won't balloon out of control! And who will ever need more than 255 characters of PATH?! File under: Problems that require a time machine to fix. https://blogs.msdn.microsoft.com/oldnewthing/20110131-00/?p=11633 https://blogs.msdn.microsoft.com/oldnewthing/20110131-00/?p=...
- biesnecker 9y agoThe road to hell is paved with one off exceptions that are temporary until we get a better implementation in place anyway. :-)
- Maultasche 9y agoI remember that in the very early days of Firefox, some websites would refuse to serve pages to anything that wasn't Internet Explorer. I did not see the point to that and I was not amused. Firefox didn't have a problem displaying those pages, so I had to install a plugin so that Firefox could pretend to be Internet Explorer so that I could just see the web page. I'm glad those days are over.
- bzbarsky 9y agoAnd in the newest installment, https://github.com/google/closure-library/issues/883 https://github.com/google/closure-library/issues/883 is UA-sniffing that is now preventing Firefox from aligning with all other browsers on whether arrow keys fire keypress events, which causes _other_ Google things, which assume they don't, to break. Also Closure assumes that only things with "WebKit" in their UA might be running on a mobile device and that all browsers fall into the WebKit/IE/Edge/Gecko buckets (and will fail badly if a browser does not). And this is just one library.
- bluedino 9y agoIn the days of Netscape, pages would tell IE users to "get a real browser"
- irrational 9y agoAren't we still saying this?
- Benjamin_Dobell 9y agoIE 7 Tax https://www.kogan.com/au/blog/new-internet-explorer-7-tax/ https://www.kogan.com/au/blog/new-internet-explorer-7-tax/
- gruez 9y agoI doubt that ever paid for itself in development cost vs "tax" collected. (yes i know it's probably a joke)
- 9y ago
- crobertsbmw 9y agoI wonder if the author of this text is religious at all..
- skellertor 9y agoJudging by his verbiage such as "In the beginning", and "behold", I would say yes. I rather enjoyed the tone.
- astura 9y agoI thought that was just alluding to the Book of Mozilla https://en.wikipedia.org/wiki/The_Book_of_Mozilla https://en.wikipedia.org/wiki/The_Book_of_Mozilla
- dlhavema 9y agoI think it's meant to sound more "ye olden times" like.
- Choco31415 9y agoFor me, the page isn’t loading. Here’s a Google cache of it: Text-only cache: http://webcache.googleusercontent.com/search?q=cache:maxiNwj6M34J:https://webaim.org/blog/user-agent-string-history/&num=1&client=safari&hl=en&gl=us&strip=1&vwsrc=0 http://webcache.googleusercontent.com/search?q=cache:maxiNwj... Edit: The full-version cache is broken for me as well!
- feelin_googley 9y agoMore cache urls http://web.archive.org/web/20180306011516/https://webaim.org/blog/user-agent-string-history/ http://web.archive.org/web/20180306011516/https://webaim.org... https://cc.bingj.com/cache.aspx?q=http://webaim.org/blog/user-agent-string-history/&d=4917026296366068&w=IDh6bxIIUwy8ASvaLhADIqZ5inWgsqxQ https://cc.bingj.com/cache.aspx?q=http://webaim.org/blog/use... https://archive.is/mJg8G https://archive.is/mJg8G https://88h6obas83.execute-api.us-east-1.amazonaws.com/dev/parse_article?source_url=http://webaim.org/blog/user-agent-string-history/ https://88h6obas83.execute-api.us-east-1.amazonaws.com/dev/p... The last one returns JSON
- kibwen 9y agoThe OP is from 2010. For those wondering what sort of user-agent a brand-new browser engine would adopt in this era, see this discussion regarding inventing a UA for Servo, which involved collecting data from popular sites in the wild to see how they treat UAs: https://github.com/servo/servo/issues/4331 https://github.com/servo/servo/issues/4331 TL;DR: you can see end result for each platform here: https://github.com/servo/servo/blob/2d3771daab84709a6152c9b56c43bad2b280b2ab/components/config/opts.rs#L456 https://github.com/servo/servo/blob/2d3771daab84709a6152c9b5..., and it looks like "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:55.0) Servo/1.0 Firefox/55.0"
- crzwdjk 9y agoGood to see that building Servo on ARM will return "i686" as the cpu architecture. Because there are plenty of sites that will just match /arm/ in the user agent string and redirect you to the mobile version, regardless of what your user agent actually is. Which is supremely annoying to those of use with ARM desktops (a tiny minority, I admit).
