13 ms·
Show HN: Virtual Machines in the Browser
- myzerox 13y agocool, looks like the natural extension of client-side programming. why should we be limited to running things in the browser while our local machines remain underutilized? just spin up a sandboxed VM via Arc - brilliant! and - like so often - a seemingly obvious idea in hindsight... should also be great for downloading torrents in a sandboxed environment.
- snikolic 13y agoThis is pretty cool. It has always seemed sort of silly to me that I have powerful so many powerful computing devices in my life and yet most of the important applications in my life are inherently centralized and running on someone else's servers in a far away location. Obviously the power of a remote datacenter is necessary for many applications, but for others it seems unnecessary or even like a hindrance.
- jetti 13y agoHasn't this already been done with Java applets? Would the difference here be that instead of running Java, you could run almost any language?
- grun 13y ago> Would the difference here be that instead of running Java, you could run > almost any language? More than just any language - any Linux software.
- jetti 13y agoAnd what are the dependencies? What is the lifetime of the VM? It says that Arc uses VirtualBox, does that mean I would need a full install of VirtualBox to use this?
- lost-theory 13y agoYes, I just tried it. The first screen on the downloaded installer says it will download & install Virtualbox, and run Virtualbox + Arc upon system startup.
- grun 13y agoVirtualBox is included in the Arc installer. It doesn't have to be downloaded or installed separately.
- slacka 13y agoCongratulations! This is a great idea. If I needed port a network and/or performance critical Linux app to the web, Arc offers some unique advantages. However there is some serious competition from Java apps, jslinux, Emscripten w/ asm.js, and (P)NaCl. I don't have a Mac, so I haven't tried out your demo yet, but ideally you should make this work like genymotion, using the existing VirualBox install in headless mode. This would also make a much quicker install option for existing vbox users. Hopefully you can avoid the mistake YouWave made of interfering with an existing vbox installs.
- BWStearns 13y agoWhere did you find the file to try it? I only saw the blogpost.
- jetti 13y agoThere was an example site that was linked in the blog post: http://peggo.co/ http://peggo.co/ It will only work with OS X 10.7+ though.
- BWStearns 13y agoOh ok, that's why it worked for me then. I thought he was making the beta of Arc available already. It looks like it might solve a problem with an in-house project I've been working on at work recently.
- deleted 13y ago[deleted]
- goldfeld 13y agoIf I have a VM in the browser can I run.. vim in the browser? My customized instance and all that? Or maybe this wouldn't be too feasible for io-heavy uses?
- kilroy123 13y agoHow does one try out this beta? Is this going to be open source?
- grun 13y ago> How does one try out this beta? Documentation for Arc and arc.js will be available shortly. > Is this going to be open source? Arc will not be. Perhaps Peggo once Arc has cooled.
- dictum 13y ago>> Is this going to be open source? >Arc will not be The project is certainly interesting and I respect your right to license it as you will, maybe for commercial reasons, but a closed source black box with relatively low-level access (like Java) makes me uncomfortable. I may be alone in my aversion to browser plugins, but most of what Arc could be good for would be better solved with actual native software. See Peggo: A GUI app for OSX with just an input box for the YouTube URL and a choice of where to download the MP3 file would be a better solution for that problem. On the devices where Peggo would be useful (mobile phones, for instance), Arc can't be used. Some things just shouldn't be web apps—I say this as someone who's never made a native app.
- azakai 13y ago>> Is this going to be open source? > Arc will not be. Are you using a commercial license for VirtualBox then (and not the default GPL)?
- jwcrux 13y agoThis needs to be answered.
- mej10 13y agoI am surprised by this. Will you expand on why you're not making it open source?
- 13y ago
- earlz 13y agoFrom an end-user POV, what will using an Arc app entail? Will it be like Flash Player and Java; ie, you download and install Arc once, and then all Arc apps will just work and be super awesome? I had an idea like this, but instead of a VM, using a client-hosted server. The big concern I couldn't solve was security. If you have, say, Peggo.. What is to prevent other websites from being malicious and connecting to your locally-installed Peggo VM and trashing it or otherwise exploiting it?
