24 ms·
New in Chrome 70
- stephenr 8y agoI'm sure nothing terrible will happen by exposing Bluetooth to the world of skeezy javascript malware.
- oaiey 8y agoA pity that the classic RFCOMM interface is not supported (at least how I read it).
- bjt2n3904 8y agoThe other day I was scrolling past a panoramic picture on Facebook. I happened to jostle my phone, and was surprised to find I could look around the picture by tilting my phone. When the fsck did this become a feature? Why did nothing ask me if I was ok giving Facebook access to my hardware? How do I turn it off? Who thought this was a good idea!? These same questions apply to Bluetooth. Already, such a terrible standard when it comes to privacy. And now, random websites can grab control of my radios? With JavaScript? Nothing wrong can happen with this, for sure! FFS. This is like the battery api. Too much time spent on "can we", too little time spent on "should we".
- andun 8y agoAll new web standars are a terrible idea to our privacy and security. And for some reason nobody seems to care.
- stevehawk 8y agoMy theory on this is becoming - because the nerds that would care all work for the Big Five and as such think it's ok because "we're not evil". Once that crowd gets quieted then there's no on to raise the flags for others.
- deleted 8y ago[deleted]
- userbinator 8y agoPeople care, but those who do are not working on them and their voices get drowned out by the "push the web forward"/"progress is always good" crowd. I suppose there is a bit of cognitive dissonance among developers of such things too.
- jake_the_third 8y agoI run my(?) browsers in their own separate virtual machines. You loose copy and past and you'll need to set up folder sharing, but shit like this is a non-issue. No major browser vendor (and I mean not a single one) puts users' privacy first. People should treat browsers as the privacy hazard they are.
- vbezhenar 8y agoWhy lose copy&paste? Virtualbox supports seamless copy&paste, every other VM probably supports it as well.
- kgraves 8y agoThis is also similar to the time that WebUSB[1] was added to Chrome, allowing access to USB devices in the browser. I feel that we are frogs in boiling hot water. [1] https://developers.google.com/web/updates/2016/03/access-usb-devices-on-the-web https://developers.google.com/web/updates/2016/03/access-usb...
- chucky 8y agoFWIW the battery api was first specified when people were still hoping that building phone widgets, launchers etc would be done with web technologies. For such usage, having battery api access in a standard way was of course a necessity. In a wider sense, there are legitimate uses for many of these apis. To me it seems like the option would be that some phones would get these apis patched into the browser by the manufacturers instead, and that would run an even higher risk of security problems than when the browser vendors do it. If you don't like your browser application having access to certain hardware in your phone, you can just revoke the permission, and it won't have the access (at least on Android, I have no idea how iOS works in this regard).
- gsnedders 8y ago> FWIW the battery api was first specified when people were still hoping that building phone widgets, launchers etc would be done with web technologies. For such usage, having battery api access in a standard way was of course a necessity. And it was done by Mozilla people working on FFOS, specifically. They had no intention of exposing it to web content IIRC.
- earthscienceman 8y agoI still see FFOS as ahead of its time. I really wish it would have worked out better.There's all this jostelling happening between the role of software based apps vs. the role of web content/apps on devices... but in the end every day I see more and more content being served through the web. As browser integration improves (through things like 'web bluetooth') I think we're creeping more closely to the browser essentially being an app sandbox for your hardware/OS. Now, whether this is good or not is left as an exercise to the reader.
- tinus_hn 8y agoI think the original idea was that background JavaScript apps could suspend operations when your battery is running low. It quite an edge case but it’s one of those things that make a web app less than native.
- koboll 8y agoRight? Now imagine phone tilt or battery information on the scale of billions of people. Imagine what you can infer. This person's phone has been tilting less often over the past decade - a trend correlated with, let's say, a more strained gait caused by weight gain. The algorithm markets them more sugary foods, because there's a higher likelihood they're effectively addicted to calories. This other person is letting their battery run down more often - a trend correlated with undiagnosed depression. The algorithm ratchets up the fear and sadness because it infers these will be more effective motivators to buy products. The best part is that this will probably all happen invisibly. GDP and human suffering creeping up slowly, with no human at the helm, and the world none the wiser.
