Bootstrap v5: drop Internet Explorer support
github.com
github.com
If you're B2C you can probably ignore that and just not support it, but if you're B2B where you're selling not to users it's very hard to get away from supporting IE11.
If your users never directly interact with you (for example you sell white-label software which gets resold) then you just can't control your end-user tech stack enough.
If you're selling to partners who sell to companies who push out logins to their customers or user base then even if <1% of users use IE 11, that becomes 5% of companies having a user with it, which becomes 30% of the partners who are asking for IE11 support.
It's one thing to turn down 1% of users it's quite another to annoy 30% of your income stream.
As long as bootstrap 4 is supported (and the legacy bootstrap 3 support suggests it will be) then this doesn't have to be a problem of course, just one more thing to be aware of.
We run a few customer portals and a customer facing ticketing system. Until now I’ve never been able to rid myself of IE 11. It’s very nice. Small banks aren’t so happy.
Some even come back with feedback "Hey this other stuff works now!"
I like to think we're helping make the world a better place ;)
Granted while the leverage is nice, supporting those customers can be a bear.
Having said that some are pretty well known large companies, but the business units that sort of operate on their own if only due to their archaic nature. The company has a policy, it just doesn't always apply to them.
Logistics is a weird industry ;)
Like every logistics organization does something some weird way (carrier, client, end customer, everyone's accounting...), they're sure it is the right way, and then the next one does it the "right way" another way and now nothing is a 1:1 ;)
Lots of old / skewed / strange practices that requires a lot of unexpected maintenance / changes. It's easy to end up swimming in a lot of bad / not equivalent data.
They will whitelist super old known insecure java versions / windows versions etc that can NEVER change. I remember having to downgrade to windows 7 to access one VPN setup (yes - to get through the security firewalls you had to downgrade the entire stack to something the "security" firewall handled). I think this all was in part because they don't patch / update, so some stuff (flash / activeX etc) just doesn't work well on a modern machine
Ironically, they also would let their key domains expire but thankfully folks just would call a helpdesk and get an IP address to use (but these domain endpoints were 100% being hit by downgraded / unpatched machines so if someone had purchased the domain it would have been bad news).
For some places that were not inside an agency we had had to keep the "secure" machine separate from the actual network because it was the most vulnerable.
Thankfully, the help desk was so overwhelmed with calls about this horribly fragile system that they would reset anyone's password over the phone, so user lockouts were easy to handle, call up, ask that so and so's password be reset to XXXX and done (virtually no authentication other than knowing what number to dial). This was critical because the passwords had to be changed every 30 days and were insanely complex - we had lockouts even though folks thought they'd written them down properly right next to the machine (cap / lower / number / letter confusion issues?).
Meanwhile, my google account has proper two factor authentication, can be accessed from most any modern device, rate limits and screens login attempts in a smart way, and I haven't had to change my password in 15 years (so I could pick a hard one I don't use elsewhere).
Fun times!
They are sold this as a virus filtering requirement or something like that.
But some agencies literally decrypt everything going out (and then re-encrypt) - talk about a security and privacy risk!
Staff can use personal phones to check bank balances, do messaging etc if they have any sense at these places.
Thankfully this all died WAY WAY down with certificate pinning - thank you google! Seriously, when the execs got the warnings from google chrome the decrypt everything situation died at a lot of places.
Google's history on securing users using chrome is not bad (if you are dealing with old IE etc chrome is basically heaven by comparison in terms of security and patch velocity)
Then we had to develop most of the times in a virtual desktop so the frame rates were like 10fps and getting animations right was notoriously hard. Now the backend seemed like a cake! I quickly moved out of there and I'm much happy about that decision!
If you combine paranoid-level security with non-technical and often lazy users, and add cost-cutting all around, you get something like described here.
I know that from my father working in the IT department of a large corporation.
It's really something.
B2B can mean you're locked in to supporting things you otherwise wouldn't.
IE8 support adds significant cost and effort, but because of our customer profiles, we must maintain it. Our leadership understands the issues and is working to change the situation, but the inertia in this field can be astoundingly hard to overcome.
Holy Sh*t. That means a: users can install software and b: they listen to some vendor telling them to install stuff. I'm shocked either still happens.
