7 ms·
The user isn't the one intentionally opening these overlapping videos. The site they're visiting is making that request, and the browser is honoring it. This i
by function_seven 4y ago
The user isn't the one intentionally opening these overlapping videos. The site they're visiting is making that request, and the browser is honoring it.
This is a bug. These are unexpected results! And as the article notes, "sometimes this behavior makes Safari crash."
So a website can make your browser crash by getting it to do something nonsensical (opening 30 overlapping full screen videos), without your forewarning that this could happen.
You can quibble and say it's a "misfeature" or similar, but I'm not sure that means much.
- Maursault 4y ago> The user isn't the one intentionally opening these overlapping videos. Yes, he absolutely is, and the proof is > So here’s a tiny web page I created to play with it. What OP is reporting is more accurately described as a possible memory overflow exploit. The software appears to be operating as designed, but a malicious attacker might be able to exploit the behavior to do bad things, though this is not exactly necessarily true, and we won't know until we see it happen.
- jaywalk 4y agoThe person who created the web page is the user? I think you've got that backwards.
- stonemetal12 4y agoHe found a bug and made a proof of concept webpage to demonstrate it. So when he talks about it he is both the user and the author of the web page. In general You wouldn't expect them to be the same person.
- function_seven 4y agoThis is weird. Okay, so it may not be a software bug at all, but I'm gonna move these goalposts and insist this is a product design bug, or something. If this is intentional behavior, I don't understand the point. A full-screen video should be the only one playing IMO. Playing multiple (windowed) videos is one thing, but having 30 of them overlap full screen is quite another. And with no affordances to mass-terminate them, the result is unwanted behavior. So: not a bug in the "off-by-one" or "use-after-free" sense, but damn if it ain't a close cousin.
- Maursault 4y ago> Playing multiple (windowed) videos is one thing, but having 30 of them overlap full screen is quite another. Behavior can be duplicated on any modern computer, i.e. you can have as many overlapping fullscreen windows as memory will tolerate, probably thousands and much more than that. Why would anyone want to do that? To cry "bug," I imagine. It may not be intentional design, but my point is that this is not a bug, by the definition of what a bug is. There is no actual error here. The code is operating as expected. There may be issues with the interface design, but there also very well may not be.
- function_seven 4y ago> The code is operating as expected I highly doubt this. When Apple rolled out multiple video support, they did not expect that a random website could—having gained permission to spawn one video player—reuse that blessing 29 more times. The browser will prevent auto-playing videos from spawning absent a user interaction. This is a feature that prevents pop-up hell. With this change, they failed to update the "make sure user is cool with this" code. It's a regression, and will be fixed in an update or I eat my hat. Again, I know this isn't some "error found on line 384 of vid.cpp" or whatever, but it's definitely not the way Apple wants this to work. My desktop browsers won't do this, nor any other browser I've used in the past 10 years.
- Maursault 4y agoDesign choices, that's all. mobile Safari is a little different than desktop browsers. It uses the same engine as desktop Safari, but I've always suspected the video player is not built-in to the browser, but instead a separate and discrete application. I suspect this because every other application appears to have an identical video player. Maybe they're all sharing code, but more likely the video player is system-available to any application. But running multiple instances of that video player on iOS is academic. Why you're not able to duplicate this in any of your desktop browsers in the last decade is anyone's guess.
- 4y ago
- SigmundA 4y ago>Yes, he absolutely is, and the proof is No they aren't there is a button that the user clicks that runs code to play multiple overlapping videos. This serves no conceivable purpose and can cause the browser to crash, it is a bug. The reason it works is the code is run from a user action, the problem is after the first video play the browser should no longer consider the subsequent plays a user action, or it should only play the last video and cleanup the now overlapped previous video.
- Maursault 4y agoYou're talking about design choices, not errors or software bugs. You have a design preference that more than one fullscreen video should not be permitted. But this is entirely an arbitrary preference. There is absolutely nothing inherently wrong (ethically or design-wise) with multiple overlapping fullscreen videos, though the OP is describing a very particular case that is strange, which is having multiple instances of the same video playing fullscreen. It's still not a bug. This is interface design.
- function_seven 4y ago> You have a design preference that more than one fullscreen video should not be permitted. I think this is where you and I are talking past each other. I'm not saying that multiple videos shouldn't be allowed. That's not the problem here. The problem is that Safari has a mechanism to ensure that the user wants a video to play. That mechanism looks for some UI action on the user's part before it will allow a site to launch the video player. With this new multiple-video feature, that mechanism is now broken. It'll say, "Hey you want to play this video? Yeah, ok, I will allow it, and any other video the site wants to spam you with now." That italicized part is the bug. It shouldn't assume the UI action applies to an arbitrary number of separate videos. The video player is fine. That's the design choice. The Safari code not accounting for that is the bug.
- Maursault 4y agoYou're still talking about interface design and not an error in the actual code. You're talking about how the user is interacting with the software, and/or how a website developer writes up his crappy site. The software itself isn't broken. But the interaction between user and client and server is getting under your skin and you're insisting it is a bug... when it simply is not a bug. "Every time a try to click this link, my browser crashes!" <--- that sounds like a bug. "I'm able to create a webpage that exploits a user interaction to create weird behavior" <---- not a bug! if a problem exists it is within the realm of User Interface Design and not software design or anything within the code itself. The design choices may cause a need to rework the code, but that doesn't make a bug magically appear in the code.