11 ms·
This is how the Web was originally designed, which is why we had Flash and Java applets. But it's hard to make those VMs secure, and yet somehow it's been easie
by ar-nelson 7y ago
This is how the Web was originally designed, which is why we had Flash and Java applets. But it's hard to make those VMs secure, and yet somehow it's been easier to keep modern browsers reasonably secure as they keep adding features.
- anderspitman 7y agoOne problem is that browser vendors are using the complexity of modern browsers to create an oligopoly. When even Microsoft doesn't want to maintain their own browser, something is wrong. A simple browser that only implemented a subset of HTML and the good parts of CSS (ie flexbox) could be implemented easily by a small team.
- api 7y agoThe driver is the desire by web app builders to build more and more niftiness into web apps. The browser vendors and standards bodies are attempting to satisfy this desire and that's leading down a path that is having the effect of creating an oligopoly because a browser must become this enormous OS-inside-an-OS. I don't think it's a conspiracy. Most things that look like conspiracies are in fact unplanned outcomes that result from an unintentional alignment of multiple perverse incentives. A different way of saying the same is that most things that appear to be conspiracies are actually "emergent" behaviors in complex systems. A different example of something similar is real estate hyperinflation. I don't think somebody sat down and said "lets make housing impossible for any family making less than 5X the local median income to reasonably afford." What happened instead was that multiple decisions made for independent and unrelated reasons created an aligned set of perverse incentives that drove the price of housing nuts. There is no one cause or one responsible party.
- redwall_hp 7y agoFlash reached a point where it was basically unmaintainable spaghetti, and not something that was going to be trivially reimplemented by a third party. Sadly, that's exactly what's happening to the Web now. Instead of being standards-first, and browsers implement it, we've basically shifted to descriptive standards that attempt to formalize what a corporate cabal unilaterally decides. And we're in inch away from a homogeny of browser engines...
- bawolff 7y agoWell multilaterally decide. Its a small group but firefox isnt totally irrelavent yet. And thats ok in my opinion. The IETF describes itself as "rough consensus and running code" and it seems to work well. I dont have a problem with the web following that model.
- anderspitman 7y agoYou're not wrong, but people have been pointing these issues out for years, and browser vendors are very aware of these opinions, and have taken no serious action I can see to realign their incentives. EDIT: But that can also be explained by incentives+emergent behavior. So at the end of the day, you're simply correct.
- thu2111 7y agoThere's no mystery to it. Look at Firefox. It's actually not more secure than old Java used to be. It has CVEs all the time. Chrome constantly patches security bugs too. The difference is they have much more aggressive automatic upgrade processes than Flash or Java did, so bugs remain usable for way less time. And Chrome did sandboxing. But Firefox doesn't/didn't. It got a free pass from the community because Mozilla is somehow seen as "not a corporation" and did a lot of drum beating about openess/webbyness/etc. So people gave it a break although the architecture wasn't really any different to something like Java applets and if anything was much worse.