Reborn 3: Desktop browser with Web 3, faster VPN and ad blocker
blogs.opera.com
blogs.opera.com
However, I really like the idea of eventually having client-side decrypted data, and censorship-resistant "torrent-like" distributed content. Whether cryptocurrencies must play a role in this or not remains to be seen.
Can we still rely on opera and trust them (after their Chinese acquisition)?
Edit: that is NOT an argument for its trustworthiness...
I did not claim that. I merely said that it powers most of the world - meaning that most of the world is compromised, if so.
This is the only assumption which is safe to make.
The question is not if your internet communications are being monitored, the questions are who and why.
Last November, Emmanuel Macron gave a big speech about the fact that the EU cannot rely anymore on the US as an ally for cyberdefense, because the US spent so much effort spying on the EU (and regularly getting caught) that it was not even nearly possible.
So yeah, I trust US companies about as much as Chinese companies, which is not much.
However, I do believe that reliance and trust in Opera of yore would have been based on those running it before circa 2011-2013 when there was a major change of staff, resignation of founder, switch to Chromium/Blink, etc. That all predates the Chinese acquisition (2016)
The VPN should be integrated at the OS level not browser level.
No, it doesn't. It just proves that you own/hold a private key. You need to build an identity protocol on top of that if you want to prove that you are a specific person/organization. Such protocols have been around for quite some time before crypto currencies. It's just they don't have a good UX, that's why most websites require a password based authentication instead of a key/certificate.
I like a lot JWT/JWT as it has a lot of useful attributes(. e.g the "acr" attribute) so you better start with that than a crypto wallet
Your statement makes me very curious because as far as I'm aware, key distribution is the core problem of asymmetric cryptography. I can generate a private key and say I'm you, and there's nothing stopping me from doing that.
The only solution I'm aware of so far is DNSSec which starts from the operating system level.
I have been wanting what the op describes for a long time - why do we have to "create" accounts? Why can't we simply tell the site our account with our request. For a dumb example, having "?publicKey=(key)" in the url. That way the site can know who we are and be able to link our profile, provable by our ability to sign using the private key, does away with login forms, does away with password recovery flow, does away with email single-point-of-failure, allows us to switch profiles easily, etc. It's mind-boggling that every site in the world rebuilds login logic.
> cost
All currencies have an acquisition cost, usually in the low percents. Bitcoin is actually on the cheaper end these days at around 10-25 bps.
> volatility
Prices of things are reflections of the aggregate opinions of those things by everyone in the market. When prices are volatile, that means people's opinions of those things are volatile. And that's because those things have a lot of unknowns associated with them. As time goes on, and society observes the thing more and how it behaves in different circumstances, the better people will be able to predict the effect of future events, and the lower the volatility will be. In a thousand years, for example, when almost any possible event that could have happened to Bitcoin has happened, volatility could be near 0, and price will probably appreciate predictably with population growth.
Interestingly, Opera trying to compete with other browsers makes it pursue users interests, while other browsers yet again don't see Opera as competition, ignore users and pursue megacorp interests instead.
Sizable communications with an uncommon IP can be singled out by netflow analysis.
But yes, it usually works.
Self hosting a vpn is still beyond the vast majority of consumers and every big player in the market has their ip ranges mapped thoroughly.
Lol, sure the closed source browser owned by chinese is out there for user's interests! /s
... the "trusting one entity" was a big part of the sell for me originally, and it a big part of the reason not to use Opera anymore. The company was purchase by a Chinese investment firm, which I'm a little light on details but seem to recall them being heavily invested in advertising.
wat?
(1) The term might be stronger than needed; I meant something a lot closer to "click-baity" than "garbage".
Don't put that snake oil in my browser, please. Thanks.
And it's my favorite method of payment, so easy.
So don't speak for everyone.
There's also a flight insurance app that I've used once. If your flight is delayed, then the contract automatically pays out.
And when I'm bored, I have a bunch of FUN tokens that I picked up for free when it first launched, so I use those to play casino games once in a while. I also loan these tokens out on uniswap.
I'm also involved in MakerDAO governance since I hold some MKR as well as DAOstack which is an infrastructure layer for DAOs.
Last but not least, I use Brave browser and get BAT tokens for browsing. That's mostly everything right now, other than experimenting with other dapps.
That doesn't mean those people are representative of something that's (a) useful, (b) an unstoppable trend as opposed to a fad, (c) can't be done better in other ways, (d) not harmful.
GIT makes use of what is basically a blockchain. Calling it useless is an extremely bold claim that requires a strong evidence.
