11 ms·
Show HN: Open-source isolated browser, free for journalists etc.
- tarulahsan 6y agoWould love to give it a try
- win66 6y agoLIve demo up now: https://start.cloudbrowser.xyz https://start.cloudbrowser.xyz
- Shared404 6y agoSuper cool looking, and a great idea. > Get and self-host This seems like it kind of defeats the purpose though. Is this section just to prove that it can be done? edit: This was not meant to be rude. I was just asking if there is another reason. The reason I listed is more than enough, I was just wanting to learn more.
- luckylion 6y agoI don't think it defeats the purpose. It's not meant to make you anonymous, it's meant to shield your actual computer from exploits. It can do that just fine running on a VPS you rent.
- Shared404 6y agoAaannnddd... I now feel stupid. I should've realized that, I've definitely studied enough. Thanks for taking the time to explain it to my slow self.
- dylz 6y agoI am slightly concerned that it's being advertised as security software, but the commit log looks incredibly... unpolished and uncared for, to say the least.
- mr__y 6y agoDepends on the motivation to use - self-hosted option is of course bad for privacy, but still good for security - you could use a browser running on a separate machine, effectively making it a physically isolated sandbox
- Shared404 6y agoAn excellent reason. I feel stupid now, I should've recognized that.
- DyslexicAtheist 6y ago> self-hosted option is of course bad for privacy, but still good for security there are plenty of anonymous hosting services out there in which case it would be exactly the opposite: "good for privacy, bad for security"
- mr__y 6y agothat's a valid point as well. This pretty much results in a privacy vs security choice, you either run it in infrastructure you fully control at the loss of privacy or some anonymous service, where you could have privacy but loosing the security. Although one could argue that using an anonymous hosting service, there's still a risk that whoever is running that infrastructure could monitor your activity meaning that effectively you have neither privacy nor security.
- bernardlunn 6y agoWhat do you mean by isolated browser? What is use case?
- Shared404 6y agoWebpage -> Remote server running "isolated browser" -> Local Browser Use case is to protect security by not allowing any arbitrary website code to run on your local browser, the remote actually renders the webpage and just sends you pixels -- I think. Kind of like a proxy on steroids.
- Andrew_nenakhov 6y agoSound more like MitM on steroids.
- Shared404 6y agoThus the self hosted option I was so confused about before.
- oefrha 6y agoThis will definitely be brought up, so why not from me: this is not open source by Open Source Definition standards.[1] You're free to sell your builds as commercial, but if I can't compile the source code myself and use it at my workplace (assuming I'm not a journalist or any other type of listed free-to-use professional) then you're discriminating against fields of endeavor. [1] https://opensource.org/osd https://opensource.org/osd
- tannhaeuser 6y agoFlagging this as harrassment. I'm sick of self-proclaimed "orgs" (with unclear sponsorship) or SJWs claiming ownership of commonly used terms. OSI: speak for yourself! You in no way represent or help developers, and have no standing as an organization to decide which licensing terms someone puts on his/her work. In fact, your continued insistence on the laughable dogmatic "four freedoms" is what's helping to enslave people into platforms made from 99% open source, with only a tiny web wrapper. All the while development work gets no funding. Time to move on!
- oefrha 6y agoReplying to a now flagged and dead comment, as it's a common sentiment expressed in a rude way, and the sentiment deserves a reply: > I'm sick of self-proclaimed "orgs" (with unclear sponsorship) or SJWs claiming ownership of commonly used terms. This is revisionist history. OSI was formed and OSD was published in February 1998 immediately after the term "open source" was proposed, and OSD was largely based on Debian Free Software Guidelines which predates the term.[1][2] So the term only became popular after the "self-proclaimed org" formed and popularized it. The OSD clearly predates any so-called open source abuse, and AFAIK it was never revised due to some sort of corporate sponsorship. You can coin your own term and try to popularize it. FSF has their free software (well, that's actually a weak claim on a broad term) and libre software (much better). You can also get behind some weird term like "Open Source with Commons Clause", or just use another commonly used term, "source available" (which, granted, spans a pretty wide range on the restrictiveness spectrum, so definitely not ideal). Meanwhile, many of us get annoyed when commercial products try to reap the marketing benefits of open source but does not grant the rights we've come to expect from the term. This particular case isn't even subtle like the Commons Clause. [1] https://opensource.org/history https://opensource.org/history [2] https://en.wikipedia.org/wiki/History_of_free_and_open-source_software#The_launch_of_Open_Source https://en.wikipedia.org/wiki/History_of_free_and_open-sourc...
