Microsoft Edge Experimenting with a Super Duper Secure Mode
microsoftedge.github.io
microsoftedge.github.io
Websites doesn't require JavaScript, what really needs JavaScript are Singe-Page-Web-Apps-Somethings with anti-patterns like infinite scrolling. You get two things in return, a "super duper" fast web and a more secure web-browser. For example Amazon supports usage without JavaScript very well. Another experience is Stackoverflow, things like the preview and highlighting doesn't work. The highlighting can be added with server-side code but this will cost some CPU-Time - and it is not your CPU-Time. It is their CPU-Time? There is tiny feature I would appreciate in HTML-Engines "copy link to location" instead of using JavaScript - but there is this usable hierarchical address-bar a the top (which Google tries to hide) which already serves this purpose.
I'm not against JavaScript. JavaScript is just a tool but I ask the question if good websites require it? Hackernews uses 134 lines of JavaScript, this is alredy nearly nothing. Can you imagine using Hackernews without JavaScript?
My webbrowser (WebKitGtk) provides a permission panel for every website:
* advertisements
* notifications
* password
* location
* microphone
* webcam
* media
A first step would be adding there JavaScript, too? Maybe some nasty Cookie-Dialogs will disappear as consequence. But that is not a loss?
How would we accomplish this sort of UX without javascript?
Some sites I've accidentally browsed without NoScript makes me question how people access sites with JS enabled at all. There are some shockers out there.
Edit: here it is https://news.ycombinator.com/item?id=16319248
I foster myself some weird JavaSript to allow hardware-access. But I think business itself should not be the driving force for the technical development and society.
It‘s simply like having an automatic transmission in an ICE car.
The motor type is an implementation detail the user does not want to care about.
I want to press the pedal and the car accelerates. What happens in the background does not concern me.
Same for websites.
If I see a list that is larger than the height of my screen, I want to be able to keep scrolling until I decide to stop.
I do not care that the creators of the website have structured their database so that the current DB would return 573738 entries.
I also do not care that the way the developers decided to present the application to me (via a browser) means that every row entry is a HTML element and showing 573738 HTML nodes at once would slow down the browser.
I just want to keep scrolling (and will stop after a few hundred rows anyways).
Having these kind of ivory tower fringe opinions like „infinite scroll bad“ is gate-keeping by middle-aged backend devs that panic at the speed and impact of the frontend world, plain and simple.
Most of us humans have an urge to finish things, but infinite scroll by definition never finishes. This increases engagement of users by utilizing their psychology, which is basically the definition of a dark pattern.
There is an argument to be made that it also increases usability, so it's inception probably wasn't malicious. But it's definitely another product of today's addiction driven design philosophy if you just look at the psychological effect it has on users
Your problem is with pointless dark-pattern ridden attention-grabbing social media using that tool (and rightfully so!).
Now imagine a useful application, like an email program.
Infinite scroll is useful there.
Imagine having a paginated inbox!
The pagination is a nice break and lets me know I am done, everything on back pages has been previously processed.
A better case for infinite scrolling would be chat history, where you'd want an entirely separate UI widget for "jump to date", with bidirectional infinite scroll that unloads distant content, and a way to grab permalinks. Missing any one of those features, or the fact that messages will never be re-ordered for marketing purposes, infinite scrolling becomes a hinderance.
Finite scroll is a compromise that you get some amount "you are here" context from scrollbar thumb size and position. If you are interrupted you can generally visually guess about where you left off, maybe.
Infinite scroll is terrible tool for an inbox because you no longer have such context. Scroll too far and the scrollbar thumb changes size because new items came into view. Most infinite scrolls entirely hide the scrollbar thumb because it is precisely so useless. Try to resume where you were in your inbox after an interruption and you have no idea how far to scroll down, and you can't just use the scrollbar thumb and hit an approximate spot. You have no context for where you are, you are lost in an infinitely scrolling maze of items all alike.
Even if infinite scroll wasn't a dark pattern (and it is, there's enough behavioral psychology studies now that have gathered enough evidence that infinite scroll feeds addictive behaviors), it is a terrible tool to work with if you are trying to get stuff done. It has none of the context of "you are here" and "here's how you can come back to where you were if you need to leave". Both of those things contribute to why it is such a dark pattern. Both of those reasons are strong reasons why it is an anti-pattern anywhere you expect people to work/to get stuff done. Pagination is great for getting work done and infinite scroll is awful. Finite scroll is alright compromise between the two for some apps.
