5 ms·
You just announce you are making a change and then turn it on later.
by dfedbeef 2y ago
You just announce you are making a change and then turn it on later.
- schrodinger 2y agoAfter building enterprise APIs for a few years, you’d be amazed at how hard it is to get companies to make even minor changes; backwards compatibility is key. Often it’s because they _can’t_ make the change themselves since they outsourced the code to a consulting agency. So they’d have to sign a new contract and get an agency to make the change. They just won’t, and you’ll have a browser that people stop using.
- bee_rider 2y agoIt is probably outside the scope of what one company can do (although Apple is quite large…). But we need to fix our understanding of backwards compatibility. If a computer system provides the ability to keep doing something, but the way it provides that capability requires it to be insecure, then the system should not really be thought of as “backward compatible.” Because reasonably prudent people can’t actually keep doing the thing they were doing before. Of source, modern computers on the modern web don’t really provide the ability to do much at all in a reasonably prudent fashion, so it is all a bit moot I guess.
- lxgr 2y agoAnnounce what to whom? To the hundreds of millions of users out there that don't even know what a browser is, let alone why it's now talking to them about something called a "site isolation framework"?
- plufz 2y agoI would guess you would use a deprecation message in the console? Like they have done over cookie changes, etc. A normal user would obviously not check the console, but the devs or admins of the site sure might.
- lxgr 2y agoThat's assuming there's still a dev around that has knowledge of, or even access to, the source code of a given webapp depending on the legacy functionality.
- plufz 2y agoSure. I just got a vibe from this thread that breaking security changes in the browser is a totally unknown phenomenon, but we had changes to behavior from other origin headers, demanding ssl and changes to cookies. Somehow we survived. ;)
- lxgr 2y agoA lot of people did complain very loudly about enforcing SSL, and it took decades to get here. Same for cookies. So yes, breaking changes for privacy/security reasons do happen, but they're very painful, and if there's a more secure alternative (in this case, still isolating communicating processes and providing communication via IPC, and providing an opt-out way of the legacy behavior), that's often the easier path.