- gitgud 6y agoSo it's a browser within your browser running on a remote machine somewhere? At first glance it seems needlessly complicated, but modern browser finger-printing is also incredibly complex. So this might be better than a VPN... As both the IP and the browser are proxied
- mr__y 6y agoWith https over VPN, at least the vpn provider cannot inspect the contents of your traffic. With a browser running on a remote machine, whoever controlls that machine can. This is better than VPN only in a scenario when you either controll that machine or fully trust the provider
- Wowfunhappy 6y agoI assumed it was more for security than privacy. Run the Javascript remotely so your own machine will be (or at least, is more likely to be) be protected from zero-days.
- chirau 6y agoWhat exactly is this? I am not sure I get its purpose either. Am I just opening a browser on a VM somewhere?
- techntoke 6y agoHere is an open source way to do this yourself: # Dockerfile FROM node:alpine3.12 RUN apk add --no-cache chromium \ && yarn add puppeteer-core \ && apk add \ --no-cache \ --repository http://dl-cdn.alpinelinux.org/alpine/edge/testing \ novnc
- win66 6y agoThis is really cool, I'm just building an image now. Excited to try it out. One small error is I think you are missing a '\' from the end of line 7 (repository flag) edit: I just got this error trying to build an image. Any idea what's wrong or how to fix it? ERROR: unsatisfiable constraints: novnc (missing): required by: world[novnc] The command '/bin/sh -c apk add --no-cache chromium && yarn add puppeteer-core && apk add --no-cache --repository http://dl-cdn.alpinelinux.org/alpine/edge/main novnc' returned a non-zero code: 1 I would super like to try this out! :)
- techntoke 6y agoThanks! It looks like the novnc package is in testing, not main: http://dl-cdn.alpinelinux.org/alpine/edge/testing http://dl-cdn.alpinelinux.org/alpine/edge/testing Please note I did oversimplify this a bit. You'll still need something like WayVNC, but it doesn't have WebSocket support yet. You can track it here: https://github.com/any1/neatvnc/issues/2 https://github.com/any1/neatvnc/issues/2 In the meantime, you should be able to use websockify (there is an alpine package already). For a simple app, I'd recommend cage which is a kiosk wayland WM for a single app: https://pkgs.alpinelinux.org/package/edge/community/x86_64/cage https://pkgs.alpinelinux.org/package/edge/community/x86_64/c... Here is an example for Sway that you could use for Cage as well: https://github.com/any1/wayvnc/blob/master/FAQ.md https://github.com/any1/wayvnc/blob/master/FAQ.md
- win66 6y agoWow, you really nailed it! Thanks, I'm definitely going to build this :)
- Fnoord 6y agoOn the live demo, ipleak.net detected my actual OS, resolution, and browser which I used to run the live demo.
- win66 6y agoIt passes through your navigator.platform, userAgent and screen dimensions, from the client you connect with. But this is not necessarily the actual values of the machine you run it on. So the site you're browsing thinks it is talking to a browser on, say, an Android phone, but actually it is (in the live demo anyway) talking to a browser running in a virtual Debian instance in GCP. For fun, check out your geolocation. That is not passed through
- enriquto 6y ago> Sure, other companies might have bigger brands and bigger sales budgets, but this is open-source. No, it's not. They are delibetarely misusing a well-established term and they deserve to be called out for that. This is extremely antagonizing and it is impossible to take the rest of the project seriously when it is presented that way. The same thing happened when zoom said that their program did "end-to-end encryption", while it didn't; it was a great project, but tainted by a callous and misleading usage of terminology.
- js4ever 6y agoSuper cool, I have just tested with YouTube and it's allowing background audio playback on mobile because the video continue to play on the server. Audio is playing on my phone with a 3 sec latency but without hiccups and good enough quality.
- win66 6y agoThank you :) I thought that would be a cool use case for people (what with free YouTube not letting you play in the background) but I couldn't find a way to get lots of people using it. Feel free to share the word about the free demo.