Firefox 93
mozilla.org
mozilla.org
Overall contributing has been very pleasant and the people on Mozilla's matrix channels have been helpful getting me on track. But better than taking my word for it, you should try contributing for yourself :)
Camino was the Gecko engine from Firefox in a "proper" Mac UI (unlike Firefox at the time, which was their cross-platform XUL UI). I used to use it as my primary browser and I really liked it.
What killed it was Apple launching Safari - which didn't use Gecko, but instead used KDEs QT-based HTML engine. They named it Webkit, Google later used it for Chrome - then forking it - and leading to the situation we have today where the two QT-derived engines (Blink and, because of iOS, Webkit) dominate.
Personally, I still use Firefox, mainly because I would like there to be another option, but I also use Safari (and I quite like the colour in the header thing).
[1] https://daringfireball.net/2021/10/the_tragedy_of_safari_15_...
Camino felt like a Mac app - and was the only real choice for that until Safari came along.
I see people write that. But I use Firefox because I truly feel it's the best browser out there.
This goes to the Mozilla Foundation and not to the browser's development. As far as I know there is currently no way to donate to the browser's development.
Electron is also popular and Mozilla could produce a Firefox-based alternative (whose selling points could be performance/memory usage/battery life) and provide commercial support.
Is it going to sustain extravagant salaries & bonuses for the C-suite? Debatable. But it can absolutely be a suitable business paying reasonable salaries.
Isn't that a lot like saying "those sausages with toothpicks in them at the supermarket" are not saleable products?
A lot of Mozilla's money seems to be spent on executive pay, overhead, and questionable side projects. Not so much (or not enough) on browser development, it seems. I'd MUCH prefer Firefox to be a product organization with its own budget and perhaps a yearly contribution from Mozilla. I have more faith in Firefox than in Mozilla.
1) The nonprofit Mozilla foundation
2) The Mozilla corporation
The foundation owns the corporation.
The corporation develops Firefox and is primarily funded by the Google search deal. It also develops pocket and the VPN and gets some funding from their sales.
The foundation is funded by grants and donations, both from individuals and from other organizations (including from the corporation).
In an ideal world the best browser would win but marketshare doesn't work that way.
Microsoft has full time development teams working on Edge and it is just barely chipping away at chrome's dominance. And, in no small part because they pester Windows users to make Edge the default at every opportunity.
import solution
and some additional fluff (tracking,telemetry and other anti features in Edge's case) did you really do your homework?
2. The story was no different even when they were still using Trident as their engine.
When 85% of people use the same browser stack we're back in the bad old days of IE6.
As someone who works on the digital payments/processing side of the house for a charity, I can tell you that accepting designations is a can of worms that smaller charities would certainly want to avoid.
it's not a small charity
Inertia and network effects won't change quickly though
Take this thread, for example: https://forum.palemoon.org/viewtopic.php?f=4&t=15168#p109681
"On the same period, Firefox marketshare was down 85%. When asked about her salary she stated "I learned that my pay was about an 80% discount to market. Meaning that competitive roles elsewhere were paying about 5 times as much. That's too big a discount to ask people and their families to commit to."
This lady then goes on and on talking about "social justice".
You can't make this shit up.
Yeah, put political pressure on technical teams to fuck up — it's a tradition.
If this CEO is providing value, I'm not seeing it.
PARTY!
I've been waiting for this for a long time. The last big hurdle for this was that color spaces weren't applied correctly.
If you haven't taken a look at AVIF, do. You can get a similar looking image in AVIF at half the size as a JPEG. I find AVIF's image artifacts preferable to JPEG's.
A great blog post on this by one of the creators of the format, Jon Sneyers:
https://cloudinary.com/blog/time_for_next_gen_codecs_to_deth...
I wouldn't be too surprised if every big CDN already does something like that internally as a competitive advantage, and if so then the incentives switch around and there's no benefit publically switching to JPEG XL - when everyone has it, there's no easy way to do better than everyone else.
For Firefox you need the nightlies I believe - I had no luck with release Firefox 93.
In Yinglish (Yiddish-English) jizzle would mean something like 'a drop of seamen'.
At least, JPEG-XL offers a solution on this side, like store as JPEG-XL and serve as old JPEG to IE11 users. Now, if only there was a JPEG-XL implementation for Java...
If you mean the image format, probably never. It's based on the HEVC/H.265 licensing minefield. For that reason, I don't expect it to ever be supported on Chromium or Firefox based browsers.
Having fewer browsers support .heic format would be a benefit -- as it would decrease the chances of the format surviving.
Edit: I found few examples here: https://colinbendell.github.io/webperf/animated-gif-decode/a...
https://en.wikipedia.org/wiki/AV1#AV1_Image_File_Format_(AVI...
When people were comparing it to GIF I specifically tried to check if it supported animations, but came up with little.
