As someone who put a lot into the old pre-12 Opera community, I will never use a closed-source browser again. This is not a commentary on quality - Opera was hands down the best browser ever built, despite being closed-source - but rather on commitment. If Vivaldi fails, all of its users will be left out in the cold. Again.
Admittedly, it is not quite so bad a situation as Opera 12. Vivaldi is mostly/largely open source[2]. It still seems like a massive missed opportunity though.
[1] https://github.com/github/dmca/blob/master/2017/2017-01-12-P...
[2] https://vivaldi.net/userblogs/entry/a-few-words-about-open-s...
Isn't the way out of this via open source and community efforts essentially why Firefox has been successful despite not being OS bundled or backed by a huge search engine company like Google?
Firefox definitely does benefit from community contributions (a lot), but the vast majority of the important code is written by paid employees.
I don't think GP has any issues with Vivaldi being developed by paid developers per se, but if Vivaldi Technologies decides to stop development there is no guarantee that anyone else will be able to take over development. Firefox wouldn't have that issue if it started today.
I don't disagree that it would be better if Vivaldi were open source. I just don't think that reason is all that compelling to Vivaldi the company. Who thinks about "what happens when my company folds"? There are other advantages to being open source than just that.
I've tried it out and it seems nice and powerful.
Yes I know they publish some source and no I don't use Chrome - for the same reason.
Best of all, it's open source: https://github.com/brave/browser-laptop/blob/master/LICENSE....
Using your analogical line of reasoning, the equivalent would be stealing the groceries from a supermarket and replacing them with your own. I don't think Brave's proposed (but apparently never implemented) ad-replacement was quite this bad, but analogies are never very accurate.
I buy the food (content) and get the branded packaging (ads)
I then serve the same food, replacing the branded packaging with my own plates.
My dinner guests will give me credit for the plates, instead of giving eyeballs to the original branded packaging.
The fact it took a second explanation/clarification is a pretty good insight into how accepting we've become of advertising as a thing tbh.
It's my understanding that they replace them with ads from their own network, but revenue still goes to the publisher.
You're right that this is "problematic", but your initial description of "Brave replacing ads with their own", while technically correct, leaves out any subtlety. They might me misguided, but this doesn't looks as malicious...
Brave blocks ads by default it does not replace them.
Edit: formatting
How come? Is there an upside to this I'm not seeing?
Rather than the idea of "happier to have my car stolen, etc.", it's more, I'm happier to be the guy who rides the train rather than the bus. I don't know exactly how the train is operated (even if I know the concepts that make it work) - my knowledge extends only so far that I know that it does what it's supposed to. I'd go so far as to suggest that relatively few rail transit riders do know how to properly operate a train - and add to that, trains can only run on rails; i.e. they do one thing well (generally speaking - let's not discuss the number of issues NJTransit's had recently). The potential for hijacking is significantly reduced by inherent limitation and obscurity of control.
So too do I want software along that same thought process. Relatively few users know how to do more than what they need to know; and even so those that would hijack it are locked into a specific set of operations.
Most humans want trains to be safe (A). Some humans are lazy fucks and will risk hurting people or deliberately hurt them to save time and make money (B). Some humans know a lot about how trains work (C). Most humans don't know much about how trains work (D). Some humans don't know anything about how trains work (E).
A train is an object that operates at normal scales, in multiple senses. It is very natural for the state of the safety of a train to be observable to its users. They would know if its rusty and unkempt, if the doors weren't put on properly, if the engine is making unusual sounds, if the conductor looks shady and may be there to scam them. Group D may not know exactly how the train is going to kill them, but you don't need to be in Group C to recognise most design failures. The safety of trains is ensured in part by the size of Group D, operators (Some C, Some B) won't make enough money if Group D refuse to ride the train so they keep standards high.
Now software isn't quite the same as trains. Software has nearly everyone, like yourself, nearest to Group E. Group D is not insignificant - these are those who work with software at a design level, and can spot design faults. Group C are minuscule.
Closed source software means that the only ones checking Group B are the members of Group C who have, for whatever reason, gone the extra mile. Group D are as oblivious as E.
Open source software allows Group D to get involved in checking that the operators are more of Group C than Group B.
---
Your busses vs trains scenario is interesting. Trains are controlled by widely available and auditable schedules, making them more open than the untracked antics of the completely closed source reasoning of bus and car drivers.
I don't think it's fair that you were downvoted, but this is an idea that developers and IS professionals tend to disagree with [1]. Even detractors don't feel that higher code availability correlates with lower levels of application security.
1 - https://www.schneier.com/essays/archives/2004/10/the_non-sec...
Being able to use code blocks from FOSS projects makes a developer's life easier, rather than consistently reinventing the wheel. It also allows for more code to get out the door, faster. So whether they're paid on salary so they can just browse GitHub (or SourceForge, etc) for the code they're looking for, or paid by project so they want to get things out quick, it's beneficial to have many open source projects across the entire ecosystem of computing.
