Kristall – a browser without support for CSS/JS/WASM or graphical websites
kristall.random-projects.net
kristall.random-projects.net
All that to say, I'm not sure I understand the criticism I'm seeing here. A Lynx-like browser with proper graphical mouse support and a couple of extras built in is a fine project. And support for Gemini/Markdown gives the browser a clear use-case beyond HTML that means it'll be practically useful for some people; it's not just an experiment in failing to render most websites because it doesn't support CSS, there's a category of content that you know will work, and a community of people making that content.
That's assuming it works well, but if it does -- I don't know, seems like a cool project? It's good to have more Gemini clients.
Radio amateurs can communicate through the internet with their phones and it would be faster, simpler and easier. But radio gives them both the nostalgia feeling and a niche community to belong.
Gemini is kinda like that.
Limitations are a way of fostering community (ham radio enthusiasts all kind of get to know local operators, Jummbox makes sharing song sources in a digestible way super-easy). Limitations also allow you to not care about complications that would be barriers to building things -- I don't want to set up a VST before I start writing music.
So my feeling on Gemini has shifted from being a curmudgeon about honestly kind of really nitpicky, shallow stuff like the ability to mark-up inline language transitions -- into realizing that when you step away from thinking of the project as some kind of attack on the web then yeah, it actually makes a ton of sense to build a small community around a very limited format that forces everyone in that community to be standardized in how they share with each other, keeps the community a little bit niche so that the people in it are a bit more friendly and personable, and forces its participants to focus pretty much only on what they're writing and nothing else.
Look up "Carrington Event".
That's also how Gemini thinks of itself. I'm a fan personally, I'm all for projects that just go and do their own thing and do it well.
Kristall isn’t very useful for HTTP even though it supports the protocol. That said its goal is the “small internet” and very basic sites on HTTP will work, which is is inline with that goal. Some have complained even Google search doesn’t work, but Google search doesn’t fall under the umbrella of “small internet”.
When it comes to Gopher and Gemini it’s far more useful, but only a small community of people use either in 2023 so that’s not going to appeal to most people here, even though that’s the primary use case of the project.
It's 2023. If it doesn't work on google.com, it's not a browser that works on "The Internet" (due to conflation of terms over the years, people assume that "The Internet" means "The Web," especially when the term "browser" is mixed in there).
To be clear though, a much better user interface for retrieving and displaying small documents through gopher, gemini, and finger in addition to HTTP is pretty cool.
... which is fine, but I suspect the headline is throwing readers here off because they're equating "browser" to "web browser" and then the actual tool flips their bozo bit when it can't even properly render popular sites in a degraded mode. Perhaps the tool can use better branding: "A general-protocol Internet document browser that can also do some HTML," for example?
I also have a File-browser on my system and it has nothing todo with html or google.
>they're equating "browser" to "web browser"
Yes they also also say Cloud = Google-Drive, do you really want to go that route?
... but nobody considers the Arduino a "computer" in the same sense they consider a Raspberry Pi a "computer" because it can't run general-purpose apps.
Arduino is a Micro-controller, Raspberrypi is a SBC -> Single board computer.
>>and user community that designs and manufactures single-board microcontrollers
https://en.wikipedia.org/wiki/Arduino
>>Raspberry Pi (/paɪ/) is a series of small single-board computers (SBCs)
https://en.wikipedia.org/wiki/Raspberry_Pi
And no, don't start with your "but normal people blabla"...because "normal" people go to wikipedia to learn something ;)
I'm saying nobody considers an Arduino a "computer" in the same category as a Raspberry Pi is a computer (and similarly, nobody should consider Kristall a web browser, though it is something else, which is cool).
I run BSD/BSD on it and it's not a platform but a Computer.
>nobody considers an Arduino a "computer"
True, because it's a f*** Microcontroller understood?
And by analogy, Kristall is a "microbrowser" and I think HN had a bad reaction to it because the top-level description was "a browser."
It's the Arduino of browsers.
That doesn't make it bad, but this site is full of pedants and when you call a tool by a slightly-different name, you get "um-actually'd" to death.