- grun 13y ago> From an end-user POV, what will using an Arc app entail? If Arc is installed, you're good to go. Everything just works. If Arc isn't installed 1) arc.js transparently falls back to the cloud and runs the Arc app on a server. The user doesn't know the difference. and/or 2) Upsell the user to install Arc. I haven't built the transparent cloud fallback yet. > What is to prevent other websites from being malicious and connecting to your > locally-installed Peggo VM and trashing it or otherwise exploiting it? The web server running in the Arc app can check the Referer header to verify the request came from a permissible domain.
- JangoSteve 13y agoCan the Referrer header not be spoofed?
- sehrope 13y agoSpoofing it in a client's browser is not possible but it's trivial to spoof referrer headers (or anything else) from a stand alone program. Beyond checking for referrer headers the server should give the client a signed token (returned back by the client to the server) to verify the request is valid. Otherwise if the client is arbitrarily sending requests to the server to "install X, run Y, ..." it'd be very easy to hijack the server for other processing. As usual this goes back to one of the standard rules of server security: Don't trust anything that comes from the client.
- 13y ago
- th0ma5 13y agoSort of maybe at an intersection of what the NaCL hopes to achieve? Mini sort-of-virtualization of x86?
- deleted 13y ago[deleted]
- tbirdz 13y agoYou might want to change the name from Arc to something else. Arc is the name of a lisp dialect written by Paul Graham, and is the language Hacker News is written in. http://en.wikipedia.org/wiki/Arc_%28programming_language%29 http://en.wikipedia.org/wiki/Arc_%28programming_language%29
- ibdknox 13y agoArc the language hasn't been officially updated in 4 years. All names have been used at some point - it's not realistic to expect them to be truly unique.
- foobarbazqux 13y ago> All names have been used at some point I'm pretty sure the heat death of the universe will occur before all names are used.
- gruseom 13y agoBut "Arc" as a name is widely known and used, at least among the HN sort of community, and although it's a niche language it's actively used within that niche. I think you're overstating things; the name "Arc" was not ready for garbage collection.
- ibdknox 13y agoIsn't this a problem that the market will correct? If Arc the language has a significant enough following, then "Arc" in common use will refer to the language. I'm not saying people should go around picking names others have used, but it seems a little heavy-handed to assume that because a few thousand people have an attachment to a name it is now off limits for everyone else. Moreover, at what point does it become ok? There's also Ark the YC company: http://ark.com/ http://ark.com/ is that fine because it uses a k? Taking a look at it from a different angle, even in the case of the legal framework for names - trademark - having Arc the language and Arc the VM thing would be fine. The truth is, if you don't want people to collide with your name, picking a 3 letter common word probably isn't the way to do it.
- invalid10 13y agoVery nice! Games such as Runescape were built into the browser stored data on users computers to track botting. So many of the first gold farming companies developed technologies like this to implement into Botting clients (which were very sophisticated web browsers). There was a very interesting tech scene that many don't know about around MMO cheating, especially Runescape.
- batgaijin 13y agoI was hoping it was a finished version of http://bellard.org/jslinux/ http://bellard.org/jslinux/
- wslh 13y agoSame expectation here. Deploying a customized VM to the browser (with networking included) will be very interesting. I am not sure about the real use cases. For learning development will be useful since you don't need to do a more complex interaction between the browser and your server.
- robertelder 13y agoUnfortunately, full networking capability as it exists in a typical virtual machine (like Virtualbox), will not be possible in pure javascript. Security features of the browser like the same origin policy restrict this from being possible. Even if you were to use some of the exceptions to the same origin policy, you will be limited to sending HTTP requests. There is no way to send a UDP packet from javascript for example. Of course you can create browser extensions which expose these utilities, but then you're taking the easy way out :)
- zeckalpha 13y agoI was hoping it used http://www.paulgraham.com/arc.html http://www.paulgraham.com/arc.html
- g3 13y agoJust give me one more month, I'm almost there ...