- obituary_latte 8y agoAlso, when the phone is upside down (reading in bed), or traveling etc. Scary to think of all the things that could be gleaned.
- Brakenshire 8y agoDoes phone tilt really give an acceloremeter data stream? I thought it was just landscape or portrait.
- tokyodude 8y agoit does but only while the page is active. As soon as you switch tabs, apps, or your phone locks the data stops
- lucideer 8y agoThe Web Bluetooth API asks you for permission every time. Like every new web standard like it. It's still something many users will blindly click through but at least there's that. At least this doesn't seem to be a priority feature for Mozilla yet. MDN doesn't even have proper docs for it. So I'm a bit thankful for that, for now. As for Facebook and the accelerometer, I'm presuming you're on Android, so you can definitely blame Google for that.
- deleted 8y ago[deleted]
- bjt2n3904 8y agoHow kind of them to ask! It has all the charm of someone walking up to my house at four in the morning, and knocking on the door to conduct a survey of which radio stations I listen to. It shouldn't be asking, ever. The answer is such a hard no, it makes me wonder why they even tried.
- vbezhenar 8y agoBluetooth provides useful features for many users, that's why.
- bjt2n3904 8y agoYes, like making poor estimates of my heart rate, being an insecure keyboard, or occasionally failing to deliver audio to my car speakers. Definitely will be useful in my web browser.
- salvar 8y agoAre you claiming that Bluetooth can never be useful for anyone because you don't find it useful?
- lucideer 8y agoWhy specifically at four in the morning in your analogy? I mean, door-to-door surveys are a pretty common thing at normal hours of the day, and that seems like a reasonable analogy without the arbitrary time change.
- realusername 8y agoThe battery api was removed from Firefox for this reason, it was only used for tracking unfortunately.
- diggan 8y ago> These same questions apply to Bluetooth. Already, such a terrible standard when it comes to privacy. And now, random websites can grab control of my radios? With JavaScript? Nothing wrong can happen with this, for sure! No, this is usually not how new features are being used in the browser (see geolocation). Websites won't be able to scan your nearby devices without asking for permission, and it's up to the user to accept/decline it. I'm actually quite excited over having Bluetooth accessible in the browser. That means that we could build P2P applications that works in the browser, that works even when not connected to a wifi and can talk with nearby computers via Bluetooth, something that has not been possible before (FlyWeb was close at achieving something like that as well)
- bjt2n3904 8y agoBecause you know, I've always been on my desktop computer and said... "You know, I'd totally use that cool mesh Bluetooth chat app that's so popular and lets you communicate with people within a 25 yard radius, but ultimately falls back to using WiFi because Bluetooth is impractical for this application. Sadly it's not for desktops. If only I could use my web browser..." No! I've never said that! In fact, no one has ever said "I wish I could use Bluetooth in my browser", except for people who want to collect more data on their users. This is like an idea from Todd on Bojack Horseman. Again, too much time on "could we", not enough time on "should we". Bojack clip in question: https://youtu.be/Ct6EuC1W1gE https://youtu.be/Ct6EuC1W1gE
- diggan 8y ago> In fact, no one has ever said "I wish I could use Bluetooth in my browser" I literally just wrote above that I do want that. I also don't care about collecting any data. Guess you have to take my word for that. So now you know one person at least :) I'm not sure where in the world you are, but there are many use cases where meshing clients together is the only way of getting non-restricted network access to each other. The only reason why I think Bluetooth + Browsers are a powerful combination is the fact that it's so easy for people to get started, compared to how desktop works. > I've always been on my desktop computer and said ... No! I've never said that! Great, maybe this is not for you but you should try to consider other peoples point of view as well, that might live on the other side of the planet. Otherwise discussing further becomes rather depressing.
- Yaggo 8y ago> [...] I could look around the picture by tilting my phone. When the fsck did this become a feature? Why did nothing ask me if I was ok giving Facebook access to my hardware? To be precice, by using the device orientation API offered by the browser, Facebook has no access to your hardware any more than it has access to your display hardware by utilizing the DOM API to draw on screen or access to your cellular radio by making a TCP connection. Whether the browser should require your permission (per site?) to use device orientation API, that's debatable. Anyway, that's up to the browser implementation.
