4 ms·
I didn't say nothing would work. I said it'd be known as the one where nothing works. Think: IE6. It implemented like 95% of all web standards as of 2006. But t
by Xirdus 2mo ago
I didn't say nothing would work. I said it'd be known as the one where nothing works. Think: IE6. It implemented like 95% of all web standards as of 2006. But this missing 5% was the difference between being at the forefront of progress and holding back the entire industry.
Today, IE6's 95% would be less than 10%. So you'd need to implement several times more features than IE6 had to be even remotely close to the status of unworkable mess that webdevs are better off not supporting.
Low-level exploits like heartbleed are quite rare actually. The vast majority of security bugs in Chrome and Firefox are in unsafely handling edge cases in parsing HTML and other media types, not isolating script execution enough, and bugs in runtime interfaces (cookies, local storage, mic&cam APIs, location APIs, etc.) Realistically, there's no way to avoid these bugs - browser engine has too much inherent complexity, statistically you're bound to mke amistake every so often. Moreover, IIRC about half of those bugs are caused by buffer overflows and similar memory bugs. So by using Rust, you can expect to have half as many security holes than you'd have otherwise. The number is still in the thousands either way.
- GoblinSlayer 2mo agoFWIW C++ can do bound checks aka hardened STL. On the other hand google did riir some of their programs and removed bound checks there for speed, welcome to real world, so absence of bound checks is not a mistake, but an intended performance goal.
- Xirdus 2mo agoGoogle is consciously making Chrome less secure because otherwise the performance is unacceptable. The end result is about 300 CVEs every year for the last 10 years. That's for an almost 20 year old project that had most of its security issues resolved very early on. And you're saying somebody who is not Google can make a brand new browser engine from scratch in 2026, have it perform good enough to be actually usable in practice, and not be an absolute security nightmare?
- GoblinSlayer 2mo agoNow you say security isn't that much of a problem. And rust isn't going to help. Also modern standard compliant (without adblock) browsers don't perform anywhere good.
- Xirdus 2mo agoI'm saying the opposite - security is so much of a problem that even the most popular browser in the world can't get it 100% right after 20 years of trying to get it right. Subtract popularity, subtract 20 years, subtract FAANG - do you see how abysmal the security would be in this hypothetical brand new browser engine? There would be a critical 0-day every single day for multiple years straight. People would keep getting their bank accounts hacked on regular basis. And yes, Rust isn't going to help. Modern standard compliant doesn't mean showing ads. It means centering the div when you have tables mixed with floating mixed with grid mixed with flexbox, and all sizes are a combination of px, em, % and vw. While rendering an animated SVG. While rendering the CSS animation of that animated SVG. While recording audio. While processing that audio in a background worker. While another tab synchronizes with the current tab using local storage. And so on and so forth. There's thousands of features you need to implements and millions of possible interactions between them. And if you get any of these wrong, some website will be broken. Ignore enough features, leave enough interactions untested, and a huge chunk of the internet will be some degree of broken.