(Sometimes, you even get someone swearing at you because they think you don't know the difference between a general-purpose small computer and a microcontroller ;) ).
This is a common trope I hear but I'm not sure it's true any longer.
One of the reasons Google login requires JavaScript to be enabled is to fix flaws in non-JS HTML that allow for hijacking passwords. It's why they took a much harder line on simple auth a few years back; too many instances of people being tricked into handing their Gmail account to scammers.
On the other side chromium devs need to develop quirks/hacks for specific sites in order to support their bloated javascript hacks (:
I find it bizzare.
https://en.wikipedia.org/wiki/Framekiller
It's one of those situations where "This was mis-designed with insufficient eye towards how right bastards could use it, but the cat is out of the bag. We can't change the spec because it'll break legitimate uses of this technology, so this is the best option we have." Similar to how images were naively scoped to be embeddable from any web domain and then people invented pixel bugs, but you can't change the security model around image loading without breaking vast swathes of the existing web.
That's never been sufficient to keep bad actors out because end-users don't grok the URL bar.
This attack is superior to a mirroring attack because it uses the target site's own UI resources, so it looks very legit (no need to pay someone to monitor the UI of the target site for changes and rework your exploit to attack them).
My mental model here is that the browser's password manager autofills a password that the user doesn't even know, and without scripting or dynamic resources, it's not possible to exfiltrate that data automatically. Without styling, form buttons would have a standard look so it's harder to trick the user into submitting something without knowing (c.f. the recently posted fake captcha that tricks users into revealing the visited state of links).
Edit: also, in a modern browser, passwords are autofilled by the browser which knows where input is going and can't be tricked. You could make an argument about other sensitive information, but that sounds like it's the same as plain ol' phishing.
Unfortunately, there's no language for querying the client "Do you support CSS" / "Do you support frames" without CSS so Google is forced to err on the side of caution and reject browser that don't support JS (because they can query that).
The hostility displayed towards an open source project in this submission is completely excessive just because it doesn't meet the requirements of many/most users. I'd feel awful if I were the creator of it and read the comments here, which are being extremely harsh about what is otherwise a very nice little project.
Personally I find it very useful, but I'm the type of person who would.
But it's not a small internet browser it's a small-internet browser. It is made to browse the "small-internet", which is not the same thing as the internet.
The World Wide Web is the collection of HTTP servers and "Web Browser" clients like Chrome, and, uh, Chrome. Also WebKit.
An "Internet browser" would be something like `dig`. Though, maybe that's better called a "DNS browser" in this boring world where every app that talks to one or more remote servers must be called a browser.
I haven't fully thought this idea through, but it does seem like it would be a manageable way to start a non-corporate browser that could handle modern layouts and some degree of interactivity without the mess of privacy and security issues that javascript introduces.
I think I remember reacting myself at least somewhat negatively to Gemini first time I heard about it, so on some level I understand how someone's initial reaction could be hostile -- but I also feel like "limited tools producing tight-knit communities and specific community-tailored content" is right up HN's alley, and I am also surprised to see so many people questioning why this should exist.
"It doesn't work for the majority of the web."
So? I assume the project isn't lying, it does actually support HTML. I just don't see how it's a bad thing to have a lightweight browser that handles static HTML; I don't think anyone is advocating that anybody uninstall Firefox over this.
----
I'll kind of go a step further here and give a mildly hot take: nobody should be doing normal browsing on an indie browser in the first place; I consider that a likely security/privacy risk. The vast majority of indie browsers do not have full-featured uBlock Origin support, they don't have the browser hardening features that something like Firefox ships with by default.
So on some level I feel like "can I use this to read CNN" is not necessarily a great metric to use for an indie project, because if you're reading CNN it should probably be in Firefox with uBlock Origin installed (or something comparable, but I typically advocate that Firefox and its derivatives have better tracking protection than other mainstream browsers).