- xhrpost 13y agoWould be neat for a project like this to go open source and accept community submissions. Not sure why the author of jsLinux didn't go that route.
- rhelmer 13y agoFabrice Bellard is the author of qemu and ffmpeg (among other things), so it is likely he is aware of the benefits of open source and it is a conscious decision (maybe there is interest from someone with relatively deep pockets, or maybe he considers it too hacky?) Don't want to speak for him here though. I do wonder how qemu compiled via emscripten would compare though...
- edsiper2 13y agoInteresting, but dependencies are a long-term killer. You should check this project: http://bellard.org/jslinux/ It creates a VM in javascript and can boot Linux.
- Scaevolus 13y ago(P)NaCl already solves this problem, without such hacks as transparently spinning up a virtual machine. I don't trust Virtualbox to be especially resilient to attacks from malicious VMs. Chrome's sandbox is well-audited and (overall) is sound. A virtual machine host has a much larger attack surface, and generally doesn't assume malicious guests.
- grun 13y agoNative Client 1) Is Chrome only. 2) Can't spawn processes or subprocesses. 3) Can't open raw UDP or TCP sockets. 4) Requires apps be ported.
- dekhn 13y agoWhile I like the idea of running a VM in a browser (not sure if I'm convinced it makes sense, I still like the idea): Argument #1 only makes sense if you support a lot of platforms. Right now you only support Mac OS X (according to another comment). The number of people who use Chrome globally is larger than the number of people who use Mac OS X. Ergo, if you used Native Client and chrome, you'd be more ubiquitous. Regarding sockets: chrome supports UDP and TCP: http://developer.chrome.com/apps/socket.html http://developer.chrome.com/apps/socket.html If there's one platform to build on that is going to cover a large number of people and give close to native performance, it's Chrome+PNaCl. I wouldn't tell everybody to drop what they're doing and adopt that target (it's not ready yet). VMs in the browser are pretty nascent, too.
- iuguy 13y agoWhy do you think that is? Is it because Google have a large team of engineers who have developed a proper security programme for the project and realised that doing 2 and 3 are bad and that as a result of that and other problems with diong this that 4 is necessary? There are reasons for these limitations.
- regularfry 13y agoVM hosts have assumed malicious guests ever since people started renting out VMs. It's a VPS host's nightmare to have a VM root exploit be escalatable to expose all the other VMs on that VM's host.
- fka 13y agoTitle is wrong. Virtual Machines are not in the browser, they are in your computer bridged to the browser.
- jijji 13y agobrowsers are essentially virtual machines themselves, so to be highly redundant (i.e. java already does this), why have VM's in the browser, which is already interpreting code on its own. The next guy is going to come along and make a VM inside of a VM inside of a VM and lets see how slow we can make the browser when its 5 levels deep in abstraction.
- AlexanderDhoore 13y agoThis is an actual linux virtual machine... Not a language runtime. It's too bad that "Virtual Machine" means so many things. Maybe someone has more info on this, but I understand that it was Java who first called their language runtime a "Virtual Machine". Partly motivated because they wanted to create an actual physical machine that ran Java (kind of like Lisp machines). Nowadays with type 1, type 2 hypervisors, and jails/containers/zones, and every programming language on the planet calling their runtime a VM, I'm not surprised that people are getting confused.
- samspenc 13y ago"$25,000 every month in hosting costs". Wow, is that right?
- cbhl 13y agoThis is really cool. It's completely backwards from my personal usage of the Internet; I get away with browsing online using a Penryn-era Pentium, a ARM-based Chromebook, and/or my Galaxy Nexus precisely because the majority of processing costs are offloaded on "traditional" websites rather than on the browser doing the rendering. But if this means that application developers won't have to recompile every application under the sun (like, say, ffmpeg or Audacity) to run under asm.js or PNaCl, then I think it could mean that we could skip a decade or two of having to reinvent the wheel. On the other hand, this feels suspiciously reminiscent of ActiveX, so I suspect you're going to have a hard time convincing people to adopt it if the security diehards warn you of running arbitrary code on your machine (even if it is in a sandbox).