- exikyut 9y agoMIRROR: http://archive.is/u22lH http://archive.is/u22lH
- Wehrdo 9y agoThis is interesting, because at every step along the way, each actor took the locally optimal step -- webmasters wanted to serve up working pages to their users, and new browser vendors wanted their users to get pages with all the supported features. Yet, in the end, we end up with a mess for everybody. What could have been done differently to end up at a good solution? I guess having universally defined and complied with standards would have helped, so a browser could just say "I support HTML 1.3".
- dragonwriter 9y ago> I guess having universally defined and complied with standards would have helped, so a browser could just say "I support HTML 1.3". Probably not; standards on the web that don't lag behind implementation end up like XHTML 2.0.
- 220V_USKettle 9y agoYou made me chuckle.
- nerdponx 9y agoHow do other protocols handle versioning? SSL/TLS seems to do it well enough.
- cbr 9y agoThey have a lot of trouble too: https://timtaubert.de/blog/2016/09/tls-version-intolerance/ https://timtaubert.de/blog/2016/09/tls-version-intolerance/
- hannob 9y agoAbsolutely not. In TLS we now have two bogus version numbers you should ignore. We also have an extension that will signal the real version number. It'll also send a bunch of bogus version numbers to "train" servers to expect and ignore bogus version numbers. This is all due to the fact that server vendors found it too complicated to implement "if I get version higher than what I support I answer with the highest version I do support". Instead they often implement "if I get a version higher than I support I'll drop the connection". But all of that was not enough to make TLS 1.3 work. It now also includes sending a bunch of bogus messages that have no meaning and are ignored, just to make it look more like TLS 1.2. David Benjamin summarized that recently at Real World Crypto: https://www.youtube.com/watch?v=_mE_JmwFi1Y https://www.youtube.com/watch?v=_mE_JmwFi1Y
- barce 9y agoThe title is simply false. I read the article and it does present interesting history from the browser wars. However, any cursory glance of web server logs will show that sometimes the user agent string is blank, or it starts with "MobileSafari" or "UrlTest." The user agent string is client generated and can be anything the client wants.
- khedoros1 9y agoAh. Which browsers ship with those settings?
- palanik 9y agoSimilar story for every animated gifs to have "Netscape 2.0" app extension.
- ohf 9y ago> What's your favorite web browser? Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.13 (KHTML, like Gecko) Chrome/0.2.149.27 Safari/525.13
- petee 9y agoOne thing I wish were explained is where the 'U' came from; it first shows up when Mozilla was born with Gecko
- petee 9y agoQuick search answered my own question - 'U' indicates USA; As a result of cryptographic export restrictions, different levels of security were shipped in early browsers: U(SA) = 128bit, I(nternational) = 40bit, or N(one).
- astura 9y ago"Strong security (Default) the browser provides crypto support that is stronger than what the "international" builds of Netscape offered circa 1995." https://cat-in-136.github.io/2010/08/u-in-ua-string-and-aboutconfig-pref.html https://cat-in-136.github.io/2010/08/u-in-ua-string-and-abou...
- Macha 9y agoIt was about encryption ciphers, when the US had export restrictions on key lengths. U = USA = 128bit, I = International = 40bit, N = None. Nowadays the U is another vestigal piece of the UA string.
- deleted 9y ago[deleted]
- hsivonen 9y agoIt first showed up in Netscape 1.x. Getting it removed from Gecko was https://bugzilla.mozilla.org/show_bug.cgi?id=572668 https://bugzilla.mozilla.org/show_bug.cgi?id=572668 . Chrome and Safari followed.
- stagbeetle 9y agoSome more fun tidbits: > ProductSub returns 20030107 for Chrome and Safari, because that's the release date for Safari which used an Apple fork of WebKit. Chrome also uses this fork. For Firefox, it's 20100101. I don't know why. > Vendor returns "Google Inc." for Chrome, but undefined for everything else. > Navigator can tell if your device has a touch screen > Navigator can tell how many logical cores you have > appCodeName always returns "Mozilla" and appName always "Netscape" > Navigator can tell if you're using: Wi-Fi, Ethernet, cellular, Bluetooth, or WiMAX > Navigator knows how much RAM you have > And the exact plugins you're using. A Firefox useragent won't hide 'type':'application/x-google-chrome-pdf' > Your screen can be shared through navigator -- without your permission > Languages are set as either `US-en` or `en` to differentiate between Americans and British > Your battery can be acpi'd by Navigator > File permissions can be read, revealing usernames And this is just navigator, wait till you see all the fun things you can do with Javascript and canvas.