Why can’t vendors refuse to support IE11 on the grounds that it’s a security risk? If you reframe the problem to “IE11 is insecure,” surely customers will adapt?
[0] https://www.zdnet.com/article/microsoft-security-chief-ie-is...
[0] https://www.theguardian.com/technology/2015/jan/30/flash-you...
I understand some companies insist on IE11, but companies insist on a lot of “requirements” that aren’t actually necessary if you push back on them. When the rubber hits the road, if your software is truly the best/only option, they can find a way to use a secure browser to access it.
"Killer app" only works in the consumer and small business spaces these days.
"Killer app" came from Visicalc, which caused millions of accountants and businesspeople to buy Apple II machines.
At my org we use Chrome or Edge as the default and define ie11-only sites in group policy. When you navigate, IE11 pops up automatically.
As an aside a company I used to work for was so underwater on tech debt that instead of modernizing their site they repackaged IE9 as a citrix app that business partners had to run. People are willing to overlook a lot when the commissions are good and that was not the worst thing I have seen in the insurance space.
As a side note, I would guess most non-GSuite users are logging into their Google account on Chrome and getting a unifed bookmark, whereas if they sign into a MS account at work/Edge, it will have to be their work Office365 account, breaking their unified browsing experience.
The only reason we have this big conversation about "supporting" different browsers is because one single holdout has been that bad for so long.
And to even MS's credit, I think a large part of that has been the fact that they're not "evergreen" (i.e forcing all users to be on the current version). They've always been doomed by the fact that "what they're judged on" isn't their current work, but is usually the version that's _almost a decade_ out of date.
Companies have lots of pieces of software that they support for extended periods of time. Also, they typically avoid requiring users to use different browsers for different applications. The number of support calls goes up dramatically if you need users to use different browsers, and it causes usability headaches when linking from one system to another, because you can only have one default browser. If you bring a piece of enterprise software into any organization, they will want you to target the browser they're using.... so, targeting IE was written into the requirements well after it was a good idea, because legacy compatibility was required. That, of course, works until MS throws a wrench in the works and discontinues the browser.
SaaS will change this somewhat, because the software is continually updated by the vendor. It's mainly on-prem and/or custom applications that cause this issue, because they don't get upgraded until big bucks are dished out.
Which is precisely why Chromium-based Edge has an IE Mode that uses Trident for given sites so that those legacy systems can be filtered to use a different browser engine from within the same browser UX.
Between ~2010 and the January release of Edge this year, a lot of organizations were dealing with the scenario I outlined.
Although as recently as this month, I've run into scenarios where Chromium-based Edge acts a bit differently than Chrome... so it's not a solid solution in all cases.
I mean the Edge team will treat any such case as a bug if you report it.
- Convince bajillion dollar investment banks to switch web browsers just to use our service
- Accept a mild decrease in developer experience
The clients I work for are all still worried about losing business due to dropping IE11...so we don't.
They have no analytics on which devices generate income, so it is hard to have that conversation. We know that IE11 hovers around 3% for most of our sites, and I doubt that many of those hits come from legitimate users, let alone someone who is going to purchase something.
The biggest issue with IE11 from a corporate IT support perspective is that it is not cross-platform so it adds another platform to test and validate against. Most organizations have to support some level of Mac usage for software developers and executives, so it makes more sense to officially support only a single browser.
When users arrive on IE11 and need to use the app they are always able to fire up chrome/Firefox/edge.
The only users with an old browser and won't/can't upgrade have had win7 + ancient Firefox.
Then your company must not have any customers in security-conscious industries like healthcare.
Any well-run IT department doesn't just allow the company's employees to install and run any old browser they want because a web site told them to do so.
I am forced to support IE11 because a very large number of doctors, hospitals, and other healthcare providers use it. These people cannot simply "fire up chrome/Firefox/edge."
A well-run IT department should be able to provide its users with a modern and secure browser. Why does your definition of a well-run IT department include the requirement that software installations should be restricted, but not a requirement to avoid using insecure and outdated software?
I believe one can make a compelling case that the continued use of IE11 within the healthcare industry is unethical, as it provides a known attack vector by which people's data can potentially be stolen. Stop giving them a pass on this.
