12 ms·
User Agent Changes
- pornel 7y agoCongratulations Google, you did it! You killed the User-Agent header. The HTML spec already requires all browsers to report themselves as Netscape in the Netscape-era `navigator` object: appCodeName - Must return the string "Mozilla". appName - Must return the string "Netscape". product - Must return the string "Gecko". So a few more "oopses" from Google products and the next spec will end up saying: User-Agent - Must be equal to the string "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79"
- chrismorgan 7y agoFor reference, https://html.spec.whatwg.org/multipage/system-state.html#client-identification https://html.spec.whatwg.org/multipage/system-state.html#cli.... Browsers are essentially required to pretend to be Firefox from 2010, or Chrome from 2003 (!), or Safari from 2003—all while pretending to be Firefox or its predecessor in a couple of other ways. I find it very amusing.
- naniwaduni 7y agoSome context: 20030107 is Safari's first public release date.
- kccqzy 7y agoChrome didn't exist in 2003. The year 2003 is because Safari existed then, but Google forked WebKit later on.
- bryanrasmussen 7y agothis reads like an April 1st spec, "The taintEnabled() method must return false" - hur hur hur.
- bowmessage 7y agoInteresting perspective; one could argue that the creators of non-web-standards-compliant browsers are really to blame here, forcing webdevs to branch / gate so often on the UA header. Agreed that it is really becoming dead, though.
- gbear605 7y agoThe whole point of the article is that a number of sites (Google, Facebook, Netflix) are returning invalid sites because the browser is Vivaldi, not to make the site work with Vivaldi, but to make Vivaldi not work. It’s entirely the developer’s fault, not the browser’s.
- bowmessage 7y agoSure, but developers were forced down this path due to IE6 et. al. not respecting an open-standards-compliant grammar for HTML, JS, etc.
- GoblinSlayer 7y agoWhat you can't do on IE6 without user agent sniffing?
- TylerE 7y agoAs soon as you trust the client, it's game over. Period.
- eru 7y agoThere's more than one kind of trust. You should totally trust your client to show stuff to the user. And you can generally trust your client when giving you user data, in the sense that you can trust that the data came from the user. (Unless the client is hacked by third-parties or buggy.) Basically, you can trust your client as much as you can trust your user. Not more.
- ErikAugust 7y agoObligatory: https://groups.google.com/forum/m/#!msg/comp.lang.java/aSPAJO05LIU/ushhUIQQ-ogJ https://groups.google.com/forum/m/#!msg/comp.lang.java/aSPAJ...
- stickfigure 7y agothe next spec will end up saying...Must be equal to the string... This is exactly the right way to solve the problem. The UA header isn't going away because of Legacy. Pin it to an arbitrary generally accepted value and be done with it. The best part about this is that any client-side developer can implement this solution unilaterally... and Vivaldi now has.
- stephenr 7y agoAssuming that the problem here is people doing UA sniffing, the problem, like with people doing glue sniffing, is to stop people sniffing the UA (or glue) - not to make the UA (or glue) unusable for it's intended purpose. Have you ever used a service that shows things like your active sessions, login attempts etc? Notice how they basically all show you what kind of device and usually what browser the session/login is from, with a date time and usually location? If everyone pretends to be Chrome what's the fucking point any more? "You logged in from Chrome on Tuesday the 3rd at 8am". "Well no I fucking didn't, I guess I better go reset my damn passwords again".
- denormalfloat 7y agoThere are wrong reasons to sniff the UA string, and less wrong reasons. If a Browser has a bug that gets fixed in later versions, sites have to sniff the UA string to do the right thing. For example, a browser bug may cause people to see an error, and the they are using an old version of the browser. The right thing to do is to upgrade, but how to tell? When you are subject to the bugs of some other code, and which are skewed across different versions of the software, the most reasonable way to work around it is by UA sniffing.