- koolba 8y ago> Whether the browser should require your permission (per site?) to use device orientation API, that's debatable. Anyway, that's up to the browser implementation. I think anything that involves making new/more input available to remote sites should require opt in. At the very least it should have a toggle to disable it globally.
- matt4077 8y ago> Why did nothing ask me if I was ok giving Facebook access to my hardware? I'll let you in on a secret: Facebook is also controlling your graphics card, and CPU, and memory. Controlling as in "sending HTML that is then displayed via those hardware components". And just like a media query can "access" your device orientation, panoramic media can adapt to the data from accelerometers. The missing information here is the concept of "secure contexts": https://w3c.github.io/webappsec-secure-contexts/#intro https://w3c.github.io/webappsec-secure-contexts/#intro. Being able to use this data does not mean that it can be send back to the server.
- syn0byte 8y agoThat's a misleading non-argument for the actual issue. "Your Wells Fargo bank accounts perfectly safe from bank employees because armored cars are used to transport money. They don't let normal bank employees into the back of those vehicles. Only licensed and bonded security guards are allowed."
- Ajedi32 8y ago"Secure Contexts" just means you're visiting the site over HTTPS. It has nothing to do with restricting the ability of JS to communicate with the internet.
- simias 8y ago>Too much time spent on "can we", too little time spent on "should we". I mean, that's the web summed up in a single sentence. What started as a way to view text and pictures online is now more complicated than many operating systems. You cram all that stuff into a single binary, give lackluster and ever changing controls to manage all that and call it the future. Never attempt to break down the functionality across several dedicated clients that do only one thing and do it well, that's for losers. But I somehow disagree with your statement in that it seems to imply that the people designing that garbage are naive or don't really think about the consequences of what they're doing. That might have been true in the early days of the web when nobody knew exactly what it was going to be but it's clearly not the case now. The folks at Google know exactly what they are doing, making browsers more complicated and easier to interconnect with smartphone is win/win for them. It makes it harder to make a competing browser (anybody attempting to make a new browser these days basically has to fork Chrome or Firefox, and generally they go with the former), you need huge developer resources to maintain and optimize it (look at how hard Firefox is struggling to keep up despite the large number of people working full time on it) and while the big G doesn't control Windows, Mac or Linux they do control Chrome and Android so they have a huge incentive to push everything possible away from desktop OSs and into Chrome. They want Chrome to be the OS. Google is 90's Microsoft with better PR. Well actually it's worse than that because MS didn't usually have access to my private data while google knows almost everything about their users if they have an Android phone and use gmail.
- UI_at_80x24 8y ago>Google is 90's Microsoft with better PR. Well actually it's worse than that because MS didn't usually have access to my private data while google knows almost everything about their users if they have an Android phone and use gmail This is the statement that I have known for years but never put into words. And it rings terrifyingly true.
- dvfjsdhgfv 8y agoWhat is terrifying for me is that when it was happening - and it didn't happen overnight, it was a long process - relatively few people were objecting. The ones who objected were often ridiculed as the tinfoil-hat group. The people who should have been smart enough have been blinded by shiny new releases, the amazing things we can do now, for free. It's only recently that the general public started to discover the ugly truth, whereas we could clearly see it already many years ago!
- deleted 8y ago[deleted]
- dtf 8y agoIf you're talking about the DeviceOrientation event [1], it's been shipping in browsers since 2010 [2,3]. It also works on your MacBook. [4] [1] https://w3c.github.io/deviceorientation/ https://w3c.github.io/deviceorientation/ [2] https://caniuse.com/#feat=deviceorientation https://caniuse.com/#feat=deviceorientation [3] https://www.engadget.com/2010/07/06/google-chrome-gets-some-early-device-orientation-plumbing/ https://www.engadget.com/2010/07/06/google-chrome-gets-some-... [4] https://simpl.info/deviceorientation/ https://simpl.info/deviceorientation/ (PS my humble opinion is "yes we should". I like being able to develop a heart rate monitor PWA for my phone, and I don't see what's different from granting some random native app the same access. At least with the web I can read the underlying code.)