- silverwind 9y ago> For Firefox, it's 20100101. I don't know why. At some point in time, that date was Firefox's build date. Then, some concerns were raised about that date allowing sites to track users based on that date so it was set to 20100101.
- edwhitesell 9y agoGreat article. Could we get [2008] added to the title please?
- jayflux 9y agoCan Mozilla/5.0 be eliminated these days?
- astura 9y agoNew pages aren't the problem - pages written 20 years ago still exist and might depend on the Mozilla/5.0 being there to render properly.
- antoncohen 9y agoIt gets one better... And Chrome was good, and MSIE wasn't, so webmasters served bad pages to MSIE. Microsoft was not happy. So they created Edge. Edge was good, but Microsoft feared webmasters would treat it like MSIE. So Microsoft Edge pretended to be Chrome to get the good pages. Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.71 Safari/537.36 Edge/12.0
- h1d 9y agoI doubt that's the case. MS knew IE was broken and outdated but so many people rely on its implementation at that state, they couldn't move it forward and they had to reset before they lost every share in the browser market. They certainly didn't want Edge to look as broken when people had, if(browserType === 'IE') doIEWorkAround() else doNormalThings() So I understand their disguise.
- hermitdev 9y agoI always feel like these timelines miss an era. The era where Netscape stagnated and MS came in with a superior, free, non-standards compliant browser that actually pushed the evolution of HTML/JS forward. IE 4.0-IE 6.0 pretty much pioneered features that would become HTML 4. For example: dynamically modifying the DOM and XML async requests. IE pretty much ushered in the era of truly dynamic websites. Granted, IE 6 sucked (eventually), and thus began the era of IE stagnation. MS got the market share they wanted, then basically sat on their hands for a decade (as the other browsers started innovating again and W3C got off its ass). Shit on IE all you want, but there was a forgotten era when it was the pioneer. Also, I'm generally finding Edge on Android a better experience than Chrome on Android after having played with it for a month or so. I still prefer Chrome vs Edge on my Windows desktop. Obviously, YMMV, but these are my personal observations and experiences.
- zamber 9y agoOn Android and Windows I'm finding Firefox better than both. Extensions in Firefox on Android are particularly helpful. There's an issue with not-always-60fps scrolling in Firefox on Android and the UX is not ideal, but having uBlock Origin and Stylus on Android in my opinion beats that.
- smsm42 9y agoShould be "Why every browser user agent string"... Non-browser agents usually don't (and shouldn't) do the Mozilla tricks.
- ogoffart 9y agoActually, we've had to add "Mozilla" in the user agent of one of our program because users have been complaining being blocked by some proxy.
- smsm42 9y agoI can get per-browser content switching, but blocking by proxy is a malpractice. Probably driven by some bot abuse, but certainly a very wrong way to deal with it.
- michaelmior 9y agos/start/starts/
- grzm 9y agoActual article title: "History of the browser user-agent string"
- askvictor 9y agoThe userAgent property has been aptly described as “an ever-growing pack of lies” by Patrick H. Lauke in W3C discussions. (“or rather, a balancing act of adding enough legacy keywords that won’t immediately have old UA-sniffing code falling over, while still trying to convey a little bit of actually useful and accurate information.”) [https://superuser.com/questions/1174028/microsoft-edge-user-agent-string https://superuser.com/questions/1174028/microsoft-edge-user-...]
- phamilton 9y agoAnyone doing anything with user agents should use ua-parser[0]. Don't even bother trying to do any of this yourself. If ua-parser doesn't exist in your language, just pull the yaml file out of ua-core. That defines the regexes you should use and how they translate to browser versions (and os versions and devices). [0] https://github.com/ua-parser https://github.com/ua-parser
- whatismybrowser 9y agoShameless plug for the WhatIsMyBrowser.com API: https://developers.whatismybrowser.com/api/ https://developers.whatismybrowser.com/api/ As per modern web dev standards: you should always use feature detection not agent sniffing to handle cross browser issues; however having accurate user agent detection is really handy for trouble shooting customer issues, bot detection, spotting trends etc.
