Lots to See in Firefox 93
hacks.mozilla.org
hacks.mozilla.org
I've been out of frontend web dev for a while... does this mean the days of trying to find/create your own (good) datetime picker component are gone?
> it may currently still be best to use a framework or library to present these, or to use a custom input of your own. Another option is to use separate date and time inputs, each of which is more widely supported than datetime-local
https://developer.mozilla.org/en-US/docs/Web/HTML/Element/in...
Which browser does not support it (if we can exclude IE 11)? And if some obscure browser does not support, it will just fallback to input[type=text], so no big deal. I'm really looking forward to get rid of all these JS implementations which can't properly handle keyboard / touch / screenreader / whatever comes.
That's because by design <input> does not let you configure a timezone (EDIT: nor a datetime format), and it's always somehow badly detected/misconfigured on a small subset of your users. Later you find out the user thought they were entering a DD/MM/YYYY date, while the browser decided it's getting MM/DD/YYYY, and hijinks ensue. It's easy to ensure the correct timezone on js pickers.
> ...the date/time and time zone values would be submitted to the server as separate data points, and then you'd need to store them appropriately in the database on the server-side.
Which, IMO is the correct way, also for a datetime-picker, anyway.
[0] https://developer.mozilla.org/en-US/docs/Web/HTML/Element/in...
For example, one customer had all their computers default to MM/DD/YYYY despite locale using DD/MM/YYYY (and all other non-browser programs using the right format). So I ended up switching to js pickers thanks to the bad experiences.
>instead of replacing everyting with your self-built thing
There are about a million different js datetime pickers which provide the entire thing in a package, rather than me writing it all by hand.
Which was one reason they removed it from the spec. And why datetime-local does not have it.
And why adding a simple <input type=hidden name=tz value=""/> can be filled by your JavaScript that detects the timezone. Or, if you need, a <select> or something else.
Besides, once I need to write js it's just as easy to pull a datetime picker and use that...
I'd like to use <input>, but they need to make it work and also allow a reasonable way of overriding the autodetection.
> One thing to note is that the displayed date and time formats differ from the actual value; the displayed date and time are formatted according to the user's locale as reported by their operating system, whereas the date/time value is always formatted YYYY-MM-DDThh:mm. When the above value submitted to the server, for example, it will look like partydate=2017-06-01T08:30.
The problem is on the other end: The guarantee ("formatted according to the user's locale") too often doesn't work, the displayed date and time format somehow may not match the locale as reported by the OS.
In the previous example, users in EU countries can get a MM/dd/YYYY input despite the locale being set right. The user can enter a date thinking it's DD/MM/YYYY (some users preferred fast input with the keyboard), so what they send to the server is really YYYY-DD-MM despite the "guarantee" because the browser somehow doesn't understand how the date should be formatted on the client.
Otherwise it was just extremely annoying to the users and to me, so it was the last straw for using <input> that way. I could hack it, but what's the point of maintaining a hack when there are many packages out there just implementing a picker?
Here's how the native datetime-local looks: https://i.imgur.com/7kNficu.png
How is that different from most or any JS frameworks with regards to DD/MM/YYY formatting? How can a user filling in a date, confuse "12 juni 2018" (juni Dutch locale for "June") with the 06-12-2018? And if so, how does any JS based datepicker solve this instead?
Imagine your screenshot instead of '12 - 06 - 2018' had displayed '06 - 12 - 2018'. For the same date (12th June 2018). Because locale detection failed it fellback to the US locale**. And it set up the input so that '06-13-2018' is legal but '13-06-2018' is not. Does my example make sense now?
In a JS datepicker, I could force DD/MM/YYYY (or whatever according to the user record) and that's it. Timezones are also a problem, but that's indeed easier to work around. The issue is that the specification by design does not allow forcing a format, despite me knowing exactly what the user wants.
It may sound fantastical that locale detection can fail that badly, but it did, and nothing simple I did could fix that - I don't exactly have access to set up the client machines, but I could reproduce on one of mine. Note that matheusmoreira here in this thread also has this problem, so it's apparently not impossibly rare.
Old Edge for example, seemed to prefer autodetection via the keyboard locale*** over the region date settings, and that was a product by the OS maker! (Also, their date picker was trash by modern standards).
** I guess all browser makers are American companies so US is default? Or perhaps it went to the US locale by keyboard like old Edge, since just about everyone here uses the English (US) locale for English.