In contrast, if something loads in this browser, what is your security risk? Limited MITM attacks and network analysis? I don't feel the same aversion I feel to most indie web browsers when I think about someone reading a limited number of indie web articles in this thing or building projects around it.
Yet it works on links, lynx and probably few other text browsers.
Sometimes small is too small
These projects do not have to appeal to large numbrs of people. The goal need not be large audiences for advertising.
I have no idea how many people use the same browser I do, that has not mattered IME and TBH I really do not care. Although I have seen on the project website that a number of companies made donations to sponsor certain features, and the company names and amounts are listed on the website. Those companies must have found the program useful.
Methinks there are just so many folks who have bet their entire livelihood and career on the asymmetry that the web has enabled, where its users are generally powerless and control nothing on their computers. Anything that could give control to users is perceived as a threat. This is highly dysfunctional, IMHO.
Even when such things have nothing to do with whatever commercial endeavors these folks are engaged in. I use HTTP every day via small programs I can edit and compile and therefore control. Everything works. I can do "industrial strength" web search without ever opening a browser. I find it hard to imagine these techniques would not be useful to others.
The internet needs need more projects like Gemini and Kristall.
Check out the arguments Google tries to make about its position as the "default browser" in this court filing from earlier this week. The company pays hundreds of millions of dollars to various parties in order to be the "default" search engine, its CEO himself was engaged in setting up such "payola" arrangements for Google prior to becoming CEO, but one would never guess that from the assertions Google is making here.
https://ia802501.us.archive.org/21/items/gov.uscourts.dcd.22...
What if these operatings systems were, by default, set to cycle through a list of search engine choices, randomly selecting one each time a search is submitted, until the user chooses one as the default. Over time, the user might become familiar with a variety of search engines. She could then make a more informed choice about which one to set as her "default". Instead, what we see in this motion is one "tech" company arguing that other "tech" companies think it is superior. Who cares what "tech" companies think. What do users think.
I thought the title was all wrong. It created false expectations. Too many people thought this was an HTML browser. I first came across Kristall when I was looking at GeminiSpace ( https://en.wikipedia.org/wiki/Gemini_(protocol) ) - the gemini protocol (a replacement for http(s)) plus GemText (a replacement for html).
Kristall is a browser for GeminiSpace - first and foremost. GeminiSpace has embraced some aspects of the legacy small-web - specifically gopher and finger. Lots of the browsers in GeminiSpace support all three: GemText, Gopher and Finger.
Some of these GeminiSpace specific browsers also try to support other types of markup languages (html, markdown) but that's not their primary use case.
I can see that Kristall is trying to be more than a Gemini Browser. It can do well here if it was clear about the level of html it was going to support. I'd be very happy with HTML 3.2 ( https://www.w3.org/MarkUp/Wilbur/ ) for example (mid-90s).
Unfortunately, it doesn't even do 'turn of the century' HTML tables very well - something that the lightweight Dillo ( https://www.dillo.org/ ) does well.
As Kristall's level of html support increases; I'd love to be able to include it as a viable html browser (similar to Dillo and a bunch of other older browsers I have installed). As a GeminiSpace Browser, however, it is among the elite. This should have been its intro to HN.
Meanwhile, this app is meant for browsing an unknown, undefined limited subset of the plain old HTTP web; and when you step out of that sandbox (and you most definitely will inadvertently do so) what you are left with is a broken experience. A web browser that goes out of its way to not support foundational basics is just a shitty web browser given that my normal web browser can hit the same sites.
How have I never heard about this before?
[1] gemini://gemini.conman.org/test/torture/
Triptych definition: a set of three associated artistic, literary, or musical works intended to be appreciated together.
There's also JGemini (https://github.com/kevinboone/jgemini), a cute little 107kb jar file that's also a full GUI browser. Yes! 107kb:-) Also x-platform and portable (java -jar ./jgemini-1.0.jar). Not many features (no tabs, just multiple windows) but it's a good example of how quickly browsing solutions can be built when markup is reduced.
That is... you don't need billions of dollars and a decade to present a viable solution in this space.
