4 ms·
I would argue that the anti-feature is the existence of local storage. Medium is just a symptom of the underlying issue, which is that browsers do not care abou
by dependenttypes 6y ago
I would argue that the anti-feature is the existence of local storage. Medium is just a symptom of the underlying issue, which is that browsers do not care about privacy.
- siscia 6y agoI am about to implement a privacy friendly base knowledge app, and local storage is a cornerstone for doing fast full text search.
- 411111111111111 6y agoErm, how should ppl keep Frontend authentication tokens etc between refreshes without something like local storage? And how would we make offline webapps which don't store anything on servers?
- dependenttypes 6y ago> Frontend authentication tokens etc Cookies or use tls authentication. > And how would we make offline webapps which don't store anything on servers? Don't make webapps in the first place.
- Jonnax 6y agoYeah let's download desktop apps! They all have permission to upload your entire documents folder to the internet.
- dependenttypes 6y ago> They all have permission to upload your entire documents folder to the internet They do not need to, and unlike "webapps" there isn't a remote server that can change the code that you are running at any moment.
- gruez 6y agoYour response entirely fails to address the parent's concern about security. It's like responding to a RCE in your backend with "yeah it's there but we'll trust the users to not use it"
- dependenttypes 6y agoI do not understand your example. It would not be the user triggering the RCE but rather a 3rd party. In addition I do not see how it fails to address their concern.
- JimDabell 6y agoNo applications installed through the Mac App Store have permission to read your documents unless you explicitly allow that. And you can revoke that access at any time by going to System Preferences… > Security & Privacy > Privacy > Files & Folders.
- Lio 6y agoIf the choice is between a webapp and a native app the webapp is going to give users more control and a choice of the platform they want to view it on. I may be in a minority but I still want to run on desktop linux with an ad blocker or vimium. Webapps give me that. Native apps don’t.
- criddell 6y agoAn ad-blocker in the form of something like a pi-hole should work with native apps, no?
- hombre_fatal 6y agoOnly when you are connected through your pi-hole. Also, when pi-hole and mitmproxy are our only options to know what our device is doing and to block things we don't want, then we've lost. The web browser is basically the last bastion of control that we have with its devbar and networkbar and all. Blocking content/requests is something our devices should be able to do themselves. It's a miracle of history that we have the browser, and it's hard to imagine us having it had it been invented today. We need to fight to keep it, not dismiss it with "ugh web tech amirite?" while we regress to native app black boxes as our only option.
- criddell 6y agoA pi hole protects your whole network. What you are asking for sounds more like a traditional firewall that I think every computer still supports.
- dependenttypes 6y ago> the webapp is going to give users more control You can't modify the webapp nor can you refuse to update it.
- Lio 6y agoOf course you can modify the webapp. You are running the source code in your browser. Even if it’s minimised you can still modify it.
- hombre_fatal 6y agoNo, I think the anti-feature is that browsers don't give users good tools to see when things are being stored in storage (cookies, localstorage, etc.), what is being stored, whether it should be stored, and when it should expire. I think this stuff should have a first-class UI component in 2020, not be hidden away in a submenu in the devbar that's frankly even annoying to deal with as a developer. By pitching cookies only, you're saying that websites should only be able to store stuff that the browser should have to reflect back to the server through http headers. I don't think the constraint makes sense beyond wasting bandwidth for settings that should stay local. Just look at this HN submission. We shouldn't need an HN submission to know this about the websites we visit. Browsers are failing us here. If a website is abusing our localstorage like this, it should be obvious (for the people who care). As it currently stands, browsers enable bad actors to do bad things silently with zero consequence beyond the few nerds who happen to notice it. As an example, I'm reminded of the new iOS feature(?) that shows when the clipboard is being accessed which spurred a bunch of "wtf is $app doing with my clipboard?" last month. That's what I think setting cookies and localStorage should be like. Or at least a way to opt in to that behavior without throwing the baby out with "disable localstorage".
- Santosh83 6y agoYup, you're on the money here. In fact browsers should make accessing the data stored by sites and modifying their permissions drop-dead intuitive, even for non-tech users and those with more knowledge should be afforded further knobs to tweak. This kind of UI might be a bit hard to design and require some thought, but I think it is quite possible, and I find it surprising that even after all these years, the dialogues and preferences dealing with examining and controlling the storage and execution of websites and apps to be poorly thought out, obscure and very clunky. I can understand why Chrome might not want to improve in this regard as its parent company's interests directly conflict with more user control of web data, but amazingly, if anything, Firefox's settings for auditing and restricting websites is even worse. And none of the browsers, AFAIK, have taken the initiative in this area and tried to really differentiate themselves. I suspect they think no one except a few tech users will be interested in these knobs, but the thing is, if you make them prominent, easy to use, understand and intuitive, I bet a lot more people will start using them.