Seriously though, the IT-only-allowing-IE11 hasn't been a sales or support blocker in the last couple years, as it has been for me in previous companies 5+ years ago, but YMMV
Every site like Stack Overflow or Google Docs that doesn't work with IE11 helps convince decision makers that maybe their IT department should actually get with the times
We've had to maintain support for Safari which has been very problematic since they initially released WebRTC support but not exactly bug free. That said it's a joy to develop for the web now without worrying about IE
And slow to adopt banks who's check scanner software STILL depends on some ie11 feature. Edge support is coming "soon" which apparently includes the past 3 or 4 years.
So even if you can convince them to use a different browser, be prepared to tell them how to configure the browser to be the default one.
However, there's a big difference between 4% of users and 4% of market. Not everybody out there is a customer, and not all customers buy equally. So the revenue falloff sill surely be smaller.
Typical browser stats also don't account for what people do if something doesn't work. Having browser issues surely will cause some lost sales. But even the least tech-savvy of people will try something on another device, like their phone, or ask somebody to do it for them. Making the revenue impact even smaller.
- For some websites (e.g. government) it is important not to "lose" even 1% of the potential userbase -- it's another type of accessibility
- For some websites, IE 11 usage will be considerably more than 1% in the first place
I. Rename IE11 something like "MS ActiveX Runtime For LOB Network Apps" (AXR for short) or something like "MS ActiveX Player".
II. Create an MMC console entitled "AXR Domain Manager" that identifies a list of domains that open in AXR instead of the default browser. This list is controllable via group policy and other MS management tools.
III. Modify IE where if a website not in the aforementioned list is accessed, a popup saying "This site will be opened in your default browser" appears and the link opens up in the default browser.
It would make it so much easier to explain to non-technical people that IE11 is really a legacy app engine at this point and shouldn't be used for modern website usage.
https://docs.microsoft.com/en-us/microsoft-edge/deploy/emie-...
> If you have specific websites and apps that have compatibility problems with Microsoft Edge, you can use the Enterprise Mode site list so that the websites open in Internet Explorer 11 automatically. Additionally, if you know that your intranet sites aren't going to work correctly with Microsoft Edge, you can set all intranet sites to automatically open using IE11 with the Send all intranet sites to IE group policy.
Since we switched from jQuery to Vue last year, we put a friendly reminder on each page saying IE11 is not supported (since its ES6 support sucks), but the tickets still came in. Finally we installed a header on all B2B sites that pops a modal error saying please don't use IE11. The tickets stopped abruptly. I was expecting complaints, but the majority of them already have alt browsers installed, so instead of asking, in this case forcing them to use a different browser worked much better.
[1] https://stackoverflow.blog/2020/03/31/building-dark-mode-on-...
For instance if your business model is to sell to/support highly regulated industries or govt users you are effectively forced to support their current user base configs or lose that share of the market because the choice for them is deal with a huge change to their requirements and support (which move at a glacial rate) OR chose a different vendor for your provided service.
I hate supporting IE, but that has always been the appeal of bootstrap for me.
But they can't really stay relevant and keep supporting IE.
As much as i hate ie11 we have to still support it as its used in many businesses using our softwares
Besides, replacing jquery May indeed be why they chose to drop IE right now. One of the biggest selling points of jquery, and one of the biggest contributors to its heaviness, is cross browser support including IE.
As one of the comments in the linked issue points out, dropping IE11 means they can also start using basic JS constructs, like Array.prototype.forEach.
Array.prototype.forEach is supported from IE9.
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...
EDIT: It is the nodelist api that isn't supported in IE. Not Array.prototype.forEach.
Quite a lot of these basic JS constructs even if they are missing (most aren't in IE11) are very easily polyfilled.
Personally I think it is fine that they drop support if they don't feel the need to support it. Bootstrap 4 isn't going to vanish.
And with time, your product that's built on Bootstrap v4 (or earlier) is only going to continue decaying.
Of people who actually order:
36% Chrome
26% Edge
19% Firefox
19% IE11Of people who actually order:
44% Chrome
32% Edge
23% Firefox
Unfortunately total orders will drop...During the weekend this kind of traffic drops significantly, which means to me that people using IE have to, and not choose to.
As a consumer, being told my light bulbs won't work with the new fixture is a great reason to no longer work with that provider.