- rsync 13y ago"the majority of processing costs are offloaded on "traditional" websites rather than on the browser doing the rendering" I have not found this to be the case. I find that most websites take a LOT of processing power to display - loaded with flash, scripts, video, etc. A lot of sites are not really guilty as it is the ad network content inline with the site that pulls all of that computing power, but other sites (boingboing, for instance) generate a lot of CPU use just on their own. And it gets worse all the time. I suspect that whatever gains we make with efficiency of HTML5, etc., will be immediately consumed by things like the OP is building. I have a 5 year old macbook air that absolutely does not need to be replaced. Except that I can't have more than 10-12 browser windows open before it's pinwheel city...
- cbhl 13y agoWith the devices I've used, I find that flash content loads and runs just fine provided that there's at most one running on each page and it doesn't crash. Granted, I find myself enabling Adblock by default on most sites because most ads nowadays are annoying Flash pop-overs. Back in the day, the Linux implementation of Flash didn't support making the Flash embed transparent, so I had to go into Firebug/Web Inspector and delete the embed/object tags entirely just to read the page. While I think that particular bug has been fixed, even today, most of the Chrome tab crashes I run into are still caused by Flash crashing. It really bothers me how much stuff depends on Flash still, whether it's putting something in the clipboard from the browser, or just Google Hangouts or Facebook deciding to play a "ping!" when a notification goes off. The only thing "HTML5" means to me is that my ARM devices can offload H.264 video decoding to the GPU, rather than trying to run a cross-compiled Sorenson decoder on the (relatively underpowered) CPU. Everything else under the "HTML5" banner seems to be just increasingly complicated browser-specific extensions to JavaScript and/or CSS. I've also noticed that the Chromebook and Chrome for Android will deallocate tabs that I haven't used recently and reload them when I switch to them, which lets me have dozens of tabs "open" on devices which are otherwise only capable of handling three or four tabs at once. Of course, this is only reasonable because of "high speed internet"; I remember being on dial-up in the late 90s running Internet Explorer 4 and opening ten windows in the background so that the pages would pre-load in the background while I read the current page.
- bsaul 13y agoIt's certainly a great project, but i can't help thinking : so now we're not satisfied anymore with running virtual machines to execute some code, we need the whole OS on top, along with the shell, and the preinstalled programs... That story reminds me of the last time I tried to compile a blackberry app on my mac a few years ago : Java VM running my code within a blackberry simulator running inside of a windows XP VM on top on my mac OS. Where will it end ?
- gtrak 13y agoPeople prefer this incremental series of hacks to the existential despair of being faced with a cohesive system, say a lisp machine. :-)
- opcenter 13y agoShould have named it red pill. :) Seriously though, I was more excited when I thought it was about running Linux inside the browser. Personally, I have no interest in installing an extra VM on my system just to make your development easier.
- lisimia 13y agoThis sounds a lot like reinventing the wheel (JVM). JVMs lack the power of a full linux core, but do you really need it? you just wanted hardware access + native threds (JVM has these and more) Also this sounds good for just 1 App, but what happens when you try to run more VMs than you have physical cores? And/Or memory, this would directly affect the host.
- grun 13y ago> what happens when you try to run more VMs than you have physical cores? The VMs are just processes of the host OS. They're multiplexed over available cores, same as ordinary processes.
- BWStearns 13y agoI might be off base here but because the processing of data happens on client side is it possible that this could be used to increase privacy through zero knowledge apps?
- deleted 13y ago[deleted]
- htilford 13y agoThe installation failed. The Installer encountered an error that caused the installation to fail. Contact the software manufacturer for assistance. 10.8.4
- grun 13y agoPlease shoot me an email so I can destroy the bug.
