5 ms·
Web browsers became what operating systems were 20 years ago.
by salamander014 7y ago
Web browsers became what operating systems were 20 years ago.
- AgentME 7y agoBut with great security sandboxing by default, with multiple interoperable open-source implementations, built on open standards, and cross-platform and not bound to any specific machine architecture. Imagine downloading dozens of different unsandboxed apps every single day on a classic operating system. You'd get so many viruses (and just broken software that breaks or slows down your system) doing that. But now we can do that safely in browsers with (web) apps. That's amazing.
- jfkebwjsbx 7y ago> But with great security sandboxing by default, with multiple interoperable open-source implementations, built on open standards, and cross-platform and not bound to any specific machine architecture. All that applies to operating systems and has been like that for decades. > You'd get so many viruses (and just broken software that breaks or slows down your system) doing that. That is simply false, and if you can prove it, there is recognition/money waiting for you. > But now we can do that safely in browsers with (web) apps. No, bugs are still a thing the same way they are for operating systems.
- untog 7y ago> All that applies to operating systems and has been like that for decades. Windows has had "great security sandboxing" for "decades"? Are you sure about that?
- jfkebwjsbx 7y agoWho has talked about Windows? Anyway, Windows has had a proper kernel since Windows NT, 20 years ago.
- AgentME 7y agoWhat operating systems are you talking about? I'm considering popular operating systems as they're used by end users that are downloading and running applications on their own machines, and I was mostly considering ones that existed 20 years ago. I'm not thinking just of what the OS's kernel technically supports, but the full experience of how it guides users to use it. All of my points go for Windows, MacOS (with apps downloaded outside of the app store), and desktop Linux, and half of my points still apply to modern mobile operating systems (iOS and Android). If you told an arbitrary Windows user to try a game/app you made, and you link them an EXE file, then at a surely 99%+ chance, if they run it, they're going to do it in the default unsandboxed way that exposes their files on the computer to the executable, and gives your executable the chance to hook itself in persistently on their system. It may be technically possible to safely sandbox arbitrary applications from accessing all your user files in Windows by using special tools or by creating a user account per app, but the operating system does not guide users to do that, there's a ton of gotchas, and basically no one does that. I feel pretty confident labelling that as not "great security sandboxing by default". >>But with great security sandboxing by default, with multiple interoperable open-source implementations, built on open standards, and cross-platform and not bound to any specific machine architecture. >All that applies to operating systems and has been like that for decades. Android is the only OS I can think of that almost ticks all of those boxes, but it still falls short. There aren't multiple separate popular/well-supported implementations of it. Its code is open, but by "open standards" I was referring to the whole decentralized standards process the web has; in Android, Google adds, deprecates, and discontinues APIs without any outside input. In the web, browsers generally only introduce browser-specific APIs in the short term and work towards unifying their APIs with other browsers. It's super rare for anything that makes it through the standards process to ever be removed; browsers prize backwards compatibility of standardized features far more than any comparable platform. Android apps generally aren't usable on non-Android devices; if you point an arbitrary Windows user or an iPhone user at an Android app, they won't be able to run it, at least not without some special expertise.
- jfkebwjsbx 7y agoSo you are changing goal posts now into the "user experience" (or something like that). It was never a design goal of operating systems to assume a binary that you yourself ask to run is malicious. That makes no sense at all. And that is still the case nowadays. It is the "Web" that brought us the "amazing", truly wonderful idea of running non-signed code on the fly. And, in Web's wisdom, instead of properly implementing sandboxing and using the operating system facilities for that, browser vendors decided to do a half-assed job. Then they realized how a bad idea that was (shocking!), and they have been patching holes of all kinds since then (and reimplement everything that was already there in operating systems, too). The last bits are the WebAssembly and WebGPU wonders. And no, I was not talking Android. At all. If you study computing history, you will realize "decentralized standards" and "several implementations" are not something that first appeared with the "Web". We are talking the 80s here. Even earlier for some stuff. So, please, if you have not studied the past, then do not claim what you know is the beginning of everything.