*** Setting up English (UK) fixed the date display. Except that comes with other downsides.
This is the entire point of datetime-local. And why other native date fields were dropped and replaced by this one.
I see 'browser will autodetect the right display format for the locale and give back YYYY-MM-DD' in so many words, which would be nice if it worked. The problem being it not actually working and not allowing me any good way to override it when it doesn't work.
To be sure I wasn't imagining things, I decided to test again, with the simplest example I could find on the net (I forget w3schools still exists).
Note the date format on the picker. I can assure the test system used had LANG, LC_TIME, LC_ALL, timezone, etc. all set to a non-American locale. I used Chromium to make sure this is on a typical(ish) browser. Still the MM/dd/YYYY format is used.
Happens to me every week. Sometimes nearly every day. It is infuriating. Why can't they use YYYY-MM-DD? When are we humans gonna stop having these problems?
It won't look and behave like how designers wanted in your company. It will look different in different browser and OS.
But designers, product managers prefer things they design.
Having looked at caniuse.com it seems that Chrome, Opera and (only just now by default) Firefox support it. With Edge, Safari, and the majority of mobile browsers still to catch up.
https://www.coywolf.news/webmaster/why-webkit-supports-avif-...
It could be my encoder sucks, could be I didn’t pick the right settings (command line opts look like the engineer’s console on the original 747). Most of the demos I have seen online with AVIF images are highly compressed images that look awful on close inspection. Maybe you can accept that for video but I can’t for my photographs.
I was disappointed.
Things didn’t materially improve when using high compression (slow) encoding settings. Could have been a bad encoder (libavif iirc)— there might be an explanation but on the face of it I saw worse performance than webp.
>> We learn information about you when you give it to us directly (e.g., when you choose to send us crash reports)
[0] https://www.waterfox.net/privacy/
Mozilla, say hello to my new little default browser friend.
I also have multiple google accounts because of it which are super simple to use in Chrome, the containers might cover that for me.
it is just not proeminent in the interface..
you can access the profiles in "about:profiles"
You can also have a shortcut for "firefox.exe -p" and it will aks what profile you want when starting..
or create a shortcut to "firefox.exe -P "Profile Name"" and it will open automatically in the profile you define in the shortcut..
But if you know about it, it makes no sense as a reason for you to stop using firefox. It only takes a few seconds to set up and you can do the same thing with themes.
> Also have you ever tried migrating profiles before Sync?
I have. You move the folder from one computer to another and the profile is migrated.
Unlike chrome, where that triggers some kind of "malware has altered the profile!" mode and it resets things. How do you migrate a chrome profile without sync?
In Chromium browsers when you click a link, whatever profile was last opens the link.
You also have to do some hacks to get FF profiles to use separate taskbar icons and they don't show a profile picture like Chromium browsers.
I work on various OSS projects for $smallcorp mostly.
For other things, I really want containers. For example, if I'm prompted to load my banking side from a google email, why yes, I do want to open this tab in my baanking container, thanak you for asking, Firefox. Oh, this is a link to social media? Please cordon that off to a separate container as well.
Profiles are good, containers are good, they both serve slightly different use cases and can be used well by the same person, so both should be first class.
Personally I think both options should be possible. Choice is good
For example I dont need every plugin I use for work while I browse the web & vice-versa.
Together with the integrated profile manager (Firefox.exe -p) its a really nice solution!
It appears to me that Google Chrome only has the option of "fully logged in with GSuite account where we track every damn thing you do" and "Guest" which is just private browsing, won't save any state, making it inconvenient.
It's creepy and presents false choice.
If the browser tries to connect directly to google that's something else.
Also it is an all around good browser.
Firefox is slowly losing users in all the countries in that list except in China. It's slowly growing there.
They really don't seem to understand the community that still supports them is exactly the community they're alienating with this.
(I'm going from memory here -- they deleted the relevant text on mozilla.org, replacing it with the apology paragraph).
https://support.mozilla.org/en-US/kb/navigate-web-faster-fir...
edit: Found an archive snapshot:
"Firefox Suggest is currently available for a limited number of users in the U.S. only" (deleted text)
>"In the future Firefox Suggest online will likely be expanded to other locales/populations."
https://support.mozilla.org/kb/navigate-web-faster-firefox-s...
> To help you find information faster, Firefox Suggest uses a service provided by us to offer relevant suggestions for what you’re typing. When you opt-in to improve Contextual suggestions, Mozilla receives your search queries. When you see or click on a Firefox Suggest result, Mozilla collects and sends your search queries and the result you click on to our partners through a Mozilla-owned proxy service.
