It's not like Gecko is an inherently inferior engine by any stretch, and it would significantly bolster their marketshare so that developers actually have to test against it.
It's not like Gecko is an inherently inferior engine by any stretch, and it would significantly bolster their marketshare so that developers actually have to test against it.
For most users, the web browser is one of the biggest attack surfaces and having arguably the best security team behind the browser engine is a good thing.
Yes some of that might be thanks to PZ, but that’s beside the point, isn’t it?
Choosing Mozilla’s platform would have been better for code diversity, which has its own distinct security benefits.
Like if you have 3 different crypto imlpementations, you have times more teams that have to get a thing right. It seems way easier to try and get it right just once.
Perhaps there's a holistic idea of "if one browser has an issue, at least it doesn't affect 100% of them" but given what CVEs look like in reality (often variations of the same attack across multiple programs) it seems like the cost/benefit would not be in our favor
This happened with Cisco routers back in the day, Juniper had to add a flag to make a routing protocol compatible with Cisco because Cisco implemented it wrong but had so much dominance that Juniper had no choice if they wanted to get in the game.
Not everyone gets hit with every attack. Biological systems work this way too.
Without serious competition you eventually get IE6.
Is this really true? someone posted somewhere(can't find it) where it shows Firefox has a worst security record compared to Chrome.
Also, in the past, Firefox was left out from hacking browser competitions because it was to easy to hack.
Outside of the security teams, I think it's actually that Chromium is much better fuzzed and scrutinized. They just have so many more resources, including those for security.
Most of what I've read relates to Microsoft products - and I'm not saying that Microsoft is better/worse than the rest when it comes to security.
The web is the safest, most battle-tested sandbox environment to run apps in. It’s so safe that you click random links all day long, running 1000s of apps and never have to worry.
I’ll take web apps over native apps from a security perspective, thank you.
There are better ways to sandbox applications in 2020.
This is true despite the fact that on iOS, sideloading custom apps without a developer account is extraordinarily inconvenient.
What's sad is that Windows 98 fully supported desktop-based HTML+JS apps ("HTA Applications"), with access to native resources (using COM via `new ActiveXObject`) and it works with IE11 still - Microsoft just never pitched it as a serious development platform for some reason. Just imagine what today's world would be like if Microsoft did pitch HTA as a successor to VB6 (instead of the quickly-abandoned WinForms platform, now barely on life-support) (I'm mostly thinking we wouldn't be stuck with excessive memory consumption in Slack, and these apps would be able to use things like native context-menus and accessibility features)
That would have been a security nightmare.
Sadly, that doesn't make it wrong per se, just deeply discouraging. It makes me think we're past the point of no return.
---
> I don't see why it's Microsofts responsibility to do whats worse for their products, users and business just to bring some sort of benefit to Mozilla which has awfully mismanaged over the past 10 years or so. The browser monoculture didn't happen over night it happened thanks to years of neglect from the other browser engines. I don't like this situation and don't even use Chrome myself but this is the reality of the web today.
I would wholeheartedly agree with you if Firefox Quantum wasn't so damn good.
I didn't use Firefox for years except for occasionally testing sites. Quantum blew me away in terms of rendering speed; it reminded me of Chrome in the very early days. I know that benchmarks say Chrome is still ever-so-slightly faster, and I can't explain that, but Quantum legitimately feels quicker when I use it. At worst, it's certainly not a downgrade from Chrome.
I do wish Firefox's interface was cleaner—the pocket integration and similar stuff just feels like icky clutter to me—but I've been able to mostly clean it up via about:config tweaks, and none of that's relevant to the rendering engine.
That Firefox managed to do all of this with much more limited resources than Chrome, and despite how many sites nowadays are built to target Chrome specifically... it's seriously impressive. I'd love to see what the engine could do with Microsoft's additional resources behind it.
So we switched to chromium/Blink in late 2015. Much later, when I visited Apple in early 2017, a devrel friend asked why we couldn't use WebKit. A WebKit founder in the meeting agreed with me that there was no way for Brave to do so on Windows w/o running out of capital. DRM again was an issue too, without WideVine. Don’t blame startup for not carrying a full engine — that needs deep pockets. While MS does have deep enough pockets, it is starting by using chromium/Blink and slow-forking.
