5 ms·
Show HN: CyberWeb – Building a Web Browser from Scratch on Windows 2000 [video]
- giancarlostoro 7y agoThis is awesome. I still remember asking what a/s/l meant back in the day when I started going on AOL Chatrooms (I must of been like 10). Havent heard it all that often since. One of the first things I kept wanting to do as a kid / teen was a browser. Nowadays there's so much that browsers support it's overwhelming.
- rogerclark 7y agothank you! really trying to go for the time warp aspect while attempting to be as educational as possible. happy to hear you enjoy it!
- Jaruzel 7y agoI've just sat through it whilst working on something else, and found it quite entertaining. I too have fond memories of Tumpet Windsock, and early Web Browsers (such as Mosaic). I am also a fellow believer in just opening a socket and parsing the results directly as it totally gives you more control. It was also nice to see you showing people that building for the Windows UI is not that hard. Keep going with this! I'm keen to see where you end up. Subscribed.
- Operyl 7y agoMan, I cringed when he (OP in this case) said that "it's honestly kind of insane that we require encryption for text based websites like .. let's go to Wikipedia." (Around 4m in the video). I'm sorry, but no .. it's not insane that we require that in this day and age. Otherwise, this looks pretty cool, will watch it further when I get the time. EDIT: Answering his next question: "Why does it really matter?" One reason is simple: These pages link to login and registration pages. If it's not authenticated, and can be modified over the wire, then an attacker could just redirect you to a different "login" page. TLS/SSL authenticates that what you received is what you expected, and that's very important on the internet in this day and age.
- kevingadd 7y agoHistorically tradition is to encrypt the login, registration and administration pages, which is what people have been doing for decades. Full encryption of everything has advantages but that's not it.
- Operyl 7y agoAnd then it was later found out that, like I detailed in my edit, that that wasn't enough. Attackers could just modify the login page link on any unencrypted page and phish you that way. What I described is just one of many reasons the industry as a whole pushed to full-encryption.
- andkenneth 7y agoYes, of course you encrypt those, but you also need to link any page which can link to those as well, otherwise an attacker could put a link on the page which goes to their cred harvesting page instead of the secure login page.
- AbraKdabra 7y agoI'm glad I am not the only one who stared at the monitor with my "what the hell did I just hear" face when he said that.
- rogerclark 7y agoI definitely understand the concerns that make people want encryption for everything -- preventing governments and ISPs from messing with your content or spying on you. I don't want that either, and I'm glad we have HTTPS to help fight that. But everything is a tradeoff, and there are actual downsides here. Nowadays, Chrome and Firefox try pretty hard to make you think all non-HTTPS sites are bad for you. What about old web servers that people never bothered to update? They effectively become "broken" without actually breaking. There's tons of great information on sites without updated certs that becomes that much harder to access because of this. There's also the concern about your actual codebase. Hypothetically, if you're building an HTTP client from scratch, you can write, know and understand every line of code in your project yourself. If you want HTTPS support, you're basically forced to link with OpenSSL, and this is almost guaranteed to take the total percentage of "your code" in your project from 100% to less than 10%. (Probably more like 1%.) You no longer actually know what's going on in your program anymore. Maybe this isn't a concern for most people, but it does matter to me -- and I suspect there are a lot of people who would care a bit more if they thought about it for a few seconds. So yeah, HTTPS is great. But everything is more complicated than it seems.
- amatecha 7y agoGood stuff man. As someone who's been developing for the web since 1995, I appreciate any retrospective on the platform (dare I say it) and any efforts to keep its history alive! Cheers :) I should mention that a buddy of mine hosts a site that is specifically designed to be a resource for people running old browsers [0] which links to useful stuff, discussion areas, etc. [0] http://altexxanet.org/ http://altexxanet.org/
- Jaruzel 7y agoOh! Darn it. I was 100% about to build something like this. I've even got an authentic non-intel server to run it all on. Oh well. :(
- amatecha 7y agohaha, go for it man! The more the better. It's especially nice to have a bunch of sites available when firing up an old machine that just got running again! :)
- rogerclark 7y agothis is really useful. thanks for the link -- i'll try to check this out on the next video!
- amatecha 7y agonice! while you're there you can grab KDX or Hotline and hop on his server if you want (where there are pretty much always active users)! Maximum 90's haha :) He's working on setting up a web hosting service for 90's era websites similar to GeoCities or the like, but I'm sure it'll be a while before that's all set up.
- judah 7y agoThis. Was. Awesome. I did some Windows programming in VC++6 way back in the day, and watching you do File->New [empty] Project was super nostalgic for me. And I actually learned a bunch of things watching this video. Kudos!
- kevas 7y agoYes! Thank you for posting this
- wolfspider 7y agoMany years ago I threw together a WebKit based browser with the frontend written in C# with SharpDevelop on Vista. I found myself in the MFC code pretty quickly and can appreciate the similarities between this video and that, definitely a monumental task. Mine took ~48 hrs to compile as did Safari on Windows back then. The hardest parts were getting a passing JavaScriptCore build and fiddling with IDL to get things to render via GDI using interop. Once it’s known to you how a browser works web development makes better sense. For instance in the WebKit code I found once it detected form tags it would jump to that first and then resume the rest of the markup after. In comparison with Chrome I found that Chrome would lower the resolution on all images to make things seem faster but WebKit didn’t. Nowadays modern browsers have a lot of code to make popular sites run better like YouTube that will reformat old links to their newer format like in Firefox. It’s interesting that after all Microsoft is taking this approach with Blink. To make a competitive browser nowadays it would have to pass tens of thousands of tests every build to avoid regressions: https://stackoverflow.com/questions/2933444/who-wrote-250k-tests-for-webkit https://stackoverflow.com/questions/2933444/who-wrote-250k-t...
- UIZealot 7y agoWindows 2000! You've got impeccable taste! I still use it in a VM to this day.