- zeta0134 7y agoI would have bought this argument a decade ago, but at this stage the number of site users not doing some form of automatic updates on their browser should be in the minority. The problems user agents were designed to solve back in the Netscape Navigator days have since been standardized using much better signals, and the odd standards compliance bug here and there isn't really justification for something as weak and unreliable as a user agent string. I say kill it. Fix it to some static value and require new sites moving forward to do proper feature detection if they really care to work around standards bugs or use experimental new features.
- cowmoo728 7y agoCan we take a moment to appreciate how obtuse UA strings are? I mean really, the user agent Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.99 Safari/537.36 Vivaldi/2.9.1705.41 is almost laughable for a strange collection of historical reasons. The history of UA strings has come up before here: https://news.ycombinator.com/item?id=16525559 https://news.ycombinator.com/item?id=16525559 When is a browser going to just ditch the cruft and present something sensible?
- naniwaduni 7y agoLet's take a look at Firefox! Mozilla/5.0 (X11; Linux x86_64; rv:71.0) Gecko/20100101 Firefox/71.0 Only, er, half of the version numbers are lies...
- NullPrefix 7y agoAre you on Wayland?
- JoshTriplett 7y agoI wonder if it'd be too late for http/3 to say "user-agent is deprecated, user-agents should not send it, any server accepting http/3 may assume the following compatibility value for the header without it being sent". Was anything like that considered during the http/3 design process? (I saw the linked "client hints" proposal in the article, but that doesn't mention the idea of completely dropping the header from client requests and assuming a certain baseline value for http/3.)
- toast0 7y agoUser-Agent for browsers is pretty much useless now, but it's still a pretty useful name for a header if you want to put real information in it. Ex, if you're calling an api, it's nice to have a version number and a name/contact so broken things can be fixed. I don't remember if HTTP/2 (and presumably /3) has a initial dictionary for header compression, they could have a suggested value in there, so if you want to look like a browser, you can use that at a low byte cost.
- ravenstine 7y agoThe user-agent header was a huge mistake.
- stephenr 7y agoNot at all. Being able to vaguely confirm the type of device someone uses can help in basic troubleshooting (particularly related to e.g. noticing unauthorised account access). Using the user agent string to identify web technology compatibility was and is a huge mistake.
- chrisweekly 7y agoNo mention of the UA string would be complete without this 2008 gem, one of my all-time favorite bits of geek lore / culture: https://webaim.org/blog/user-agent-string-history/ https://webaim.org/blog/user-agent-string-history/
- tyingq 7y agoI wonder if they debated whether to imitate Safari or Mozilla or Edge instead.
- zlsa 7y agoVivaldi is based on Chromium, so it's best to imitate the same engine. * Yes, I know that Edge is now based on Chromium. But given the two, it's better to pretend to be your parent browser, rather than a sibling.
- deleted 7y ago[deleted]
- dredmorbius 7y agoEverybody lies: https://noti.st/nielsleenheer/73y43P/slides https://noti.st/nielsleenheer/73y43P/slides
- thrower123 7y agoThis is indicative of the kind of world where we had to jump from Window 8 to Windows 10 because of shitty user-agent parsing .
- Aloha 7y agoThis is more of an asking the assembled a question.. why should I use vivaldi?
- recursivecaveat 7y agoI've been a Vivaldi user for over a year now. Mostly I just prefer the UI. You have a lot of options, especially compared to Chrome's almost zero. In particular I like to have the tabs stacked vertically along the side, so they're more manageable in quantity. Otherwise, its just Chromium, so my only complaint is the tendency for sites to nag/scare you about using an 'outdated' browser. Occasionally Youtube will temporarily break their UI in some minor, Vivaldi-only way, but otherwise I've never been blocked or had a functional problem with a site.
- alwillis 7y agoI love the UI/UX of Vivaldi. I use Brave a lot when I'm using a Chromium-based browser; perhaps when the SDK comes out, Vivaldi will integrate BAT [1]. It would also be nice if Vivaldi got Brave's features like built-in Tor and IPFS. [1]: https://www.cnet.com/news/braves-privacy-focused-ads-to-spread-beyond-startups-own-browser/ https://www.cnet.com/news/braves-privacy-focused-ads-to-spre...