- vardump 8y ago> It also works on your MacBook. [4] It did absolutely nothing on my 2015 MacBook (tried Safari, Chrome and Firefox). It does work on 2012 MacBook model on Google Chrome. I guess it only works on MacBook models that supported a mechanical disk — I think the sensor exists in the first place to protect spinning rust disks by parking the heads just before impact.
- dtf 8y agoI just noticed that [4] doesn't work on Safari or Firefox either (but does on Chrome) on my MacBook 2010. Maybe it wasn't the best demo of that feature ... The API is pretty well supported on tablets and phones though, which is where the main use case is.
- Fnoord 8y agoDoesn't do anything on my Chrome @ MBP 2015, but then again I use all kind of extensions.
- grezql 8y agoAnother one is the Push Notifications in browsers. I always block them. Once you open up such APIs websites will abuse it no matter what.
- kmlx 8y agohi. i develop webapps that run in the browser. these apps leverage webrtc, battery api, local/session storage, websocket, webvr/xr, webgl, you name it. all have legitimate purposes, all run in a browser under https and none have ever been used for tracking: one app that uses webrtc does one to many broadcasts, another uses webxr/webgl to display 3d vr experiences, etc. these apps are used by tens of thousands on a daily basis. and they’re nothing fancy. my advice is to not dismiss the advantages of the web just because of a few bad apples.
- falcolas 8y agoIt's not a few bad apples. It's a shipping container full of rotten apples, and maybe two good ones. That is to say, without the analogy, that it's the ad companies who will abuse these, ruining virtually every web site that exists, and jading users against the technology for the few websites who aren't abusing it.
- laumars 8y ago> my advice is to not dismiss the advantages of the web just because of a few bad apples. Except protecting against the "few bad apples" is exactly what we're supposed to be doing. Eg you made a point that your use cases are all served over HTTPS - why should we be doing this when it adds complexity, adds bandwidth and breaks many legitimate corporate management tools? The reason we bother with TLS is precisely because of "a few bad apples". The point of security is to harden against those bad apples rather than ignore they exist just because developers want a shiny new toy to play with.
- Ajedi32 8y agoWhich is why the web has the most robust permissions system of any platform, period. Sites that need these features for legitimate purposes can access them, while sites that don't can't.
- laumars 8y ago> Which is why the web has the most robust permissions system of any platform, period. I fundamentally disagree with that. Yes it has a permissions system but is it really all that robust? Let alone the most robust of any platform? First off you're dependant on the browser implementing that correctly (that's not always the case) and often there are thousand different ways you can still do naughty things even if those permissions are implemented correctly. Then there are the thousands of vulnerabilities built into the very design of the web that developers (of both web and browsers) are constantly having to code around (XSS, et al). And that's without even addressing the current problems we have with data leakage and privacy concerns that we seemingly have little control over at all. Compare that to networking where you have VLANs, subnets, firewalls and other network ACLs; or Linux servers where you have tools like SELinux. These tools might not be simple to use from the outset but their certainly a great deal more robust than any of the models the web has offered us thus far.
- kinlan 8y agoSite's can not do anything with Bluetooth API unless the user explicitly granting them permission to use the feature. A site can't even query the devices around the user without the user getting a very clear and actionable prompt - so in this case it is nothing like the orientation API.
- ConcernedCoder 8y agoSo the sheep can't query the interface without the wolf's permission? great... I'll be sleeping so much better tonight.
- adrr 8y agoThe industry is trying to replace native apps on mobile devices with web pages.
- jdlyga 8y agoThis is an android thing right? They gotta add more fine grained permissions
- true_religion 8y agoTechnically, Javascript can already make web requests, whoch when you are on a phone means using wifi or mobile data, both of which are radios. So Javascript has always controlled your radios. This is just one more connection.
- jackhack 8y agoOh, they're asking "should we" -- they're just not asking the public (the public is the product being sold, after all).