- beagle3 13y agoSecurity wise, this seems like an awful idea: Unless the host is firewalled from the guest, if Arc-style VMs become popular, than you'll have malicious websites starting VMs to scan your host network for unpatched vulnerabilities, and abuse them. I try to keep my network secure, but e.g. Cisco/Linksys E3000 hasn't received a firmware update in a long time, and it has known exploitable bugs - right now, the fact that it is only accessible from inside the NAT, and that webpages can't do arbitrary accesses is what keeps all those E3000s from being exploited. (My E3000 has been running dd-wrt, so it's not vulnerable to those problems; but I had to manually upgrade the dropbear ssh because of vulnerabilities - latest official dd-wrt for it is still vulnerable)
- mej10 13y agoSecurity-wise it is no different than installing a multitude of software packages onto your computer, which many developers are already comfortable with (whether they should be or not).
- grun 13y agoArc apps will require explicit permission to communicate with a local network. This can be enforced at the hardware layer by the virtual NIC.
- beagle3 13y agoHow do you define local? Is it 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16? I guess that would cover 99% of local networks. I wasn't aware virtualbox has firewalling at the virtual NIC level - my 4.1 doesn't; It's either host-only, bridged, or nat - of which bridged is unlimited, host-only is useless, and nat cannot (as far as I can tell) be firewalled at the virtual NIC level. So how do you do it?
- csears 13y agoNeat concept, but I don't see a VirtualBox-based implementation ever becoming mainstream... not that it needs to be mainstream to be useful. It seems like full blown x86 PC hardware emulation is overkill for what you're doing. As others mentioned, NaCL isn't really the right abstraction layer either. Perhaps a stripped-down version of VirtualBox could be turned into a "standard" browser plug-in and paired with something like Docker, so you're just running a minimal container image.
- finnh 13y agoI like the Docker idea, especially if Arc were providing the base linux VM via read-only mount and the website's Arc App was only a difference image on top of that ... nice and small.
- mej10 13y agoI think this is awesome! I had the thought the other day that perhaps using a VM or the lightweight container technologies (like Jails or Docker) that we should be able to do this. Glad to see someone is already working on it!
- snake_plissken 13y ago$25,000 a month in hosting costs...on a youtube ripper? :0
- smupp 13y agoAnd what happens to the VM when the user closes their arc app? It seems like you could build really powerful tools that leverage saving the state of the VM between sessions. Suppose I build an arc text editor/image manipulator, something where my workflow is boot program --> load file X --> edit file X --> save file X. In theory I could save states of the entire app between sessions, so the whole workflow becomes boot arc app --> edit file... And I could do this for any app I build in arc... Am I getting this right? Because that would be absolutely incredible for building session persistence without a home-brew backend.
- azakai 13y ago> I want to build apps in Python and C and ship them in the browser. I can't. Did you try the existing solutions for running those languages in the browser? (pyjamas, emscripten, etc.) Were there specific limitations that prevented you from using them?
- rhelmer 13y agoYes, I really wonder if emscripten was explored here... I assume he was doing this all on the server-side (since there's a mention of $25k monthly server bills). From the link: > This was painful, expensive, and inefficient. Clients are more than capable of transcoding video; the problem is browsers aren't. > Browsers can't run Linux software like ffmpeg, can't run Python, can't reach native performance, and can't make cross-domain requests. Depending on exactly what ffmpeg is being used for, the legality of distributing codecs is going to be an issue. Virtualbox VM overhead is non-zero compared to "native performance" anyway so I'd like to see numbers on this versus running in a browser. Cross-domain requests can be an issue, but CORS headers can work (unless he does not control the site in question, or they don't want people making these sorts of requests). From the post it sounds like this was a YouTube scraper, which basically means that there's no way he could legally be distributing ffmpeg + codecs needed in any case, and also this is against YouTube's ToS of course.
- azakai 13y ago> Yes, I really wonder if emscripten was explored here... I assume he was doing this all on the server-side (since there's a mention of $25k monthly server bills). It is on the client, I believe. Literally runs VirtualBox on the client side. > Browsers can't run Linux software like ffmpeg, can't run Python, can't reach native performance, and can't make cross-domain requests. ffmpeg definitely can be run in browsers, as can python. How close to native performance needs to be measured in each case, of course. I'm curious if they compared the performance and found it lacking, or just didn't try the browser options at all.