That algorithm breaks on infinite scroll.
Now, of course the ideal way to read a book is probably a navigation/outline sidebar on the left, and then the content of the current chapter in the main pane.
Kind of like the Rust book: https://doc.rust-lang.org/book/
Of course why would you have a problem with that, the only navigation one should perform while reading is change chaper, who wants to go to abitrary paragraphs.
On the contrary JavaScript developers that don’t contribute to open source cannot write two lines of code without some disgustingly bloated framework and a million dependencies to do half their job for them. You can’t even get hired without completely caving into the stupidity. It feels like cult membership lighting money on fire.
> Classic elitism, and it shows your hand as a gatekeeper. Not cool.
Cry me a river. I am not being elitist by suggesting you should learn to do your job. I really don't care how uncool it sounds or how many tears you shed.
I am not sure what you or the downvote brigade want here. Do you want me to feel sorry for you?
This is also one of the reason I'm hoping more people write in Gemini, because it's just text
> Can you imagine using Hackernews without JavaScript?
It definitely works, it's just a very few small features that need javascript. The most important for me is the ability to collapse sub-threads, which is mandatory when reading threads with lots of comments.
I think that covers 90% of my needs. If we could get that without enabling JS. Some function could move back to Server at the expense of more CPU cycle.
Although pushing more features to HTML isn't exactly a great idea either.
And if I remember correctly, writeable memory pages were the main reason why iOS banned browsers like firefox from embedding their own rendering engines.
Perhaps this kind of approach could address such concerns and enable other rendering engines.
Facebook buying two of their competitors resulting in crickets.
I would be interested to see how this affects the performance of websites that make use of complex JavaScript for things like charting/visualization (like the D3.js demos, or online formulae graphing tools), audio waveform rendering/processing, games, and other complex uses of JavaScript (including things like vue, react, bootstrap or other JavaScript UI frameworks).
Most people won't alter those settings, so whatever is "trusted by default" will run faster. The average user will just note that some sites are very fast, while others are very slow.
There is a sizeable subset of people who are curious and do care, and who would be eager to try that "one weird trick that speeds up <hot web property du jour> 200%" spreading through their Telegram group.
But for the most part, non-technologically inclined people seem to have a Hindu cow-like frustration tolerance when it comes to technology. If Windows takes twelve minutes to boot and your browsers viewport has shrunken to the size of a postage stamp due to toolbars, then that's just the way it is.
I would wager that for them, site Y running half as fast as site X matters a lot less than you think.
There are lots of things could be done to even the playing field. Eg require all browsers to come “out of the box” with with zero sites trusted.
This would incentivise regular sites to not use heavy JS, if they knew they won’t be JITed by default.
And by all means, if you use say Salesforce, by all means trust the site. But that tiny bit of friction is a good thing imho, analogous to running ‘chmod +x’ on Unix.
In general, I think it’s time to say that browsers should have a more refined security model, and letting every darn site on the internet access to run code on your computer is maybe not a great idea.
I wonder why JIT was put on in the first place. I mean if it has little to none end-user impact when removing it. JIT sounds like a great deal of doing nothing except for creating 50% of all bugs.
It this a case of JIT was meaningful when first introduced but overtime advances in other area has made this obsolete/redundant?
The users will have less power of the content on their browsers with compiled code and something like ad blockers become challenging to implement again. I'm not really big fan of this trend. For example Google Docs is being rewritten to use canvas and who knows what it actually does behind the scenes.
For something we do have networking protocols.
I know, I know! "Super Duper Secure Mode For Professional Enterprise Datacenter Unlimited Seats"
edge://flags/#edge-enable-super-duper-secure-modeDisabling CPU's speculative execution on untrusted code (browser) too
I'd guess it's safer than JIT because the translation to assembly is simple, or can be simple. It's not trying to do the complicated process of analyzing a dynamically typed language and applying different ways of optimizing.
> Disables the JIT and enables new security mitigations to provide a more secure browsing experience - Windows