- mtgx 8y agoWebAssembly and PWAs are only going to make this worse, as they give browser vendors an excuse to give websites full access to the user's local machine.
- philosopherlawr 8y agoGet Off My Lawn!
- thrower123 8y agoIf some browser application can get bluetooth devices to actually work and do things for it, good for it. I sure as hell have never been able to hehe.
- shwetank 8y ago> And now, random websites can grab control of my radios? With JavaScript? No. Only the user allows it. >FFS. This is like the battery api. Too much time spent on "can we", too little time spent on "should we". The battery API can be tremendously useful on mobile if used effectively. For example, disabling certain animations and high end GPU intensive effects if the battery is less.
- baddox 8y agoWould you complain that web browsers have access to your keyboard and mouse without explicitly asking? If not, then why complain about access to DeviceMotionEvent?
- limeblack 8y agoMac has supported beginner friendly ways of sshing into let's say a Raspberry Pi over Bluetooth[0]. I would love to see a progressive really any app for Windows like this. [0]: https://hacks.mozilla.org/2017/02/headless-raspberry-pi-configuration-over-bluetooth/ https://hacks.mozilla.org/2017/02/headless-raspberry-pi-conf...
- kaffeemitsahne 8y agoI wonder what the next layer is gonna be after web browsers have completely taken over all operating system functions.
- tonyedgecombe 8y agoIt's JavaScript all the way down.
- pavlov 8y agoWeb workers and service workers are already a new layer of tightened sandboxing on top of the JavaScript sandbox whose volume of sand is soon approximating Sahara.
- oblio 8y agoI like how POSIX is loved and the web is hated. Guess what, after companies agreed to POSIX, they wisened up. The web is the best cross-platform platform we're ever going to get. Best not because it's amazing, but because everything else will be nipped in the bud by today's crafty multinationals.
- fredoralive 8y agoThe greatest threat to the web is those that want to turn it into an “app platform” instead of a hypermedia system. Sadly the battle has probably been lost.
- chatmasta 8y agoIn what way is it a threat? It’s not like every website needs to use the new features. If you mean security/privacy wise, then yeah I agree. But I don’t think it’s a “threat” in any other sense, eg it doesn’t mean every website is suddenly going to be using accelerometers and Bluetooth. It just means a subset of websites will have more features for browsers that support them. Aside from the security/privacy issues, shouldn’t we be celebrating this as a liberation of functionality from walled garden app stores?
- addicted 8y agoYou are right. The sites that will use this are those who have a strong incentive to do so. Therefore this will likely be used by: 1) A really tiny minority of sites that enhance functionality with this. 2) Malicious sites. 3) Sites that are trying to track you more and better (so, for example, FB can use this to ID you across devices even if you’re not logged in because you probably use the same Bluetooth headphones across your devices).
- UncleMeat 8y agoA really tiny minority? Today I navigated some maps in an unfamiliar city in a web browser. I also edited some images. I streamed some video too. These are incredibly useful features. Pretty much the only "raw document" websites I ever visit are wikipedia, hn, and stack overflow.
- AnIdiotOnTheNet 8y agoYou think this is bad? Wait 10-15 years, when the next layer of abstraction starts to take hold and now you're running some other platform on top of a web browser on top of an OS and all the kids are saying "this time will be different!".
- nemodmarg 8y agoWhat is the realistic everyday use case for this?
- shamas 8y agoIt can be used to access a company's own hardware.
- stirlo 8y agoConfiguring a Fitbit directly from their website?
- mrweasel 8y agoOr just uploading fitness data from a device that's not paired with a phone.
- codingdave 8y agoMaybe not a wide use case, but the first thing that comes to mind is for people who work outside an office (law enforcement, for example) to collect data on their device as they do their job, then have a way to upload it into a web app when they return to the office, and not be sending it over a more public network while in the field.
- spreiti 8y agoNot a use case per se but, I think it could be useful in combination with Progressive Web Apps (which can work without an internet connection) to control bluetooth devices without installing an App.
