Until OS vendors are willing to provide a safe sandbox to run untrusted code in, and untangled from a non-technical curating mechanism which has all sorts of conflicts-of-interests of what's morally acceptable and what's not, WASM is the next best thing to an open, yet secure, platform.
Desktop Linux aside, the web is currently the only open platform for distributing software outside of the interests of a single "platform owner". Google may close this "loop hole" soon, so I'm not too optimistic for the future, but today, that's what it is.
Mind you, I'm using a Lenovo laptop, so it's among the best supported hardware you can buy for the purpose. But the fact that there aren't more boutique computer makers selling GNU/Linux systems installed by default is an interesting statement on the industry.
I'm sure ultimately it comes down to the availability of software like Microsoft Word, but ironically having so much stuff move to the cloud is a boon in this case. With so many web-based apps available, nontechnical people can switch from Windows to a well-configured GNU/Linux system and not notice much of a difference.
With that problem out of the way, a hypothetical hardware vendor can focus on building sane defaults, a good user experience, and good documentation (good for users, not developers). Then if and when it works out and marketshare ends up in double digits, more non-web software will start to become available anyway, and/or a lot more corporate money could start flowing into established projects like LibreOffice.
Obviously the Chromebook was a thing, and you can buy System76 machines today, but the former was too extreme and the latter is probably too expensive for grandma just checking her email.
I assume the reason it doesn't exist it is because the logistics and economics of the hardware don't work out. But I wonder if it will become feasible some time in the near future.
I would say, that enough OS primitives should be present so that as an example SQLite3 can compile and run, and you can get a compatible file out the other end.
Yes, you can. You have always been able to.
> (not when Catalina will be out anyway).
Yes, you will be able to.
I just downloaded a music tracker/MOD player from the Mesozoic (well, not quite) and it runs fine on Catalina Developer Preview 4.
I can understand the confusion – I had the same concerns while watching this year's WWDC's Platforms State of the Union – but please do not spread FUD, or accept it as true without credible sources.
Apple does require developers to update their old apps now and then, and that may not be convenient for some devs, but I feel it's overall good for users, and they don't force anyone to distribute via the App Store only or give Apple a % of their sales.
In fact, a few companies have withdrawn their products from the Mac App Store, like Sketch and Coda and others.
I've been running the Catalina betas, and running non-notarized apps only requires right clicking instead of double clicking. If that's too much of an obstacle for you, you probably shouldn't run the app.
Gatekeeper on macOS is a technology designed to protect careless users. It makes it slightly harder to shoot yourself in the foot. It doesn't prevent you from doing it, though.
Yes you can:
https://forums.macrumors.com/threads/unsigned-apps-catalyst-...
WASM is the next best thing to an open, yet secure, platform.
So, instead of walled gardens with signed and checked applications (bad). We have to run untrusted and unchecked code of vendors who run code to track your movements around the web and in their applications? (Even worse)
Desktop Linux aside
Maybe we should make Linux an acceptable platform for more people rather than optimizing for proprietary web applications that you don't even own a copy of anymore.
Won't ever happen for two reasons: 1) The Linux Desktop community would have to admit that there are better ways to do things, and 2) They'd have to agree on what those things are. 20 years of Linux Desktop history show these things to be impossible.
Theoretically, a new community could spring up and put a new userland on top of the Linux kernel, like Android did, but it would seem like the people who have the interest in doing such a thing (like myself) lack enough time, talent, and/or ability to organize sufficiently to pull it off. Not to mention that we'd all have to agree too.
Have you taken a look around Casey Muratori's handmade.network? Or interacted much with the guys who watch Jonathan Blow's livestreams? They make much the same point you do about taking the linux kernel and creating a new userland around it.
Anyone who's interested in working on something like this, email walkinginalinuxuserland@lj3.me. The least we could all do is keep in touch, right?
I also think a forum or IRC channel would be more appropriate, but email is a start and I appreciate you taking the initiative.
See also Probono's Hello[0], but I'm not sure he hasn't decided that Haiku already fits for him.
I don't think that is the case. Simply because a WASM application will have to request the permissions it needs up front (assuming a sane runtime) and you don't have to give anything run in background permissions... also, it won't have access to other apps, so it can't really track you.
The bigger issue with Desktop linux is very few people run it, and targeting a specific subset for linux as separate from other platforms is difficult and costly, to say the least.
Something like Redox(1). It's even MIT licensed, so you could include it in a commercial distribution with your own changes if you so chose when you made your gui.
and sandboxed. yes, this is way forward.