- rhelmer 13y ago> It is on the client, I believe. Literally runs VirtualBox on the client side. Right, sorry I meant the situation that Arc was intended to remedy (from the site): > I want to build apps in Python and C and ship them in the browser. I can't. > I ran full steam into this problem when I built Dirpy, a web app that records MP3s from YouTube. I could have built a native app in Python and C, but to test, distribute, and maintain builds for every OS is a total nightmare. So I built Dirpy as a web app, did all the work on servers, and paid $25,000 every month in hosting costs. >> Browsers can't run Linux software like ffmpeg, can't run Python, can't reach native performance, and can't make cross-domain requests. >> ffmpeg definitely can be run in browsers, as can python. How close to native performance needs to be measured in each case, of course. I'm curious if they compared the performance and found it lacking, or just didn't try the browser options at all. Totally agreed (I was quoting the site there, to be clear) - I am a huge fan of emscripten's approach, and I think it would work really well for this use case. VirtualBox is overkill here, and getting people to install something like this is a huge barrier. However I still think that it would not be legal to distribute the codecs one would need to do this, and it'd also be against YouTube's terms of service.
- JoshTriplett 13y agoOn Chrome platforms, this could make use of Native Client to run the VM directly in the browser, rather than requiring the installation of an un-sandboxed browser plugin.
- helloNSA_ 13y agoSo we use ArcVM (aka VBox--controlled by Oracle) instead of JavaVM(also controlled by Oracle)? Qemu would seem to be the better choice.
- kudu 13y agoI think it's a nice idea, but you should consider adding support for other backend providers such as Docker.
- trumbitta2 13y agoThis seems to me as a very good chance to work together with the Vagrant team and win. http://www.vagrantup.com/ http://www.vagrantup.com/
- iuguy 13y agoThis is a terrible idea. The author needs to stop what they're doing right now, from a security context this is really quite dangerous. Arc uses a desktop virtualisation tool to run arbitrary code on your system. The manifest provides a set of packages to download and install and a series of commands to execute inside the downloaded Arc VM image. A malicious server could use this to run an app that attacks your network, the host, acts as a bot, anything. I'm assuming that in order to run native code like this, there's no sandboxing. I've seen no mention of it. There's a reason you can't run native code in the browser without restrictions, and this bypasses all of that.
- hyperion2010 13y agoThere is sandboxing. The native code is not run in the browser or by the host OS. The native code is executed inside a linux guest running on virtual box. The browser itself does not run any native code. Others have pointed out that there are still security concerns having an arbitrary code execution device suddenly appear inside your network.
- iuguy 13y ago> There is sandboxing. I think I missed that. Can you point me to the bit in the source code where the sandboxing is so I can have a look and assuming it's good retract any claims about a lack of sandboxing I may have made?
- AlexanderDhoore 13y agoA lot of comments below recognise this. Most people here probably know... It's doomed to go wrong. This isn't supposed to be anything more than a neat tool. But still quite an interesting experiment, no?
- iuguy 13y agoAs experiments go, it's as interesting as changing genes in foetuses to produce blonde kids. It's stuff that might seem intellectually interesting but falls into the category of things people shouldn't do because of the consequences.
- nine_k 13y agoA new, better, richer, open-souce Flash or Silverlight? Well, it could have some uses. But in my opinion the browser will eventually simply become the OS: you will compile everything to Javascript (or at least asm.js) and use all the interesting APIs from there. Sad but very probable.
- acscott314 13y agoDesktop client disk space is large enough to have a VM for many sites. In the future, if it increases enough to have a VM for every web application _and_ work offline you have the selling point that the app can work during infrastructure failures. People will buy that. Sandbox the networking so it only can call your site and you have solved some of the security problems mentioned. Trouble is, large amount $$$ is behind tablets and their ilk. So you have to work on this for another 10 years when desktops come back. That will happen when Moore's law returns into existence. Light-based computing or analog-fusion-digital computing comes on the scene. What you have is a homomorphism to just a desktop application. The browser has grown to be a glorified dumb terminal that can display rich interfaces, and so the lines are blurred enough to confuse anyone trying to handle the client/server distinction. Best bet is to turn it into a platform that enterprises can use to solve their existing problems. Niche play. Great work, BTW.