- zawerf 8y agoPairing your phone with your pc for realtime inputs w/o going through internet. For example https://www.airconsole.com/ https://www.airconsole.com/ turns your phone into a gamepad for multiplayer browser games. But I think they are using web sockets or webrtc right now which is kind of silly when everyone is in the same room looking at the same browser.
- userbinator 8y agoGreat, another feature that is probably useful for <1% of websites but will likely be used for anti-user functionality like tracking and surveillance more than that. Maybe I'm just old, but I find this trend of exposing more to the outside over the network quite disturbing, and it's also becoming rare for me to be joyful about a new version of software instead of "what did they break or bloat this time"... the Web was far more pleasant when it was about hyperlinked documents and not this cloud-computing-inspired frenzy.
- matt4077 8y agoIf you don't use these capabilities, they probably amount to less than a Megabyte increase in the file size of the binary, and the potential that you could be shown a dialog when a website asks for permission. I fail to see how this might significantly cramp your lifestyle, or what this has to do with cloud computing. (You can even disable these functions globally. Or at least that's what you can currently do with similar APIs like MIDI device access. (And btw: Did MIDI device access ever get you profiled by the CIA?))
- ptero 8y ago> potential that you could be shown a dialog when a website asks for permission First, I suspect that this is in itself annoying to many users (it is to me). Next, even at 1% of accidental clicks it would give out large unintended access. A cynical part of me says that if technology shows tracking benefits it would switch to "accept once, reject every time" and many users would be tempted to click on it just to make those annoying popups go away. The main beneficiaries of this misfeature are advertisers.
- onion2k 8y agothe Web was far more pleasant when it was about hyperlinked documents and not this cloud-computing-inspired frenzy It was also a lot less useful though, as it was mostly about consumption. All of the creating happened elsewhere. People made things on their computer in other apps and then published them to the web. Now though, the web platform is shifting towards being a creative place in itself. People can make and share things entirely within a browser. I'd think that's a significant positive change.
- LegendaryPatMan 8y agoWait... Windows 10 allows applications to control radios... So couldn't you go past some site doing a driveby, Chrome get's control of the Bluetooth radio and then the site can just go Bluesnarfing against nearby devices? Or say have an extension in Chrome that gets control of the radio and you can use the control of the radio and go sniffing for data like I don't know messages or health data sent between phones and smartwatches?
- CyberDildonics 8y agoMost of this thread seems to be people upset that this exists. Do people not realize can control javascript permissions?
- fenwick67 8y agoThey're rightly concerned that it will be used like notification permissions: just one more thing you need to cancel when you use a site. Yes you need to consent, but even being asked is audacious.
- Ajedi32 8y agoNotification permissions are widely (mis)used because many sites already have a legitimate use-case for that permission; keeping users updated on new articles posted on the site. It's not at all clear that a similar widely applicable use-case exists for Bluetooth.
- Outpox 8y agoThis is just plain boring to be honest, I don't want to be notified when a new article is released, I'd rather manually check a RSS app when I want to read such news instead of receiving a notification while I'm working. To each its own I guess.
- krapp 8y agoPeople are upset that javascript exists as well
- stephenr 8y agoIt's another google invented 'extension' to the web, built for one purpose: to validate their assumption that a Chromebook is a viable computing platform. "The web has all these limitations, how can a device run only web apps" "Oh well we're google, we'll just shoe-horn whatever shit we need into web specs and force them through." When this came up for discussion a year or two ago, it was highlighted that they acknowledged the potential for harm, and gave zero solutions to resolve that issue. Edit: its an almost comically similar story with their other attempt, "web usb"
- jatsign 8y agoAside - It also lets you install progressive web apps onto the desktop. Has anyone built PWAs, and if so, why? Do they work cross-platform/mobile well?
- Scirra_Tom 8y agoInstalling as app works great for our PWA: https://editor.construct.net/ https://editor.construct.net/ > Has anyone built PWAs, and if so, why? Do they work cross-platform/mobile well? Works cross platform great. Construct 3 is a sophisticated productivity app, although it works on mobile devices it's not the ideal environment to get lots of stuff done with it. Coming from a Windows native app, main advantage in developing a PWA is that it allows easy cross platform support (Chromebooks especially good for educational markets) and much more agility in developing compared to say a native app.