- Scoundreller 7y agoHeh, I remember my university wouldn’t let you login to wifi without having their site-licensed anti-malware software. So I changed my UA to a Mac and got online without it.
- bullen 7y agoUser-Agent should be able to be set by the page following the spec. there is a chromium bug since 2015 that covers it but Google doesn't care: https://bugs.chromium.org/p/chromium/issues/detail?id=571722 https://bugs.chromium.org/p/chromium/issues/detail?id=571722 which is blocked by https://bugs.chromium.org/p/chromium/issues/detail?id=595993 https://bugs.chromium.org/p/chromium/issues/detail?id=595993 which is blocked by https://bugs.chromium.org/p/chromium/issues/detail?id=963260 https://bugs.chromium.org/p/chromium/issues/detail?id=963260
- Thorrez 7y agoFixing that won't help any of the problems listed in the post. Also it wouldn't set the User-Agent on top level page loads, just on XHRs/fetches.
- bullen 7y agoTrue, but it's more important since XHR/Fetch can be used for real-time data!
- Thorrez 7y agoI don't understand why real-time data is more important than the initial page load. XHR/Fetch can only read data from the same origin (unless there are CORS headers allowing cross-origin). AIUI, since it's generally the same origin, there generally shouldn't be any User-Agent problems, because the team making the calls is the same team controlling the server-side code. So spoofing a different User-Agent for compatibility shouldn't be necessary.
- bullen 7y agoBecause if you use HTTP for real-time stuff and you make say 10 requests per second and you can't remove the User-Agent header which is like 100+ bytes long that makes for a lot of bytes per month (if you have 1000 users): "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" 114x10x60x60x24x30x1000 = 3TB/month Edit: but now that I checked ingress data is free on all cloud operators! What?
- fouc 7y agoDoes anyone think that User Agent should be killed off? If we had no way of detecting between browsers that would lead to a much more consistent cross-browser experience in the long run and not allow one browser's dominance to affect the internet experience for the rest.
- thayne 7y agoIt also removes some legitimate use cases including: - identifying active sessions - working around bugs in specific versions of a browser/os - changing UI to match the native experience of a user - seeing percentage of users using different browsers (which is important to know if you can use new features in web apis) - etc.
- forgotmypwd123 7y agoWeb pages should not work around browser bugs, its like a linux distro working around kernel bugs. Just fucking fix it.
- namibj 7y agoYeah, it's called polyfills. It's bloat when not needed.
- WhyNotHugo 7y agoYup, it should be killed off. First step would be for all browsers to send the same UA. Once it becomes completely meaningless, nobody will read it any more and we can drop it permanently.
- boring_twenties 7y agoI'm surprised Slack isn't on the list, it refuses to work with Waterfox at least (which only appends its name to the Firefox user agent it's based on), and presents a stupid and condescending lecture about why it's for your own good, to boot.
- chrismmay 7y agoI have seen a few cases where users complain that our mobile app (which runs in a webview inside a native app) doesn't work for them. When we look in the server logs, we find a user agent string that indicates a user is running iOS 11.4.1. My theory is that the older version indicates that the client's mobile device has run out of storage space. The device can't download the update to iOS 13.x since there is insufficient storage available on the device. Even if the user frees-up some space on their device, not enough to upgrade to iOS 13.x, but enough to run our app theoretically, our app still fails to run for them. Uninstalling and reinstalling the native app that contains the webview that runs our web app doesn't solve the problem either. My theory is that there are truncated versions of some of our javascript files left over from when the device ran out of storage that don't get re-downloaded even when storage is later made available.... I've been telling people to free-up space on their device and upgrade it to iOS 13 to fix the problem. I sure hope that works... If all user agents become a fixed string, how on god's green earth will we troubleshoot problems reported by users? I sure hope we get another header that will tell us the real client platform information so we can eventually repeat this exercise after another few years... This scenario is complicated, but my point is really that of course we need a User Agent to accurately tell what platform the client is running for entirely legitimate reasons and mega corporations should not do patently evil things to make the lives of developers and support people even more frustrating than they already are. There should be laws against things like this. It really is fraud to change something like the User Agent string to a constant value that is incorrect, and it WILL lead to damaging events in real people's lives if it happens. People could be fired for being led down the wrong investigative path when troubleshooting problems. From the article, it sounds like significant damage has already been done.