> AV1 Image File Format (AVIF) is an image file format specification for storing images or image sequences compressed with AV1 in the HEIF file format.
layout.css.prefers-color-scheme.content-override = 1
# An override for prefers-color-scheme for content documents.
#
# Dark (0), light (1), or system (2).
I use it to force webpages to use light theme while having dark browser UI elements (menus, tabs etc).My problem is that Firefox has a "snapping" scroll behavior that I find very annoying. When I move my fingers on the touchpad of my laptop, that does not immediately move the page. Instead, it waits until I moved a certain distance and then moves in one big swoosh.
Starting Firefox from the command line like this solves it:
MOZ_USE_XINPUT2=1 firefox
Is there a way to make this permanent or accomplish the same via a setting in about:config?
Although the scroll is more fine grained now, it looks kinda wobbly. Almost as if there is a raster interrupt at play, lol. As if the screen gets repainted mid scroll and then needs another round until the whole screen is updated.
export MOZ_USE_XINPUT2=1
into your ~/.bash_profile or ~/.bashrc (edit: or just ~/.profile under ubuntu).You'll have to logout/login to "apply" that.
Alternatively you can edit the .desktop file of Firefox, but that might not catch all the ways in which firefox may be launched.
So I guess it would also not work in .bashrc. But not sure.
Your .bash_profile allows you to set up the environment for your entire session.
I'm afraid each desktop environment probably has its specific way of adding environment variables.
Usually, PAM will load environment variables during session initialization; I'm pretty sure that's the thing that reads /etc/environment. See man pam_env; though whether it works depends on whether that module is enabled in your PAM configuration.
You can also have other things read environment variables. If a user systemd instance is launched that starts the rest of your session, that will load environment variables from various places (it also affects things launched indirectly through it, eg. via D-Bus, that can't inherit your environment from the shell)
The "last" level in a typical GUI session is the shell in your terminal which will read the "traditional" files, but they aren't usually very useful for GUI applications because the GUI applications generally aren't started from any process that has a shell in its ancestry nowadays.
Wiki for the curious: https://wiki.archlinux.org/title/environment_variables#Per_u...
You can also use containers on Firefox for isolating specific sites
Firefox can do that. Just run firefox -p.
>tied to an account
Is that really necessary?
Yes, I'd like extensions, history, cookies, etc to be tied to the account and have them be isolated. I can't do that now.
You can log in into accounts in each profile, of course, if you want.
Simply start it with "firefox -P" and create two separate profiles (call them "work" and "personal"). Then just start two instances of Firefox, with "firefox -P work" and "firefox -P personal". They will be totally isolated - cookies, history, addons, everything.
Ideally they'd expose more options through web extension APIs or build in a native profile switcher in the main ui rather than as a command line flag and a dedicated about: page. It'd also be cool if the account containers could be customized to behave like profiles e.g. isolate history, but that gets a classic "we need to do this yak shave first" response whenever it gets brought up.
For me, one profile with "Temporary Containers" and "Multi-Account Containers" works well enough.
Alternatively, you can start Firefox with `--no-remote -ProfileManager` flags to get a totally separate instance, like Chrome does.
Personally, I use Multi-Account Containers together with the Temporary Containers add-on, to by default get a fresh cookie jar for each new tab, but I do have some websites tied to a named container for session persistence.
But Firefox has a much better feature: tab containers. You can attach a label to a tab, and only tabs sharing this label will share states, such as cookies, cache, localstorage and so on. This means you don't need to open a new window. You can have 2 HN accounts with each a different user logged in, in 2 tabs, next to each other, distinguishable with a color.
You can use it by activating a few settings in about:config (https://support.mozilla.org/en-US/kb/containers#w_for-advanc...), but the easiest way it to use the addon : https://addons.mozilla.org/fr/firefox/addon/multi-account-co...
Not. On. Android.
https://github.com/mozilla/multi-account-containers/issues/1... https://bugzilla.mozilla.org/show_bug.cgi?id=1283320
Multiple browser profiles also let me have one profile for work, another one for personal stuff, and yet another one only with stuff like vue/react/svelte dev tools and remote debugging enabled, and _then_ decide which one to open at any given time. This instead of opening every container at once, or something like selectively opening a bunch of bookmarks manually into a specific container (I use buku to manage and sync my bookmarks too, so no tab container support there).
The second part of this feature is that for <iframe sandbox="..."> elements, regardless of HTTP/S origin, Firefox will no longer allow the iframe to initiate downloads unless the sandbox attribute explicitly includes allow-downloads
It appears that there are a pair of preferences in about:config to govern these: dom.block_download_insecure and dom.block_download_in_sandboxed_iframes
When reopening FF, e.g., after restarting Win or Linux, all FF windows are restored to a single virtual desktop, even if they were on different desktops previously. Chromium-based browsers don't seem to have this problem.
They tried fixing it a few times [1,2], but the bug persists, and I am not aware of any add-ons that could serve as workarounds.
0. https://bugzilla.mozilla.org/show_bug.cgi?id=372650 1. https://bugzilla.mozilla.org/show_bug.cgi?id=1401143 2. https://bugzilla.mozilla.org/show_bug.cgi?id=890125
There a few more bug reports that I didn't link to. I have just found one saying that the bug will be fixed in FF 94. I don't have high hopes because this bug seems to come back from the dead soon after being fixed, but fingers crossed!
https://blog.mozilla.org/security/2021/10/05/firefox-93-feat...