Maybe crypto transactions, basic at first but growing in complexity as each industry works out their own standards is how a decentralized semantic web will eventually energe
That said, IPFS servers and clients are there but it's not in use. So it would be quite a stretch to call that "officially" Web 3.0 until it will be in use by a significant amount of end user applications. Until now also blockchain (read Bitcoin) payment is very exceptional despite tons of frameworks, libraries, servers and clients. Even for the semantic web there are bizillions of tools but the information value remains questionable.
Looking back at Web 2.0, the transition went much more smoothly from static Web 1.0 to usage of "DHTML", HTML 4.0 with much JS/Ajax and eventually popular services making a lot of use of it, namely Facebook and Google including their plugins that were embedded on lots of websites at that time and still are.
Anyways, would be nice if a new development would get traction...
https://github.com/ethereum/web3.js/
The idea is that cryptocurrencies will represent the 3rd wave of the internet after web 2.0 https://en.wikipedia.org/wiki/Web_2.0
Although Tim Berners lee tried to coin web 3.0 as the semantic web but that's not really taken off as a concept.
I had the feeling everyone tried to coin web 3.0 for many years now and it didn't really take off.
So while they market decentralization and trustlessness, they are one server-compromise away from getting fed a completely false view of Ethereum's blockchain state and losing all their funds.
If that's an attempt on web 3.0, we might as well just skip straight to web 4.0.
Umbrella Corporation... here we go
It's not a Blink fork, if that's what you mean. They built a new browser, using the HTML & JS engines from Chromium. The rest of the browser is different. As a user, I consider the HTML & JS to be commodities, and everything else to be the salient aspects that I look at when choosing between browsers.
spatial navigation, bittorrent, author mode, full page indexing for history, mouse gestures, key bindings editing, icons/buttons customisation, cycle show images/cached images/no images, shrink width to fit screen, presentation mode, panelise web page, navigation bar, tab preview pictures, custom icon sets installable from vendor homepage, all menus customisable by editing ini files
their definition of web3 is kinda limited as it revolves heavily around cryptocurrencies instead of the more broad vision of web3 that is basically anything decentralized; ipfs, dat, zeronet, etc.
Pretty important press release for Opera. You'd think they'd proof read it?
How can they do this for free?
Also, many vpn providers let you use open source software, like OpenVPN.
Opera, however, can ship an installer with a statically linked mock ssh lib, that's always showing a green lock. It's a much more sinister threat model.
The browser already has access to all your keystrokes and all the data it's displaying to you. In some way, it's a "Man In The Middle" that sits at the UI layer and will be able to sniff anything both ways irrespective of the networking layers.
That password coming from your "secure keychain" (or any other password manager)? It is also visible "in the clear" by the browser. Only challenge-based, out-of-browser authentication methods will keep the browser from seeing your secret, but it'll still be able to snoop your interaction both ways, and make sensitive API calls on your behalf (like transferring money, etc). There are other methods like OTP that also limit the exposure of your secret, but don't protect against the main threat of hijacking an authenticated browser session.
Thankfully some services add another layer of authentication for "sensitive actions", but it's not that common, and it is often weak (for example, sending an SMS with a code). Better than nothing of course.
Few days ago we were discussing how VPN is important but won't save the day if you don't know what you are doing.
When we have calls of "I won't log you", I always try to image how tha mine's bird will be set: and if have to log me under some subpoena, how will I know?
Does anyone have any recommendations for a lightweight browser, if such a thing even exists anymore? Perhaps Chromium + Scriptsafe + uBlock is what I need, but ultimately I want is a tabbed browser without a load of unnecessary features bundled in.
For example; there is no way I would trust the VPN embedded into a browser, thereby rendering it useless bloat. Much like I don't trust the ad blocker in Brave for Android, but I find the experience better than Firefox mobile, and carry on using it despite my displeasure.
It was a little barebones for me when I tried it some years back but it might be what you are looking for.
I do wonder, why?
That's some high quality humor.
At least I don't live in the Chinese jurisdiction, while the tech giants do whatever they can to slip their tentacles into every website you visit, even if you don't do any business with them and actively fight their spyware. The Chinese government doesn't want to sell me anything either.
And make the web nigh-unusable.
SurfEasy, which was an Opera VPN company, collected logs and sold it.
Preferably nobody would have it.
I assume American VPN providers are all gathering data for the NSA. Russians for Russia, China for China.
Edit: oops, Trident was the Microsoft browser engine.. i guess i meant 'Presto' as the name of the old ditched Opera web engine.
(But seriously, it's like HTML5; there probably won't really be another major version ever, just new things built on top of the existing schema)