As a provider that knows this, I'd rather support the old tech stack right up to the point my ability to keep the lights on isn't at risk.
We don’t use Bootstrap, but hopefully this encourages the companies that do use it to usher their users to something more modern and secure.
We were almost forced to find another library or write our own but we were able to find articles where Microsoft had said publicly that they no longer consider IE11 a browser and it shouldn't be used. It saved our hides.
Typically if 25% of my users use IE11, I will just make sure it works with IE11. If I have to stay use an older version of the library I will just use that unless I can polyfill or patch the lib to work with older versions of IE.
Then again I am kinda strange in the fact that if it should work in an old browser (and time permitting) I will normally make sure it works well enough that it is functional in that browser.
I think that’s the point.
Those who want IE 11 support will stick with 4, whilst those who want the latest can upgrade to 5.
Unfortunately, lots of users (mostly older) still associate the internet with "Internet Explorer". Simply telling them to use Chrome or Firefox solved the issue in a lot of cases.
And this was on a pretty big media company with a large digital footprint.
So dropping IE is almost a service for them.
Source : french administration with thousands of employees.
I push as much as I can to POs / stakeholders to just disable non-critical features on IE11 and just leave the basic functionality.
I doubt anyone using IE11 likes that fact, so sounds good to give them just another reason to complain about their experience to their superiors. I will definitely never see "The product that just works on IE11" as a slogan, so being competitive in this won't be reasonable argument.
Lots of emails come around saying use/don't use IE11 for this operation because half the time it doesn't work, and half the time the sites being linked aren't standards compliant.
As an ex webdev it's hard not to be annoyed.
Bulma claims 90% compatibility with IE11 at least. Foundation 6 seems to support IE9+.
This can certainly be true.
The amount of revenue my company generates from IE11 users is at least an order of magnitude more than its Chrome, Firefox, and Safari users combined.
We build an IE compatible marketing and sign up flow, so I may only be seeing the motivated users' behavior
They may. They may also just hit the back button. One of those actions requires much less inertia than the other.
Right now its the same front end stack (Vue, BS4) for both sites, and re-build and re-test for IE11 infrequently, so we're not paying the cost constantly.
Stay on Bootstrap 4. It will be supported until late 2021.
By extension, can we classify IE usage as a disability? Only half joking: I imagine a lot of current IE users are either doing it because of work or because they are technologically illiterate.
Nobody likes to support IE11 but dropping support moves Bootstrap 5 from "just use Bootstrap" to "Bootstrap has tricky pitfalls". Before someone can use Bootstrap 5 they need to be sure and confident that they don't need IE11 and never will.
As of now, Bootstrap 5 cannot be considered for use in any website with heavy use from enterprise users.
Edit: though it is nice to see that Chromium Edge is already catching up to Spartan Edge!
It's another story if you are selling, but if the users must use your application, they will click on the other blue e icon.
https://i.postimg.cc/FzBj9Ttp/Screenshot-20200407-084447.png
In practice we find solutions, such as installing chrome or using mobile devices. I know it depends on the domain and the country, but companies with outdated desktop pc running only internet explorer are becoming rare. We prefer to refuse one of them than wasting time supporting outdated environments.
I'm more receptive to backwards compatibility concerns than some in the thread. But when IT admins have new software available, disable and block it arbitrarily, and then complain that new services aren't supported by the old software, I lose my patience.
The only reason anybody has ever given me for disabling Edge is that users find it confusing. If you haven't educated your users on Edge and feel that they are only appropriately trained for IE for the past 5 years, you're not really trying to roll forward with the industry and you're going to be left behind due to your own stupidity. No sympathy.
We gotta move forward. The web can't be held hostage over decade old corporate contracts.
It has gotten to the point where IE11 in a VM is my main browser for testing and debugging.
IE11 lives on because many corporations run software that requires it.
There's a network effect, because links don't open the a browser that's compatible with the destination, but in the same browser as the link. So the corp with one IE11 app wants to serve their intranet home page in IE11, and so they want everything to run in IE11.
There are mitigations and migration paths, but that's all swimming up-stream -- it incurs risk, and costs time and money -- so it happens slowly and only in spots.