Maybe they will show up eventually in the list of security-related blog posts? https://blog.mozilla.org/security/category/security/
EDIT: Looks like that link works now
This is why I can't switch to firefox, chrome is better at this, doesn't wait until 'system memory is critically low' and supports all platforms not just windows.
I don't like them (automation doesn't make the same choices I would), but I do use an extension which allows me to manually unload tabs.
https://developer.mozilla.org/en-US/docs/Web/HTML/Element/in...
[0]: https://developer.mozilla.org/en-US/docs/Web/HTML/Element/in...
I've been waiting for some of the more advanced options of <input type="range"> for ages. <input type="color"> is supported but often a bit clunky in its implementation. Hence people don't use them, hence they don't get improved.
Some sort of drag and drop reordering widget would be really nice as well
https://developer.mozilla.org/en-US/docs/Web/HTML/Element/in...
Once. Coming up on 5 years ago now for me. Every time since, I log into sync, and it appears with all of the proper configurations already set up to my preference.
It shows a clear case of mission statement in conflict with business model and shakes my confidence of Mozilla as the champions of privacy and freedom they paint themselves as.
Keep in mind that they don't even need to make it built in, they could instead bundle ublock origin as a preinstalled add-on and provide a little bit of money to the developer. It would simultaneously improve the security and browsing experience of many of its users while attracting many new ones and funding the fight against invasive online advertising.
But big daddy Google would get so cross then and Mozilla would be forced to adopt an actually privacy respecting alternative like duckduckgo and lose a lot of their funding.
I don't want to main Brave as I currently do, both because of its use of chromium and my ill feelings of the CEO's donations to political movements against the LGBT community but Mozilla management have lost my confidence over the years despite the actual deveopers remaining world class.
I don't think Google would be as mad as every other publisher on the internet who relies on ads for their living. They would go on campaigns to block Firefox from their websites entirely. They already rail against adblockers with full-site popups and blocking content until you disable your adblocker, making adblocking a default would escalate the situation exceptionally quickly.
Firefox's marketshare would drop even more quickly if people couldn't visit their favorite sites with it (and were likely directed to Chrome or Edge).
Without an alternative, readily available method of monetizing websites, it's realistically going to have to remain opt-in (i.e. installing uBlock).
This whole argument is largely invalided by the mere existence of Brave anyway. You could argue that their crypto based mode of monetisation is not the absence of rather the reimagining of ads but regardless of how you feel about crypto, it's definitely superior for the end user and offers effective monetisation that is optional.
Also, you can choose to disable all the crypto and still get the built in adblocking. With Firefox, you can only turn to add-ons.
(Google)
How's it do on battery life? How often does it turn out to be the culprit behind system-wide performance problems, if you've just got it sitting open in the background while you're doing other stuff?
[EDIT] FWIW, FF user since Phoenix & Firebird, haven't loved it since IIRC FF3 (yes, 3) when it started to bloat itself into being the sluggish, huge thing it replaced. I still use it on my Windows gaming desktop, but that's because I barely use the browser on there, and it's plugged into wall power. Safari 15's UI is god-awful though, so I'm primed for a switch.
Mind you, HTTPS doesn't mean downloads are safe. Not remotely so. HTTP just means they're way less safe, and if you're on a HTTPS website it definitely should not be serving downloads over HTTP
[0] https://twitter.com/codelemur/status/1052285395575164929?s=2...
1: https://developer.mozilla.org/en-US/docs/Web/Security/Secure...
Mozilla: Okay, done.
The Venn Diagram of people who forgo managed hosting with SSL built-in and set up their own servers to host HTML pages on the internet and the people capable of following a guide to configure certbot is a circle.
And what of those who have left their old site (that has no need for TLS) online for years without ever knowing 'insecure' HTTP is being deprecated? I don't think their sites breaking and showing warnings should be acceptable when the security benefits are so marginal.
Let's Encrypt has made installing a cert a 5 minute process, including setting up automated renewals.
Even at lawyer rates ($200/hour), that's still less than a one time $20 "cost".
Look I get it, if I hosted sites on shitty providers and couldn’t change because of corporate BS I would be frustrated too. But “everyone else should change to accommodate my problems” isn’t the right response. It’s the same with crappy SSL middleboxes, I feel for people who have to deal with broken sites because of them but breaking TLS as a workaround can’t be the way forward.
> Targeted users in Turkey and Syria who downloaded Windows applications from official vendor websites including Avast Antivirus, CCleaner, Opera, and 7-Zip were silently redirected to malicious versions by way of injected HTTP redirects. This redirection was possible because official websites for these programs, even though they might have supported HTTPS, directed users to non-HTTPS downloads by default.
Talking about certs, nowadays it seems browsers want to make you believe that self signed certs are some diabolical work straight from hell. Using self signed certs with websockets on Firefox is actually nearly impossible [1].