6 ms·
> I personally think we should abolish JavaScript and not allow arbitrary remotely loaded code to execute on our computers. > "I want web sites to do everythin
by Permit 5y ago
> I personally think we should abolish JavaScript and not allow arbitrary remotely loaded code to execute on our computers.
> "I want web sites to do everything a native app can do" is a suicidal mistake.
If you think you're ceding a lot of power to Google and Apple when it comes to browsers, I fail to see how "That webapp you're building can't use Javascript so build it in Objective-C/Swift for iOS instead" would cede less power to Apple.
At least I don't need Apple's approval to build my website...
- madeofpalk 5y agoI also fail to understand how "lets install native code to run on our OS" results in more security and privacy. The browser is inherently more locked down than native apps. A Facebook app on your computer can read anything on it without any pesky browser security and privacy features getting in the way.
- fnordsensei 5y agoThe Twitter thread isn’t discussing security or privacy. It’s discussing who (effectively) controls web standards right now, and who should do so in the future.
- threeseed 5y ago> A Facebook app on your computer can read anything on it without any pesky browser security and privacy features getting in the way This is not true, at least on OSX. It will ask the user to confirm whether the app is allowed to read/write to key locations e.g. Documents, Photos as well as access key sources of data e.g. Contacts.
- smorgusofborg 5y agoThat just leads to decision exhausted users saying yes by accident. Traditional browser policy errs more on the side of not making things that are too often dangerous especially if they are rarely beneficial over safer flows. Trying to make progressive web apps do whatever an app can do is basically being bug for bug compatible with bad ideas that sound "convenient".
- murukesh_s 5y ago>decision exhausted users saying yes by accident true this. day before yesterday, i had a webapp ask camera and mic permission and after giving yes to both got a third dialog immediately - i read it but gave yes accidentally before realizing it was permission for push notification - such a dark patterns can be used for exploiting users.
- solarengineer 5y agoUnlike on iOS, we are unable to determine access per app at a file level on MacOS (OSX). The permissions are at a folder level. Thus, if we give access to the Documents folder today and then pick a single file, the app is actually free to scour the Documents folder and act on its own (scan the meta data of all the files, upload all the files somewhere, for e.g.)
- deleted 5y ago[deleted]
- 1vuio0pswjnm7 5y agoNo need to even go this far. Just have Javascript as an option, not a default. People seem to have lost sight of the fact that the web was and still is functional without all the added browser features. By all means, have the features, but making them defaults is something very different. It is denying the more basic functionality of the web. In some (read: many) cases, using the web in a more basic way without certain features reduces the amount of risk a user undertakes. Sometimes it is just plain faster and more reliable, too. This developer-dictated "defaults" strategy is developer-friendly but user-hostile; it's why we end up with power users commenting on HN along the lines of "I can't turn off X, because then all sites will break." Most users (non-power users) cannot even turn off X because they do not even know they can. They haven't got a clue. Developers like it this way. This is some highly manipulative maneuvering; this is unethical IMO, but I think like a user not a developer. Defaults are definitive. Perhaps that's why the current CEO of Google, before he became CEO, worked so intently to get vendors to make Google the "default search engine". Users do not change these defaults.
- enriquto 5y ago> Just have Javascript as an option, not a default. This is already the case, isn't it? You can easily disable js for good, and then enable it as needed on a per-site basis.
- SkeuomorphicBee 5y agoIt hasn't been the case for some time now. JS started as something to spice up the html content, to add extra niceties. But The rise of virtual Dom JS rendering Frameworks brought upon pages that don't have any html content, that don't display anything without JS, Just a Blanc page. For some time adopters of such Frameworks would keep a limited functionality noscript page, but it didn't take long for them to drop the extra work. The highest profile website following this theme is Twitter, the dropped noscript a year ago. So JS is not optional anymore, to browse the full web you need JS, without it you get a subset that doesn't include some major social networks or some major news sites.
- 5y ago
- danjac 5y ago"Apple has too much control over the web, so let's build native apps in Apple's walled garden" is not exactly the most persuasive argument.
- tehbeard 5y agoDon't forget to pay your apple tax (TM) on the hardware to actually build said native apps. And your yearly tribute to the apple app store so they flip a coin as to whether your app is listed or removed.
- jensensbutton 5y agoAgree. I can see why a Mac/iOS developer might feel that way though.
- zepto 5y agoThe author never says that - you are misrepresenting them. They are against the walled garden.
- username90 5y agoBut removing javascript from browsers will just make more walled gardens. Browsers are not walled gardens, unless your OS prevents you from installing other browsers (see iphones...). It doesn't matter what you say you support if the consequences of what you do hurts that goal.
- zepto 5y ago> But removing javascript from browsers will just make more walled gardens What new walled gardens do you think would be created if JavaScript was removed from browsers?