- ec109685 7y agoI am surprised clearing the cache doesn’t remove these lingering files, given their remnants would be a privacy problem.
- chrismmay 7y agoThis is a webview embedded in a native app that we don't control, not a web browser. No, clearing the cache in Safari doesn't help. This stackoverflow https://stackoverflow.com/questions/5468553/clearing-uiwebview-cache https://stackoverflow.com/questions/5468553/clearing-uiwebvi... says you can write some native code to clear the cache, but we don't control the native app, we control the web app that runs in the webview. We will report the problem to the native app developer, but hopefully the user can just free-up space and upgrade their iOS in the meantime.
- Dolores12 7y agoThat is so bad idea. Why choose Chrome? Let it be Firefox? Web analytics will show even higher numbers for Chrome, hence developers would not bother to test anywhere but in Chrome.
- fantyoon 7y agoPretty sure Google is already attacking Firefox in the same way. I remember having to change my User-Agent to Chrome on Firefox mobil because a bunch of Google sites where broken otherwise (but worked perfectly fine when thinking that I was using Chrome). If your only goal is compatibility and thats the only thing you care about, using Chrome is the choice.
- agluszak 7y agoOh, these sweet monopolistic practices...
- bambax 7y ago> Every other site will get a User Agent that appears to be identical to Chrome. There is a downside for us in doing this since Vivaldi will effectively disappear from third party rankings of browser popularity (we will be indistinguishable from Chrome) but that is a price we will happily pay to provide the best website compatibility for our users. Why not choose a FF UA string then? At least they would be doing the world a favor!!
- tsukurimashou 7y agoWell they didn't say it clearly but they chose chrome because a lot of people use google products, and their browser will work best if they pretend to be chrome, it is that simple. Firefox has the same issues they describe in the article, google throttle perfs and break things on purpose for Firefox (gmail features, youtube features, maps, etc...).
- pgcj_poster 7y agoProbably because Vivaldi is based on Chromium.
- 3xblah 7y agoComments here on User-Agent fail to mention how browsers can be distinguished by the headers they send and the ordering of those headers. For example, the User-Agent header might be the 9th header in a Chrome browser while in a Firefox browser it might be the 2nd header. By default, neither Chrome nor Firefox may send exactly the same number of headers.
- hiruxxy 7y agohttps://www.helathlktip.club/2019/12/how-to-weight-loss.html?m=1 https://www.helathlktip.club/2019/12/how-to-weight-loss.html...
- dependenttypes 7y agoThe question is, why ever use a unique user agent?
- dethos 7y agoGood move. Other browsers should follow.
- Tepix 7y agoI think they went exactly in the wrong direction. Given that they have a very small market share it is understandable. However, what if the latest Firefox or Chrome would just have a user string "Chrome/80.0 (Windows 10; Win64; x64)"? And if you run into a problem you get a button that reverts to the old horrible piece of junk. Now that robots.txt is established and security.txt is almost there, the next thing we need is a contact.txt that browsers can use to offer a button that will allow sending bug reports to webmasters without having to search the site for the contact address.
- onreact 7y agoNah, just prevent dominant corporations like Google to use anti-competitive blocking or redirecting measures. Vivaldi has to mimic Chrome because otherwise Google throws errors. It's not that Google is unaware that there are browsers or that Vivaldi is not Chrome.