GeminiSpace actually reminds me much of the early days of the web. People will complain about the limited markup. For some users, the additional security/privacy of the protocol and the reduced 'noise' makes this appealing.
-----------------------------
Gemini (protocol), Gemtext format:
Can you elaborate on how react and angular have destroyed the semantic web?
In the old days you could look at at raw non-rendered HTML and it would be so simple that you can render it in your head.
With the advent of more sophisticated web frameworks like the one mentioned, that’s no longer the case. The site consists of MBs of scripts and templates that take a gigawatt to render.
On complicated scripts taking a gigawatt to render, I would like to point out that in the good old days that was all happening too — just not in your browser. Inefficient PHP and CGI scripts, massive Java frameworks. Today, still the majority of complexity and heavy lifting is kept away from our browsers. It's sobering to think that most of the gigawatts we burn on our phones, do not show up on our power bills...
For interactive sites, if videos were limited to 480p on mobile and 720p on desktop unless manually changed, I imagine the carbon impact of data centers would drop considerably. For content viewed on TVs (where you usually sit quite a bit farther back than a monitor), such as Netflix or Hulu, I think they could set it to 480p by default and a lot of people would never bother to change it.
Unfortunately actually calculating the carbon footprint of a bloated web (compared to a lite version) would be very difficult. As you mention, a lot of that bloat is on the backend. New Reddit may transfer 6x more resources over the network than Old Reddit, but both of them have to process on the back-end what links should even be shown for a given user, so I doubt switching to Old Reddit would result in 6x fewer emissions. But even if it only resulted in 2x fewer emissions, that'd still be a considerable improvement. Part of the investigation would require seeing how much energy is used by the data centers processing what to send, versus how much energy is used by ISPs transferring that data across networks to the end-users.
In any case, if sites were more like Hacker News, Craigslist, and Wikipedia, versus New Reddit, Amazon, and most news sites, I feel confident that the carbon footprint of the Internet would go down notably. HN and Craigslist's designs are going to be hard sell for most businesses, but something like Wikipedia proves you can have an attractive design with low page sizes. And in the case for newspapers, it'd be nice if their web versions were more similar to their paper versions. That is tough with a free + ads model, but honestly I'm more likely to see an ad if the whole site is just text and there's a text ad in the middle of it (hopefully properly identified as such, though.)
* JSON-LD markup exists in plenty of modern sites
* schema.org markup exists in some
* microformats.org briefly raised its head
The BBC website is the biggest example I know of which has a lot of semantic markup/annotations. IIRC they used to actually have RDF attributes in a lot of the BBC Radio listings
Then you have HTMLite verifiers (probably the simplest thing to verify!) to ensure a site is compliant and voila you need no Gemini protocol, only simple HTTP/1 and you can also render it in anything from Firefox 1.0 to Kristall to Lynx to Chrome 100+. As a bonus now you would also have very mature accessibility support thanks to modern browsers.
We already have the tools for smolnet. We don’t need to enforce it by removing features. We just need to define what little it should be.
Having said that, all the power to people who love tinkering this way instead. I just think it will be a hindrance to broader adoption and wasting a bit of flexibility and reach (in terms of both software and people).
> The problem is that deciding upon a strictly limited subset of HTTP and HTML, slapping a label on it and calling it a day would do almost nothing to create a clearly demarcated space where people can go to consume only that kind of content in only that kind of way. It's impossible to know in advance whether what's on the other side of a https:// URL will be within the subset or outside it. It's very tedious to verify that a website claiming to use only the subset actually does, as many of the features we want to avoid are invisible (but not harmless!) to the user. It's difficult or even impossible to deactivate support for all the unwanted features in mainstream browsers, so if somebody breaks the rules you'll pay the consequences. Writing a dumbed down web browser which gracefully ignores all the unwanted features is much harder than writing a Gemini client from scratch. Even if you did it, you'd have a very difficult time discovering the minuscule fraction of websites it could render.