- jatsign 8y agoVery cool. Do you happen to have any links to read about getting started? Any specific technologies (frameworks/libraries/etc) that helped out? Any lessons learned?
- Scirra_Tom 8y agoMy brother (and co-founder) actually develops the product with 2 other full time engineers, I'm not involved in the product development directly. It was all built from the ground up though. I think we were well ahead of the curve when it was started to be developed 3-4 years ago. Mentioned in another comment yesterday that we decided against using third party UI because we were worried about bloat, third party dependencies and general responsiveness. Whole app is usable in ~1mb of network load (less than lots of big-corp homepages) and we get comments from users saying after using it for a while they forget they are in the browser which is great and a strong indicator we've hit the mark. If we were to start again today, we'd still roll our own UI. My brothers blog is very good and often technical and goes into a lot of interesting web tech stuff relating to Construct 3 and PWA's: https://www.construct.net/en/blogs/ashleys-blog-2?orderID=1 https://www.construct.net/en/blogs/ashleys-blog-2?orderID=1 There are a whole raft of benefits of PWA's, probably too many to list especially coming from our native predecessor Construct 2. Auto updating users to latest versions, no download/installation which helps significantly with converting users into just trying the product, faster load times than our native Windows predecessor, easier distribution etc etc. Cross platform support is an incredible competitive advantage in some markets such as education where Chromebooks are common and competition is sparse/non-existent. It even runs on Raspberry Pi's and we're confident we're future proofed for new devices. Making your PWA fully functional online is tricky but doable and I believe particular care needs to be taken here from the beginning. Retroactively implementing offline support would be difficult. It's also important to not get too fancy and building it for offline use helps you avoid these traps. We've seen some PWA's record every user interaction within the PWA which appears to be the basis of some features such as undo - this brings in a huge raft of complexities. A few shortcomings, but the gaps are being bridged slowly but surely. For example copying images to clipboard: https://bugs.chromium.org/p/chromium/issues/detail?id=150835 https://bugs.chromium.org/p/chromium/issues/detail?id=150835
- Proven 8y agoWhat could possibly go wrong?
- emsy 8y agoSo many I'll informed comments on top of this submission. First, the web Bluetooth API requires a permission. It's useful for more fully featured PWAs. Even though I personally think the browser shouldn't have become an app platform, that's the world we live in now. The best cross platform solution is the one most platforms support and today this is the browser.
- baybal2 8y ago>First, the web Bluetooth API requires a permission. ActiveX also required a permission...
- Uhrheber 8y agoBeing able to use Bluetooth REPL for microcontrollers running MicroPython is somewhat cool, but also rises serious security concerns, if such a device is used for IoT.
- sctb 8y agoWe've reverted the title from “Chrome 70 supports Web Bluetooth on Windows 10”, which breaks the guidelines by editorializing.
- emehrkay 8y agoI wonder how much of this is directly related to Google’s game streaming ambitions. Chrome, the browser, is pretty much it’s own os at this point
- Spivak 8y agoGotta say though, the OSification of browsers has been the greatest thing to happen for Linux compatibility. We can talk about efficiency and purity and integration and things but hot damn a decade ago I would have never thought I would be able to run so many apps without any sort of friction.
- cromwellian 8y agoHackerNews is starting to become less and less useful for reading tech news as of late. I come here to read stuff that's interesting in tech/science/etc, because the signal-to-noise was great. The vast majority of comments on this article are complaining about a single thing: a bluetooth API behind permissions check, and then spilling over into political arguments about what the Web should be (documents only!) and hyperbole (e.g. "i'll be bombarded by permission requests" -- lots of Web APIs can ask for permissions already like the Mic and Webcam, why isn't there an epidemic of permission spam from those, but you expect BT?) For example, if I hadn't read the link in detail, I wouldn't have even known about the Web Authentication API extension (https://developer.mozilla.org/en-US/docs/Web/API/Web_Authentication_API https://developer.mozilla.org/en-US/docs/Web/API/Web_Authent...) to the Credential Management API. Improving authentication on the Web should be an interesting topic for HN, but no one even mentioned it. The ship has sailed, we're 20+ years into this open ecosystem of ephemeral, mobile code execution, with Web Assembly poised to take it even further. We're not going back to documents-only, so either we improve the Web, it's security, performance, and capability, or we freeze in place, and hand our lives over to the App Stores of the world (the security world of native-platforms with side-load app capability isn't very impressive at this point)
- Grazester 8y agoI absolutely feel the same way and was thinking about this when I read the comments. Its like we have become old and disenchanted. We no longer see the the positive potential of an underlying piece of technology(or even the technology itself) but see ways to further exploit us.