Oh wow, stop the presses everyone.
I don't see it myself at all but that's because it was only enabled in the US so far
>When contextual suggestions are enabled, the feature uses your city location and search keywords to make contextual suggestions from Firefox and our partners, while keeping your privacy in mind.
I think the comments have merit if it was on by default but it's not. You have to explicitly give permission. I honestly don't see an issue with that.
Who the hell at Mozilla thinks that:
1) this is a good idea? 2) that they can sneak this by all of Firefox's tech-savvy users?
I mean, it just seems like such a low risk:reward ratio, what's the point? There's no way that this makes them enough money that it could be worthwhile.
Big difference and they can't be held to the same standards.
There is no war on privacy. It's gone, the war is over and we lost. This is a true "Et tu, Brute?" moment. I'm really disgusted.
Not at the moment, but long term they need to diversify their income. They lose users and the management doesn't work for free.
The VPN thing was a nice idea but too niche to count. I don't want a VPN linked to my browser anyway.
I'd pay for Firefox Sync though. I'm surprised they never made that paid.
Remember when you could make Firefox look and behave exactly like you wanted it to? Because I sure as hell do.
Looks like they are very well paid. So much that they had to let go 250 engineers last year.
Actually, they likely do need to sell ads if they want to keep Firefox alive.
https://www.zdnet.com/article/sources-mozilla-extends-its-go...
Tl;Dr: Mozilla gets no less than $400 million yearly from Google just by keeping it as default search engine.
I was happy to donate to Mozilla in the past, and would do again even knowing about the agreement with Google; I want to support them. But I'm donating to support development and promotion, not to make some rich execs even more richer. If that's the case, then I'll use my wallet elsewhere.
What if a fork was funded in a kickstarter like way, enough ideally to pay the salaries of the development team.
I'd happily pay ~$20 per month knowing that the money was going where it should.
I never accepted it. You force-upgraded me and opted in without consent. And then hang a 30 day window of data retention... If that's true at all.
There was no informed consent. No opt-in. It was just turned on without my knowledge. I had to find out on Twitter infosec to watch out for this.
Settings -> Privacy and Security -> Address Bar -- Firefox Suggest -> Contextual Suggestions -> Include Occasional Sponsored Suggestions
For me it's selected, so I deselected it. Still a good browser.
Edit: They do say opt-in, but the opt-in was in version 92.
[0] https://support.mozilla.org/en-US/kb/navigate-web-faster-fir...
Linux distro removed it? Or Firefox know apple, windows people will just put up with anything but linux people probably won't?
edit: Don't see it on an v.93 on an old mac laptop either. checkboxes for browsing history, bookmarks, open tabs, shortcuts, search engines only. I wanna yell fake news out of FF loyalty boosterism but I do actually believe you so I wonder what's going on?
Presumably they are trying to gauge the density of the resulting shitstorm before going all in.
Address Bar — Firefox Suggest
Choose the type of suggestions that appear in the address bar:
Browsing history
Bookmarks
Open tabs
Shortcuts
Search engines
Contextual suggestions (this was checked when i became aware of these settings and went to look)
Learn more
Include occasional sponsored suggestions (this was also checked)
Helps fund Firefox development and optimization.
Change preferences for search engine suggestions
Maybe that's why it isn't highlighted for new things for version 93.
To be honest, as a faithful Firefox user, I'm very hesitant to update my browser. A few months ago FF rolled out an abysmal UI update out of the blue, and I had to rely on third-party "fix" [0] to this problem. I really don't want to lose the "fix" due to update, the low contrast of default theme makes Firefox just unusable to me.
I wish there was a no-bullshit fork of Firefox with no Pocket, no Suggestions and Photon UI.
Epiphany needs a noscript equivalent so I can retire FF.
Turn off auto updates here: options-->general-->firefox updates
Did I ever mention I fucking hate automatic updates?
Is "royalty-free" an unequivocal good, or a good with caveats?
I would assume it means you don't have to pay licensing to encode or decode the format. Are there any restrictions?
Lol wat?
For reference - in a password hashing context, you generally don't care about about collisions. Its not really a relavent attack.
What you do care is speed and memory hardness. Generally you want a slow hash, like bcrypt or argon2, so that in an offline attack the attacker can't bruteforce very quickly.
Sha256 is almost as bad as md5 in this context.