- Noxchi 13y agoThis project is going to die unsuccessful. The sooner you stop working on it, the less you will lose unless you really enjoy building this for no other reason than doing it and having something you can put on your resume. People who need solutions like peggo needed can use the Java applet a portion of their users already have, or they could use asm.js and convert their binaries into JS that runs in the browser. Months ago, I saw a post here where I ran a Qt desktop GUI in my browser that was nothing but JS. I don't see any real projects / sites that would use Arc, because it would be a lot of friction / poor UX for their users, and it is simply unnecessary because there are already usable solutions to client-side computing.
- RivieraKid 13y agoReading the comments here... wow, HN must be a depressing place for people who create things. I feel sorry for the author.
- dictum 13y agoAs someone who gave depressing feedback, I'd like to defend my actions: I've learned that attention is more important than appreciation. When you introduce a project, it's better to get people thinking about it, nitpicking and even questioning the point of your project, than to get a few replies of "Nice!" and be ignored in the long term. I've noticed another thing: most things of which I'm initially slightly dismissive fail to reach any success, but the things I'm very dismissive succeed. I've seen products get very harsh feedback and, a few months later, the products were successful, had better user experiences, and their users loved them. But the visceral reaction to his project may have to do with the kind of expectations we have from web use vs. installed software. I know some people install anything they happen by, and will try all one-line command line installs and random .pkgs they find, but most people who care about security are wary of installing closed source software from a not-very-known third party, or run arbitrary code in a virtual machine. When you browse the web, there's an expectation of not worrying about security and malicious code execution. Javascript blurs that line, but it's mostly kept away from the innards of the host. Installed software is more intimate; in some ways, it's like letting a stranger into your kitchen, but not into into your bedroom. Of course, they can do harm in the kitchen too, but the bedroom has implications that go beyond physical access. HN can be very negative sometimes, and seeing angry or snide comments makes me sad too. You can give concrete, actionable advice and feedback without being an asshole, and no, that's not pretending to be nice, it's simply not going out of your way to be rude. But if you take everything into account, it's better to get discouraging comments from HN and filter them for real information than to be ignored.
- RivieraKid 13y agoI think you may be right with the idea that lot's of negative feedback may be good in a way, interesting observation. I think one of the main reasons why projects like Arc or NaCl started is that the web is that the web is not a very good platform. It was created as a platform for documents, not for apps. I wish there was a platform having advantages of both web and native platforms (Windows, Linux, Android, etc.).
- gosukiwi 13y agoAren't browser plugins like Java and Flash bad?
- rdl 13y agoI like the idea here, but really wish you'd rename it to something which didn't collide with pg's Arc (which runs Hacker News). There is a lot of awesome stuff you can do with "local, short-lived VMs". I've thought about how to do this securely (using hardware) -- an awesome end state would be letting a data owner with local data, and a code author in the cloud, both mutually distrustful, allow data owner's data to be processed by code owner in a safe way mutually agreed by each. You could do this with trustworthy computing, or a dedicated trusted third party environment on the net, or maybe with MPC someday. Not sure if Linux or x86 vm is the right level of abstraction; maybe the "peggo" level where you have a higher level might be better for users. Maybe even something like Docker (but on the client)?
- neocodesoftware 13y agoit's a 171.5MB app to convert youtube videos to mp3s I didn't click ok Maybe 40MBs is ok… :D
- ashkav 13y agoI'd like to see this come to fruition.
- mvip 13y agoAwesome. Glad to see that you got it out the door, Arthur!
- igorhvr 13y agoThis is really cool. Thanks for releasing it to the world! Of course it is as secure as the virtualbox Sanbox is, but some variation of this statement would also be true for Flash, for Java and a host of other technologies that despite whatever flaws they had did allow a lot of interesting things to be built. I am here musing, trying to come up with something nice I could build once the Linux-packaged version is made available...