- ravenstine 8y ago> Users can now install Desktop Progressive Web Apps on Windows & Linux! This is great, but hopefully Safari(especially on iOS) will follow suit and support PWAs. I recently wrote a PWA but changed it to use Cordova because Safari on iOS doesn't support "Add to Desktop" for PWAs. If it does, I definitely couldn't figure it out when running the latest iOS. One thing I'd like to see Google do is allow PWAs to be listed in the Play store. A lot of apps are already web views, and a PWA could be much more practical, especially if they provide some APIs to fill the gap between web and native. EDIT: Nah, I take that back. Fuck the Play store. I hope people can become comfortable with downloading PWAs directly. One of the things that held me back from releasing a PWA is the people I tested it with weren't comfortable downloading an app from a "random" website, which is pretty ridiculous seeing how easy it is to release horseshit software on the Play store.
- jf- 8y agoIt definitely does. If it’s not appearing something is wrong. A common cause is some asset being delivered over http rather than https. Actually, it should allow you to add ordinary websites to the desktop, but doesn’t display them full screen. Forgive me if this is a stupid question, but did you just not scroll right on the menu in safari? I couldn’t find it the first time I went to add a site to desktop either.
- Serow225 8y agoDoes anyone know of something like a search engine for PWAs? I'm kind of intrigued by the new desktop PWA functionality described, but I don't know how to find out which sites I can desktopify. Thanks!
- pasbesoin 8y agoabout://config (ok, chrome://config) is gone Nothing Bluetooth is in chrome://flags Google search results are their usual, these days, jumble of largely uselessness. In the context of a relatively quick search and results skimming, this result is dated 2015 but still seems to be pertinent. It is also the link that is cited in the OP's linked announcement. https://developers.google.com/web/updates/2015/07/interact-with-ble-devices-on-the-web https://developers.google.com/web/updates/2015/07/interact-w... In particular, where it says: https://developers.google.com/web/updates/2015/07/interact-with-ble-devices-on-the-web#dev_tips https://developers.google.com/web/updates/2015/07/interact-w... A "Bluetooth Internals" page is available in Chrome at chrome://bluetooth-internals so that you can inspect everything about nearby Bluetooth devices: status, services, characteristics, and descriptors. Checking the system I'm on, I'm not hooked up to any Bluetooth devices. I see the Status panel shown in the article, although it's not titled. Nothing else. There are two left-side tab-ish controls that let me switch between "Adapter" and "Devices". Devices shows the headset I was using the other week. It also has a button to "Scan". Nowhere, a browser-level control to turn this off. This is not acceptable. Google et al. are not going to stop. So, we are going to have to rewrite support for these stacks, and/or reconfigure how we run their apps and under what permissions, to cut them off. OS development (on "free" OS's, at least) is going to have to start assuming that applications the user actually wants and needs to run, can be and are at the same time at least partially hostile. Or, we just put up with this situation and being relegated to "cattle". I was just at a dairy farm the other week, and they now tag both ears -- so they don't even potentially have to take a step to identify the cow. This system uses Ubuntu 16.04, so supposedly control of this subsystem is more limited than on e.g. Windows 10. But there's no way I'm "relying" on that, all the more so going forward in time.
- favorited 8y agoMaking "Hold ⌘Q to Quit" the default on Mac is such a user-hostile change. There is no reason to deviate from the platform default that literally every other Mac app uses.