But as a streaming technology, torrents are still pretty great. And like it or not, being able to run in browsers is a major advantage right now.
The case the author is going after is downloading a large Debian distro, so in the use-case of large, distributed file distribution there will always be solutions like the author.
1. video streaming
2. centralized sources like news websites
3. sharing in group chats
End users don't really download large files like Debian outside of gaming and OS updates. To that end, Blizzard Downloader [0] uses BitTorrent, and Windows 10 uses some similar p2p system [1]
[0] https://wow.gamepedia.com/Blizzard_Downloader
[1] https://www.pcworld.com/article/2955491/how-to-stop-windows-...
Donating bandwidth to a community torrent for the general good is not really the same thing as donating bandwidth to a for-profit corporation. I'm much more inclined to do the former than the later.
Someone is actively working with the maintainer of libtorrent (popular implementation of BitTorrent) to get support for it into the library: https://github.com/arvidn/libtorrent/pull/4123
[0] What are those? Plain Old TCP Sockets?
[1] You mean, WebRTC, right?
This would obviously require majority of the torrent clients to implement WebTorrents as otherwise it wouldn't make sense and you'd exclude more than you would include. If I'm not mistaken, libtorrent is used among many of the open source torrent clients, and so I think merging this code would suddenly give WebTorrent users an enormous amount of peers once they all upgrade. For client implementations upgrading is probably requires next to no code changes.
You close browser = close WebTorrent = you stop seeding
You stop watching video = you stop seeding it
Long and large video file? = if most people watch at half of video, then data from beginning is already out of the buffer = no seed for first half of video.
To this day there is still no support for WebTorrent in other popular Bittorrent clients so they can't connect to each other. But there is some movement in libtorrent library so we will see.
A quick glance at the webtorrent readme says it uses UDP on node.
There is a webtorrent desktop app in beta that does both.[0]
Here's hoping it makes it to libtorrent. Even then, I'd imagine it would take quite a while to make it into the clients running on seedboxes, desktops, etc.
It's more convenient, it's safer, it sucks for other torrentors because I don't seed as long, but let's be honest, most people downloading torrents don't care.
Of course, you could make the personal decision to trust a client, and that is fine. But if you aren’t willing to blindly trust a client, the other guy’s point still stands - browsers are probably just the better choice here from a security POV.
And as the original article demonstrated the first half of that is a weekend project.
They also have a monstrous attack surface because they are "web-facing". A specialized client that only implements one protocol without any connection to the "web" is far easier to reason about and debug.
If you only consider the number of man-years an application has been battle-tested, you imply that design complexity and attack surface doesn't matter. If we account for complexity by using a metric like "(man-years of battle-testing)/(magnitude of attack surface)", a well-tested specialized client that hasn't had many recent bug reports is a much safer choice than anything running in a browser.
> blindly trust a client
That's even worse for the browser: you have to trust several orders of magnitude more code implementing a massive set of interdependent features. Yes, there are probably a lot more people working on fixing bugs in the browser, but there are also a lot of people adding/modifying features and thus creating new bugs.
My sibling who isn't a programmer. They would have no clue what is trustworthy or not. Downloading random executables from the internet is not a good idea. How should they know qbittorrent is safe as long as it's downloaded from www.qbittorrent.org but utorrent is basically malware? (Or at least was for awhile).
They already know they can trust firefox and chrome, so it's better for them to just do that.
That's before you get to questions about security of the clients, security of the website you are downloading the torrent clients from, etc.
OTOH, `apt search torrent` on Ubuntu probably doesn't recommend any malware. Though their GUI nowadays promotes snaps and I'm not sure how much that is better than random executables.
If you’re worried about how “sketchy” it is most busybox applets can be read through and totally understand in a few hours tops.
But you're missing the point, even if it did it wouldn't be a torrent client non-technical users can use. It's not me, a programmer, who I'm talking about here.
https://github.com/DiegoRBaquero/BTorrent/issues/71#issuecom...
I'm much more concerned about "real" viruses like ransomware that the browser does successfully protect against.
For a dedicated torrent client to infect your PC with a "real" virus, you'd need to download the torrent and execute the file yourself (PEBCAK). I trust my own judgement much more than some random webpage.
Or in other words torrenting becomes no worse than everything else you do.