- MisterSandman 5y agoA walled garden for every OS. MacOS and iOS apps will need to be written in Swift, so you better hope all devs know Swift and have Macs to write code in. Windows Apps will need to be written in... uh, C#? Good like finding as many devs for that as there are currently for JS.
- whywhywhywhy 5y agoI think more effort should be put into cross browser support, but that said. > "I want web sites to do everything a native app can do" is a suicidal mistake. Most Mac users are just using MacOS as a windowing system to run Chromes browser engines multiple times across the bunch of Electron apps they use to do their work. The age where Mac users were mostly working all day in native Cocoa apps is long dead, I think I might be the only person in my office that uses a text editor running on Cocoa not Chrome. We didn't get here by accident, end of the day Figma is better than Sketch, Google Docs is better than passing Pages files around, Google Maps in a browser window where your actual research is happening is better than opening the Apple Maps app and Slack is better for work than Messages. The world moved forward, Jeff might not like which tech stack it chose but no one is making anything written "natively" on Macs that can compete, and it's silly to say that it shouldn't exist while that fact is true.
- viktorcode 5y agoWe ended here for pure business reasons, and not as a convenience for end users. JavaScript programmers are dime a dozen comparing to Cocoa programmers. What we ended up with is suite of software almost no one uses on their free choice.
- tolmasky 5y agoThe business decision Apple made to largely ignore Cocoa, especially any semblance of documentation, and then confuse “native developers” by giving them conflicting half-baked solutions like Catalyst and SwiftUI? I guess given the option between a closed-source half-assed framework like Catalyst that even Apple themselves can’t make reasonable apps with (see Apple News), and an open source half-assed framework like Electron where you can at least contribute a fix instead of having to wait a full year for the surprise of whether your reported issue got fixed or not, most people just preferred the latter.
- 542458 5y ago“Business reasons” and “convenience for end users” are not entirely decoupled because developer time is not infinite or free. As an end user, the app that exists on my platform (Figma on windows) is better than the app that never got ported because it’s codebase is tied into a bunch of OS native stuff (Sketch). If an app costs half as much because it’s easier to hire developers who know JS compared to native devs, I’ll also be happy. If an app gets features added faster, or is less buggy, or has a better plugin interface, hey, I won’t complain. There’s nothing that says “as an end user I’ll always prefer electron” - I don’t care what it’s written in. But from my perspective there seems to be a lot of high quality electron software that may not have existed otherwise.
- skohan 5y ago> I personally think we should abolish JavaScript and not allow arbitrary remotely loaded code to execute on our computers. Yeah this is honestly where I stopped reading. The ship has long-since sailed on this one - on-demand software clearly wins on utility over local software in most cases, a fact which is proven by how dominant web is over native software despite it's many shortcomings. I actually think what we need to advance software is a better stack/tooling for web to bring it closer to the native experience. I.e. I can imagine a world where my laptop is mostly a platform for running WASM/WebGPU code downloaded from network on demand - and it would be nice if that type of software was not so reliant on the browser as a middle-man.
- deleted 5y ago[deleted]
- adam_arthur 5y agoYes, that would be great! Except Apple deliberately hobbles their browser to prevent competitiveness with native apps. But I guess that's the whole point of the discussion :)
- zepto 5y ago> Apple deliberately hobbles their browser to prevent competitiveness with native apps. It might be true that it’s not competitive but no evidence that it’s deliberate.
- username90 5y agoIf it wasn't deliberate they would let you install Chrome instead of forcing you to use Safari with a chrome skin. And why do they have Safari with a chrome skin? Because then most gullible users thinks they can actually use chrome and that chrome and safari are mostly the same, when they are actually really different and they therefore don't understand what they are missing. Even here on HN where people should know better you sometimes see users say "if you don't like safari you can just install chrome!".
- xg15 5y agoI think that goes back even further: The industry has invested a lot to push the concept of arbitrary automatic updates. Today it's not just normal that the code and functionality of your installed apps is constantly changing, it's almost expected. An app that doesn't get updates is considered dead. Nevermind that this results in a system that is completely impossible to reason about, that this allows companies and corporations to play out business politics right on your hardware and that now suddenly apps can be taken over by malicious parties. Suddenly, we need a privileged "app store" 3rd party that can constantly monitor apps and ban them, should they suddenly turn into malware. That is suicidal.
- city41 5y agoSeems like the original tweet is now gone? But I do want to say, full fledged webapps have been an absolute game changer for internal tools at large companies. I can't even imagine maintaining internal tools any other way now.
- zepto 5y agoThe author also is critical of Apple’s control of the App Store. There is no contradiction.
- ksec 5y ago>At least I don't need Apple's approval to build my website... Yes. But some day you may need Apple's approval for Apple's user to visit your website due to security / privacy / or other ideology them deem unfit for their user's consumption.