To use Bootstrap 5 you have to answer this question: are corporations my customer, or could I ever pivot to a business strategy where corporations are my customer?
If you don't care about money, then you can just answer no if you want, and you'll be fine.
But the consumers you can reliably insist run modern browsers don't pay for websites (not directly), so if you are running a business you are either committed to an ad-driven model, physical goods model, with no b2b option, or you're going to keep IE11 in-play.
I just don't think most people want to make a far-reaching commitment about the nature of their future business before they develop their first web page. (They do it all the time, but not on purpose!) A framework like bootstrap should free you from coming to grips with all that, but bootstrap 5 pushes it into your face before you are probably ready for it.
> If you don't care about money, then you can just answer no if you want, and you'll be fine.
You come off as weirdly bitter and hostile here.
Obviously when you choose tech, you have to weigh the pros and cons. It's part of our job. Why is it not our job when picking the foundation framework for our web client?
If you need IE11 support you can stay on Bootstrap 4 (we're still using Bootstrap 3!) or any of the other CSS frameworks. What's the problem?
Also, most people aren't in a position where they might accidentally take on corporate business in the future, either. Seems like a weird niche position to hammer on. And if you were in that position yet you chose a framework that, what, only works in Firefox unstable nightly, then you made a bad call and maybe you'll learn from the decision. So what?
Seems like weak reasoning for Bootstrap to never push the envelope when there is still Bootstrap 3 and 4 available. That's why they cut a new brand each time instead of just bumping semver on the same Bootstrap product. Every major version hop is basically a new framework.
If the bootstrap team is looking at their (or even average) ie11 %'s to determine if they should drop support they are really making that decision blind. It would instantly take bootstrap from a viable framework on many sites to a deal breaker.
I mean, if you're writing for IE11 that's true of any library or framework you might consider, even the ones that "support" IE11.
If you're still supporting IE11 I don't see why it's so weird to do so with Bootstrap 4.
I used it excessively 6 years ago. Then the v4 took an eternity to release and I already switched to different solutions.
I would have thought that people that are still using it are doing so because of legacy support.
Like how YouTube basically killed off IE6: https://www.theverge.com/2019/5/4/18529381/google-youtube-in...
As long as people don’t have a reason to change, they won’t. I say you drop support now and consider yourselves lucky that you can ditch your more difficult and problematic customers.
I mean, of course, I know this isn’t a realistic course of action for everyone. But I wish it was.
Eventually, the web will just break (for example, http/3), and IE will be forced to retire.
We just need the "right" pieces to break before it can retire in peace.
Being that it is still an early Alpha, this change may not have a significant impact for a while.
Seriously: 90% of the value of bootstrap was homogenizing browsers and making horizontal positioning easier. Both these issues have improved dramatically, with browsers converging and CSS Grid becoming available, respectively.
At this time, bootstrap offers little more than a somewhat more opinionated set of margins and other defaults than what browsers ship with, plus some higher-level components.
Why would the developers of a Bootstrap-based site that works fine overhaul it completely for CSS Grid, which has far less backwards compatibility? What would be the benefit?
Bootstrap is more than just a layout grid, it's also a UI framework, so abandoning it would mess up things like tabs, accordions, modals, etc.
Using Bootstrap isn't going to make your site less accessible or less secure.
the same could be said for jQuery, still less and less people are using it
That is why BS5 can afford to drop jQuery as a dependency. Developers working on highly performant apps where ops/second matters would already be using vanilla JS, and that's what BS5 is trying to support with this; jQuery doesn't play well with React/Vue after all.
But devs that are working on CMS-style websites, which make up the majority of actual websites on the internet, can continue to use jQuery if they want to.
Among the downsides is its size, obviously. I also consider the html it encourages among the ugliest things since the invention of PHP. This is from the documentation:
<button type="button" class="btn btn-dark">
Classes such as “col-sm” are little better than style=“...”. While accessibility seems to have improved over the last years, my intuition is this happened in spite of the idea of semantically meaningful HTML being abandoned and not because of it. I used to worry about this, but had to abandon that particular fight for the sake of my mental health at about the time someone decided to name one of these frameworks “semantical”.But with CSS Grids and Flexbox, layout has become just as easy and actually more flexible than using Bootstrap. Why would you add code and become pigeonholed into one framework when you could archive the same using vanilla CSS?