> Alternative, simple-by-design protocols like Gopher and Gemini create alternative, simple-by-design spaces with obvious boundaries and hard restrictions. You know for sure when you enter Geminispace, and you can know for sure and in advance when following a certain link will cause you leave it. While you're there, you know for sure and in advance that everybody else there is playing by the same rules. You can relax and get on with your browsing, and follow links to sites you've never heard of before, which just popped up yesterday, and be confident that they won't try to track you or serve you garbage because they can't. You can do all this with a client you wrote yourself, so you know you can trust it. It's a very different, much more liberating and much more empowering experience than trying to carve out a tiny, invisible sub-sub-sub-sub-space of the web.
Lagrange (cross-platform) looks much better, and does zoom. In the terminal is nice too, I like Amfora (Golang single binary).
http, https are disabled by default, they need to be enabled in File/Settings/Generic.
I was hoping it would be a single executable but (on Windows) it's 56 files: 1 exe, 33 dedicated dlls, 22 translation files.
Google Search does not work, it's impossible to get past the cookie consent page: https://imgur.com/a/daGMASS (Same thing happens if one tries to put the search words in the url.)
DuckDuckGo doesn't display a search box either, just links about itself: https://imgur.com/a/UMLKiOv
No search box on Bing either; it's possible to access a page like https://www.bing.com/search?q=hacker+news for example, but the SERP is wrong and says "no results" whatever the words searched : https://imgur.com/a/J2Y4CU6
The modern web is hard to use with simple tools.
I believe Google will still work on very old browsers through something like user agent sniffing, maybe setting the UA to IE5 will trick it into rendering HTML that might actually work (though the search results will probably still be useless)
Nowadays you have to install an extension just to get this promised feature
But it's designed to work without CSS and scripts, I test it with w3m and lynx, so I hope kristall can deal with it too.
Edit: as ketzu points out (https://news.ycombinator.com/item?id=34351753), Kristall simply doesn't render form elements. Which makes it pretty useless ATM IMHO.
https://github.com/MasterQ32/kristall/blob/6b39f24484bb0796f...
The GitHub notes that they only support a reduced set of HTML, but not which set it is. My guess is they do not support any interactivity related elements.
https://www.dropbox.com/s/xtezzcsm2qcat8a/Screenshot%202023-...
All I can think is that it doesn't support canvas - which would have surprised me anyway.
I think that it's kind of an anti-tool-for-thought - meant to be an art piece or a political statement, and not a tool for getting work done.
I'm all in for a simpler Internet, but on HTTP(S), with images and other media if needed
And that is by design. Gemini is designed to exclude those features, because the target audience of this protocol wants to browse a web where those features are impossible to include.
Edit: The creation of new protocols and technical solutions alone increases cognitive complexity. From this point of view, it is even counterproductive if existing solutions can enable the same.
Its built-in limitations also inspires quite a lot of creativity.
Gemini cannot do a lot (which is by design), but it also has huge capabilities. For instance, while client-side logic is impossible, there's nothing preventing you from writing a "web app" that does its logic on the server side. Yes, you would require page refreshes to update what the client sees, but with Gemini each page load is much, much cheaper than HTML because the response payload is smaller to transfer and easier to parse.
Assuming that your Gemini client allows enabling inline images, there's absolutely no reason why you couldn't build a stateful web-app that is a clone of Twitter, Facebook or another social media site. There's no reason why you couldn't design a simple webmail client a la Gmail, or a system monitoring dashboard, or a bug tracker, or basically anything else that doesn't have to rely on complex layouts or inline video to do its job.
Some people had an idea, went out, and made it a reality, built a small community around it and now we have Gemini.
We should encourage such things. Projects don’t need to change the world and they don’t need to be useful to all people or exploitable by corporations. Building something because it’s fun, or because you want it to exist is good enough.
Toys are way better than startups and growth and monetization and disruption and onlyfans to pay the bills.
This "killed" Gemini from the start
Like this page https://memex.marginalia.nu/log/ is rendered from this code:
# Gemlog
=> /topic/ Browse by topic
=> /links/aggregators.gmi Aggregators
=> /log/feed.xml Atom Feed
This section of the memex contains what might described as a weblog.