Thing is, "safe" OS-sandboxes are not safe; "local" privilege escalation vulnerabilities are still pervasive. Until OS's are safe enough that I can run `sudo -u nobody untrusted_binary` and not even think about the possibility of it taking over my system, something like the WASM sandbox (perhaps extended with WASI and other optional mechanisms) will always be needed.
Why is everybody so insistent on running untrusted code?
Regardless of is this a trap or not, it's obvious to me that developers want simplicity and consistency. WA provides both so don't wonder why it's taking off.
> So instead of Linux/Windows/OSX we will have Firefox/Safari/Chrome/Whatever all with their own implementation gotchas
I let the compilers worry about this :)
Hopefully in 20 years, when people are talking about MetaWebAssembly to abstract away the platforms that run on WASM, you'll have a different perspective on what you've said here.
But then, this is what humans have been doing since we figured out stone flints.
But there probably always will be a safe flag that generates everywhere running binaries.
I think win is having free software or at least opensource apps that are trusted by distributors and easy to analyze/modify, and actually own (meaning have on your harddrive and fully control). And we already have that win.
There's a big difference between an imperative (e.g. arbitrary code) and declarative installation process. Imperative installation is most common on Windows due to the initial decisions made by the registry designers + the Windows Installer originating from Office and starting with imperative. Declarative installs are common on the Mac where "installation" usually means dragging a binary from the DMG to your Applications folder. OS X then manages OS integrations declared in an app manifiest.
Declarative installations delegate to a system which has a broader view and standard mechanisms to handle state transitions required for installs, upgrades, and uninstalls. Imperative installations frequently leave residue and are hard for even Windows to fix. I spent years of research and have several patents on trying to figure out how to distinguish between "extension points" of the OS and private state to create a sandbox with the necessary pinholes. Even with those tools handy, many software shops see no reason to upgrade because the Windows end user accepts a life of installers.
I see logic in starting from scratch. This time we can create an end user expectation of declarative and (laterally + vertically) sandboxed apps. Hell, that's what we tried to do with Windows 8, but it was unfortunately restricted to the "modern" (aka full screen) apps that never caught on.
It's still sandboxed, and limited, so what's cached this way is perhaps easy to totally remove by the browser. But that's not because of the declarativeness, but because of sandboxing.
sure, linux is doing that much better, but until we get linux (homebrew for windows?) installers for windows, i'll prefer webassembly, at least for casual use.
I was involved with Java applets when Java was in beta and one of the most annoying things was that JDK 1.0 did not come with serialization.
I would build applets that displayed content generated on the server and serialization-deserialization code could be 2/3 of the program. Most people had a slow net back then, so the download performance was a big deal.
JDK 1.1 put serialization in right away, but Netscape had already introduced it's own incompatible serializer, and there were delays in getting JDK 1.1, plus people didn't like Java serialization -- practically there was a year or two where you couldn't use it.
Applets had enough teething pains that people quickly came to the conclusion that they weren't worth the trouble, then Flash came along which came closer to what people wanted at the time.
Especially since so much of the internet was once on Flash and we're looking at the loss of historical archives.
The models for installation, security, privacy and updates on the desktop platforms have barely improved in twenty years, and they really needed some improvement.
The models for installation, updates, payment, portability and development tools on the mobile native platforms all have major downsides as well.
If you build and distribute your software as a web app, you can still do everything that matters for many purposes, you retain complete control of your own software, infrastructure and business model, and your app can work well with relatively little effort on a much wider variety of target platforms.
It's businesses that demand web applications, because native deployment (in-house or for customers) is a tougher sell. A lot of it has to do with the bad security model of desktop operating systems combined with the overhead of administration.
Last but not least, web developers are the biggest pool to hire from. It all adds up to where the benefits outweigh the (significant!) drawbacks.
Actually understanding more about JS and the browser, and actual application development, and how it fits are good places to start. I find that the browser model actually fits a redux-like master state machine better than MV* that a lot of experienced developers, but inexperienced web app developers tend to focus on.
It just depends. I think there's room for most players, and IU do think WASM offers a LOT or will as runtimes and standard libraries shake out. I'm looking forward to seeing things develop more... IMHO there should be a focus to standardize interfaces for Canvas, WebGL, Audio and FS first. When you can run an application against canvas 2d or webgl with audio and sqlite, I think that's a large way there. Better input support (controllers as well as kb/mouse) is also pretty high. I know people are working on these things.
Getting something that runs almost everywhere will be very nice and although there's some overlap with the intent of the JVM, WASM has more primitive options (for the good) and can support a greater range of sources to a single target set of interfaces.