- kccqzy 9y agoAre you encouraging people to do browser sniffing accurately? Aren’t we supposed to discourage such sniffing instead?
- BHSPitMonkey 9y agoYou can still want to parse UAs for other reasons. I used such a library recently in a project where a user is shown their login history, including what OS and browser was used, in a human-readable format (e.g. "Firefox 58 on Linux").
- paulddraper 9y agoIdeally, you would not care at all. You would simply develop HTML 4/5/6 a user has a browser that supports that spec. In reality, browsers have known bugs that last for years, you need to collect stats to figure out support policies, and you need to reproduce customer bugs. Example: old versions of Firefox have an RCE vulnerability if you use third party jsonp apis. If you use these apis but don't block these ff versions, your users will be vulnerable.
- deleted 9y ago[deleted]
- nabla9 9y agoAnd Alan Kay saw this coming from a mile away and said: "What a total stone age BS this is. We already did it better in the PARC". Instead of sending shitty text files to rendering engines to parse all their own way, we should send objects. Every object should have an URL and the users should interact with these objects. And he teamed with David A. Smith and six others and they made it happen... aand it had 2d objects and it had 3d virtual reality where objects from different servers interacted and everybody saw it was cool as hell, but nothing came out of it because the world is path dependent and network effects rule. http://wiki.c2.com/?OpenCroquet http://wiki.c2.com/?OpenCroquet https://en.wikipedia.org/wiki/Croquet_Project https://en.wikipedia.org/wiki/Croquet_Project https://www.youtube.com/watch?v=XMk9IGwuRmU https://www.youtube.com/watch?v=XMk9IGwuRmU TL;DR: Future was already here, but it could not communicate with the present.
- jwilk 9y agoCopy of the wiki.c2.com article that doesn't require JS: https://gist.github.com/anonymous/157c4b7eca4105bb6d374d551aec3186 https://gist.github.com/anonymous/157c4b7eca4105bb6d374d551a...
- orf 9y agoWhile cool I'm not sure a 3D interface to a Wiki was ever the future. Thank god.
- nabla9 9y agoIt was a phase. There was VRML, The Second Life, Linux had that 3d cube where every side was a virtual screen. Everyone had been reading Snow Crash. And just like virtual reality was just around a corner, it was also the time of the first digital currency boom: Liberty Reserve, E-gold, DigiCash, Flooz. More things change, more they stay the same.
- wlesieutre 9y agoFunny you should mention it, I just ran into VRML today. In AGI32 (a terrible piece of lighting simulation software) if you hit export in a rendered view that's the default format it offers you.
- pastelsky 9y agoIt's quite interesting how user agent stings have changed and become more bloated with time. Other fun facts: - Chrome on iOS reports its chrome version (eg 64.0.36), with no way to get the underlying Safari engine version. - Android webviews have replaced one UA string pattern with another close to three times (pre-Kitkat, Kitkat till Marshmallow, and one for marshmallow and above) - Chrome continues to add a "Webkit" version to its UA, even after having forked to Blink. Though since Chrome 27, the webkit version always says "537.36". Src - I wrote a library that generates user agent strings programatically - https://github.com/pastelsky/useragent-generator https://github.com/pastelsky/useragent-generator
- samfisher83 9y agoI learned from that article what Mozilla means: Mosaic Killer.
- deleted 9y ago[deleted]
- ersh 9y agoMy user agent starts with "Wget" :)
- arca_vorago 9y agoThe ol Stallman-oroo
- baleine 9y agowhat should the user agent be if you have to plug in the internet throw a plug behind your head, in the coming soon 20 years later
- biastoact 9y agoI once created a similar problem. I built a tracking and split testing system designed around a list of features activated during a page load. So a single page load might be described like: root,signin,bluebutton Where bluebutton was a design we were testing for our signin page. Of course once bluebutton worked and had run for a while everyone was afraid to change it in case there was a dependency of some kind. So the Facebook login that replaced the old signin would look like: root,signin,bluebutton,fbookredirect Even though no sign in page was shown let alone a bluebutton.
- qwerty456127 9y agoThe whole thing should be deprecated altogether.
- walrus01 9y agosaying "... and used KHTML" glosses over the entire Konqueror project and existence of Konqueror long before the first release of Safari. I was using Konqueror on a KDE 2.0 desktop quite happily for a while.