%%% FEED
%%% LISTING
(the FEED directive tells it to generate an Atom feed, and LISTING to inline the documents list rather than put it in the side-bar in the HTML version)Gemtext is very close to what I want. The only thing I wish is that it had some rudimentary support for illustrative images. Not like inlined in the text, but at least centered figures. That would go a long way.
Gemini is fully encrypted
It simply doesn't rely on the same chain the CIA and other agencies own
inline images are left to the client implementation.
Lagrange supports them, for example.
The only thing missing to make it perfect is XUL addons
Gemini it's something else. It supports non 80x24 displays with automatic resizing and fixed-width text, among the images category.
So also known as TLS with support for evesdropping. I doubt even an expert would be able to browse the web securely in that model.
Yeah but this is not a browser for the web.
Gopher and HTTP used to be about as popular. Now we have other protocols like Spartan[0].
Got nothing against the idea. It is about the implementation. I care about retro hardware and minimizing requirements; they don't.
Spartan is cool.
Gemini’s TLS requirement prevents access by a of machines that could benefit from it.
Antenna is an aggregator feed for Geminispace. You can subscribe to it with a Gemini client that supports Atom feeds.
=> gemini://warmedal.se/~antenna/ Antenna on Geminispace
excluding mobile platforms
Really. I want Epiphany and Firefox to allow me turn off JavaScript like I can allow/disallow {Audio, Video, Webcam, Location, Notifications...}.
The single wrong decision was following Google into that JS-Show. JS has it rationals, I'm using it as programmer sometimes. But JS was consider harmful for the reasons! Google intention was using JS for it's so called web-application/single-page-application to lure users into the cloud. And they opened the opportunity for a bloated web with user tracking via JS, bitcoin miners via JS, animating all kind of elements with JS and so on. Result? Fan spins up, laptop battery discharged.
[1] http://links.twibright.com/
PS: I bet Steve Jobs would have banned entire Electron from MacOS. For same reasons Flash was banned.
uBlock Origin can do this, I believe. NoScript is a more involved solution, but it also still works. I don't know about Epiphany, though.
You can set a shortcut to enable JavaScript (“Relax blocking mode”, cmd-J for me. I don’t remember whether that was the default.)
You can persist enabled JavaScript for the current domain for the future.
I find that with JavaScript enabled on some 20 websites, the rest of the web works pretty well with the occasional cmd-J in case it doesn’t.
On mobile I haven’t found a good way to do it. Brave browser makes it easiest to enable/disable JS on the current page, among the ones I tested.
I still don't understand why it's utility is being questioned, when the entire category clearly has a user base.
You're right, there isn't yet here we are. Where I need to download and run a React program every time I want to read an article.
(IIUC, there was a proposal in Firefox decades ago to make the engine into several flexible modules and a page could declare which modules it depended upon, then the browser would either cache them and use them for multiple sites or already have them builtin. You'd get the best of both worlds: rich and expressive pages without the frequently-paid cost of poly-filling the gap between how the developer wants the render engine to work and the actual implementation of the render engine.
Sadly, I suspect the actual complexity to implement would have made for a worse overall situation than what we have now).
Where is the security? Chrome last I checked had eight actively exploited zero-days last year, which is laughably bad compared to the other operating system I use. Perhaps if the modern web was simpler, a browser would be easier to implement, and more time could be spent on making it not a raging security dumpster fire? But it ain't, it's complicated.
How does one even setup user agent stylesheets? What could that be but yet more complexity? Meanwhile, I'll use w3m and amfora and if it's a broken page that mandates Flash, JavaScript, whatever, I most likely won't bother launching a "heavyweight champion" browser. The CPU fans will last longer that way.
Edit: ^A modern browser
This doesn't match with current versions of accessibility software which either connects to a browser or simply bundles an embedded version of Chromium. The ship has sailed on no-JS websites sadly, and not supporting (substantially) all of CSS modules would simply render 90% of websites inaccessible.
If there is content/ads ratio problem, you just leave the site.