The reason you gave here for Brave not choosing Gecko (or WebKit) is interesting – but given Microsoft's deep pockets and tech know-how those reasons don't apply to them.
I think this is a strategic blunder on Microsoft's part and I say this as a Linux user. :)
Microsoft has now warmly embraced Linux – and I think they could have chosen this time to warmly embrace Mozilla. Oh well.
I hear what you're saying – but! – a tech giant has to play the long game. The Web is an open (for now) platform and Microsoft, like Apple, like Google, need to have their own web client/server implementation. Makes no sense to be beholden to Google imho.
I'm stunned at how little desktop browser share Edge has (4.6%): https://gs.statcounter.com/browser-market-share/desktop/worl... – however, changing browser engine is not going to change that, is it? I suppose, if Google and Microsoft end up equally and democratically sharing Chromium development then all's well.
Given the recent layoffs at Mozilla it's a pity (in hindsight – for the benefit of the open web) Microsoft didn't back them :(
Anyhow, thanks for the response.
In 2001, Apple could have picked Gecko but forked KHTML instead to create WebKit/Safari because it was smaller and seemed easier to work with.
It doesn’t change the fact that back in the day, high profile companies picked WebKit—Google, Blackberry, Nokia—for their browsers.
In 2013, Google forked WebKit to make Blink and nowadays, Microsoft, Opera, Brave and others have picked Blink/Chromium for their new browsers.
Even as Mozilla is making great strides with updating its engine (was Gecko; now Quantum), nobody else is going on that trip with them.
"I can code in X so I should be able to jump in to any other language and get to speed instantly." is obviously wrong.
You can nest functions nicely and work with closures when it makes sense, if you like that sort of thing.
The async programming model is also really nice to work with.
You also don't need to create classes for every noun, verb, and adjective in your system either - when all you need is a function, you just write a function, not some weird object to hold it.
You also don't have to write a f after all of your decimal values to tell the silly compiler that you mean for 0.25 to be a float. (this one truly does not matter, but there are a lot of little things like this that add up)
I know you can do a lot of that in C#, but its just so effortless in javascript. You just need to be more disciplined about how you code it
I finally got transferred to the client team one whole month later, in early May. Then I had ten days to demo-day.
Why do you feel compelled to make up a story? Because it sounds nicer to you to denigrate my work, it seems.
Because randos on the internet (especially business types) love to make stuff up in the name of puffery and deifying. Legends are rarely true.
Thank you for clarifying.
So, thank you very much for laying down the foundation for a whole generation of new programmers!
https://www.youtube.com/watch?v=aX3ZABCdC38
Friends from SGI recruited me (second attempt) in March 1995, I joined in early April but in the server group. I thought a lot -- but worked too little due to server commitments -- during the month of April, about "the scripting language" which was suggested to be Scheme when I was being recruited, but which by the time I joined could not be Scheme, due to the impending Java deal between Netscape and Sun.
Java meant either no scripting language, or a kid-brother language, which meant C-like syntax, primitive vs. object types as in Java, and other unfortunate consequences.
When I transferred to the client group in early May, I had to produce a demo very quickly. I chose first class functions and (barefly there at first) prototypes as the building blocks. The rest is history.
The Belgium Post built a whole web app+service architecture on LiveConnect.
Think of LiveConnect as "Active Scripting" on MS's platform, which enabled Java components to be developed and glued together by JS.
Edge still has (had?) so many rendering issues on sites we make. One thing I find really impressive about Firefox, despite the completely different engine I _very_ rarely find FF-specific bugs.
Many (all?) Oslo postcodes start with 0, and their site truncates the 0 when you try to enter your postcode. Their stated solution was to use Chrome, so they don't get any of my business.
[1]: https://www.w3.org/TR/html52/sec-forms.html#number-state-typ...
> User agents must not allow the user to set the value to a non-empty string that is not a valid floating-point number. If the user agent provides a user interface for selecting a number, then the value must be set to the best representation of the number representing the user’s selection as a floating-point number.
If Chrome is your only target, the standard ceases to mean anything. The real standard is just whatever Chrome does.
The usual answer to that complaint is that Gecko is harder to embed. MDN pages on the subject even mention it’s deprecated and that the documentation is obsolete.
[1]: https://servo.org/
I think it will be around anyway btw, although I'm perhaps less sure.