It's open source and can be forked and modded to your heart's content. How is that being pigeonholed?
Most developers don't work at companies where they roll their own UI components, and have QA and accessibility experts that can determine if their in-house accordions, modals, etc. are ARIA compliant.
The business case for switching over has to go beyond "it's vanilla CSS", especially if time can be better spent improving the user experience or product features.
But consider how CSS files easily become append-only junk drawers. And you may have to scour arbitrary files just to see what CSS affects this one button on this one component on this one page. And even if you find the CSS that you think affects the html node, you have to open your browser and use inspect element to see if there's anything that cascades over it. Meanwhile, a simple class doesn't lie.
And CSS doesn't even have native mixin reusability like `.form button { @mixin button } `.
There are clearly trade-offs here. For example, it's a huge deal when modifying complex UI to see these classes inline and being able to change things in a single file without the indirection of a CSS file.
You can get a chip on your shoulder about your arbitrary views on what is right and wrong, but people clearly find these non-semantic classes useful. I've worked at a company that had very purist views on how CSS should be written where there were almost no classes in the html, and it was very hard to make large UI changes without credentializing in multiple CSS files. There is no free win.
Some of us need opinionated defaults like these in order to ship something that looks decent. Can you suggest an alternative set of opinionated defaults?
If I was building a node website which depended on a bunch of packages from developers who may or may not care about IE11, this would not be possible. But since I’ve done the entire design by hand with HTML and CSS for over a decade, I can keep it IE11 compatible without issue. Also, everything works if Javascript is turned off, and there are reasonable (if not great) fallback fonts for users who disable webfonts.
(also, please let's cut it out with the "young developers" stuff. I've been around long enough to see lazy developers both young and old.)
It’s also perfectly readable in browsers without CSS and Javascript, including Lynx. Dillo and Netsurf both have CSS implementations so broken, some versions of those browsers have rendering issues unless they disable CSS.
It is possible to make a website which renders in Lynx, which is perfectly readable in IE6, which can be read in a browser without CSS or Javascript.
The first half though...we have grateful degradation for this reason. There's no reason to serve larger woff fonts to all users when it is so easy to use it as a fallback, preferring woff2 when supported. There are a lot of simple ways to improve the experience and data consumption for modern devices without sacrificing functionality in IE11.
I also add about 10k to the combined font stack file by adding hinting which is only seen on 75dpi displays, because too many users are still using low resolution monitors.
The main reason I use woff fonts and their approximately 120k size is because the days of “font-face: Verdana” giving (almost) everyone the same looking website are a thing of the past with Android smart phones everywhere.
If you do use this method, I highly recommend testing both the standard loading method vs Base64 method on a low spec device (e.g. Moto G4 via WebPageTest) and seeing which performs best for your website.
This method used to be used on GOV.UK until we removed it 18 months ago. I wrote about the change here if you are interested: https://technology.blog.gov.uk/2018/10/04/making-gov-uk-page...
I have had issues with a single font file sometimes hanging when trying to load it, so having them all in one file is also more stable; I plan on getting new hosting soon who will hopefully not have those kinds of issues. I also very aggressively cache the font file so it is only loaded once every six months for people who have been to my web page before.
It’s possible to avoid having base64 fonts block the loading of the page by putting the relevant <style>@import url('/fonts.css');</style> at the bottom of the page, at the expense of having a “flash” before the font is loaded.
I enjoyed reading the linked blog entry. One thing which stuck out is how you guys are able to interact directly with the type foundry to get them to make the web fonts smaller. I don’t have that luxury, but I do very aggressively subset my fonts, and I use zopfli with its most aggressive compression setting when making the WOFF fonts. I also use the Bitstream Charter font for italic and bold serif text, since that particular font is a very nice looking open source webfont with a very small size (download time) footprint. The main body text of Bitstream Charter is a little too thin (thin strokes) on Windows + Chrome (but it looks fine in IE, older Edge, and Firefox) especially on low DPI displays, so I use its (using more space and longer load time, alas) sister Charis SIL, a Bitstream Charter variant with thicker strokes, for the main body text.
One final thought: I think I still have an old Moto G3 with WiFi I can use to test things on that platform.