Being able to review source makes an IS professional's life easier, because rather than testing the I/O of a black box (which is often time-consuming), they can look over "important sections" of the (often human-readable) code. With something like Notepad++, they have code indentation and highlighting, and can search for key phrases to identify those "important sections" which often show some kind of major security hazard. This means that they get more projects done, in turn being able to make more money.
So when you look at the situation from a "cui bono?" ("who benefits?") perspective as a relative outsider, those two groups of people who are most strongly in favor of open source are the two groups which are most likely to benefit from it. As such, I consider their statements subject to bias, whether conscious or not!
Given the last few years of adventure in the OpenSSL land I make no assumption about superiority of the open sourced solutions security-wise. Hence the curiosity, what is the motivation of others.
I wouldn't have a clue what to do with browser code, and I don't inspect the code of the browser I use, but I am happier if people who can understand the code and who aren't dependent on the project for their living can check it.
This feature looks nice and I hope other browsers adopt and adapt and make more meaningful end-user advancements like this that are visible to the eye.
I looked around a bit and didn't see anything about the license on their site. If I missed it and someone has a link that would be appreciated!
Cars without the very very very best armour are completely unsafe. Don't use this nice, good, performant, practical and mostly bulletproof van, instead settle for the google armoured car because think if someone starts shooting at you with a 50 cal sniper rifle from a perfect angle!
PS: for extra goodness the hood of the google car is welded (closed source even if we know the engine from chromium), pulling trailers (real extensions) is not possible and by default it records your every turn of the wheel and sends it to Google because you never know...
PPS: Oh, at close range even the google car yields to a sniper rifle.
Me: happily using Firefox. Happily driving a reasonable family car. There are certain places I won't drive that car at night but I can live with that.
(Feel free to bookmark and reuse. : )
Also- I think you vastly underestimate how often people get hacked through their browser.
As a seasoned IT pro I should know. Yet in the last 20 years I was hit by a drive by exploit once.
Other people: tons of times.
By some weird coincidence this seems to be the same people who insist on trying to run the latest crack of Photoshop etc.
I do explain to people that just as there are certain places you won't go at night there are certain places they shouldn't necessarily visit on the Internet.
Other than that it is tech support scams, driver update scams etc, but not many drive by exploits on places I frequent (HN, occacionally dzone, reddit and slashdot, technical blogs, mainstream and not so mainstream (both very correct and somewhat uncorrect ones) news in my language etc.
Browsers are free.
> pulling trailers (real extensions)
Well look what's happening to Firefox's extensions soon.
> PPS: Oh, at close range even the google car yields to a sniper rifle.
http://www.tomshardware.com/news/pwn2own-2017-microsoft-edge... - Although the statement "Firefox was back at this year’s Pwn2Own after missing last year, seemingly because the browser would’ve been too easy to hack" probably sums it up nicely.
Browsers are free.
Using Chrome would cost me a lot. Both because it is sub-par for my usage patterns and because it feels bad to support it.
Well look what's happening to Firefox's extensions soon.
Last I checked whey will still be miles ahead of every other browser.
"Firefox was back at this year’s Pwn2Own after missing last year, seemingly because the browser would’ve been too easy to hack" probably sums it up nicely.
Pwn2own is the equivalent of lining up cars and inviting people to bring their preferred weapon to test the armour.
As I have pointed out elsewhere either I am unusually lucky or drive-by exploits are way less common in the wild than people think. Or maybe it is just because I don't go hunting for Photoshop cracks and free movies with my work browser.
In any case: Yes, the safer the better, but we need to stop this "nothing but the most secure" mindset because in the end it only results in a Chrome monoculture which I think is worse in every way, even securitywise.
Doesn't change the fact that your analogy is flawed.
> Last I checked whey will still be miles ahead of every other browser.
Vimperator maybe, but that stopped working a while back.
https://arstechnica.com/information-technology/2015/08/mozil...
Still, they're moving. And why do you think they're moving?
> Pwn2own is the equivalent of lining up cars and inviting people to bring their preferred weapon to test the armour.
I agree with you, but I was responding to your comment about a sniper rifle. I'd argue that pwn2own is the equivalent of using a sniper rifle - and Chrome seems to have dealt with it well.
> In any case: Yes, the safer the better, but we need to stop this "nothing but the most secure" mindset because in the end it only results in a Chrome monoculture which I think is worse in every way, even securitywise.
Like I said, I'd been using Firefox for years because I honestly think it's a better browser. That doesn't excuse how far behind they are security wise though. They seem to have the resources with the companies they've been acquiring but IMO they (the resources) are misplaced.
I much prefer open source, and on my home Arch Machine I use Chromium but at work I'm required to use Windows so I use Chrome because otherwise it's awkward.
Once Mozilla gets sandboxing implemented I will be moving back to Firefox.