Show HN: BrowserBox – do stuff with browsers that you can't normally
github.com
github.com
I think a feature comparison would help show why someone should pay that premium. What does BrowserBox have that the others are missing?
[2] https://www.cloudflare.com/plans/zero-trust-services/
Edit: Clicking "Purchase" shows that the pricing is actually $50,000 for a pack of 50 seats, so 51 users would need 100 seats at $100,000. That's misleading.
Thanks for the pricing comparison! And the tips! I really appreciate that.
I thought we made the pack of 50 seats clear! I see it’s not, thank you, we’ll fix that.
I mean honestly we could run SaaS instances of Pro for a fraction of this cost, with 24/7 availability, and even less if you "amortize" it over a pool that supplies an instance on-demand.
I am talking about the Java ME application. Not the more recent browsers they’ve made.
> It was primarily designed for the Java ME platform, as a low-end sibling for Opera Mobile
> […]
> The functionality of the Mini mode is somewhat different from a conventional Web browser, with the amount of data which has to be transferred much reduced, but with some loss to functionality. Unlike straightforward web browsers, Opera Mini fetches all content through a proxy server, renders it using the Presto layout engine, and reformats web pages into a format more suitable for small screens. A page is compressed, then delivered to the phone in a markup language called Opera Binary Markup Language (OBML), which Opera Mini can interpret. According to Opera Software, the data compression makes transfer time about two to three times faster, and the pre-processing improves the display of web pages not designed for small screens.
https://en.wikipedia.org/wiki/Opera_Mini
Interestingly I found that someone has written a script to convert OBML to HTML. Their intended use-case for the script is to make pages saved with Opera Mini viewable in other browsers. But to me the main interest is that I would like some day to make something similar to Opera Mini on my own, and the README of the conversion script has some technical details about OBML.
> because OBML files are the output of Opera's HTML rendering engine, many elements are pixel-positioned according to the original device's screen size and font metrics. Because many J2ME devices had custom fonts (optimized for low-res screens), it's possible that your computer will show the same text as too-tall or too-wide, and lines may overlap.
> […]
> OBML does not have <a href=...>, i.e. you cannot actually have text that is also a link. Instead the engine outputs text and links as two separate layers – first it places the actual text at position (X,Y), then overlays it with "link" rectangles at position (X,Y,W,H).
> […]
> OBML does not have styled widgets the way HTML would. The style is actually pre-rendered, and those pretty 3D effects are made out of pixel-positioned lines and rectangles. Even button gradients are pre-rendered and drawn as a series of 1-pixel thin lines.
I can definitely confirm that Opera Mini was one of the more usable browsers back in the day. I think I remember using it on a few S60 Symbian devices and when sites worked, they did so really well and you could open dozens of tabs with no problems. I actually miss those Nokia phones and computing back then, hah.
I used Opera Mini (not Opera Mobile) on a few Android devices as well, because the built in browser was too sluggish in comparison. I recall about 3 open pages causing issues on an Android 2.0 or 2.1 device, though that problem more or less persisted to some newer budget devices, too.
It is just with my newer devices that I've switched to Firefox on the mobile and find it largely sufficient nowadays (though now Chrome would also be okay).
They also used to publish a really interesting report called "State of the Mobile Web" for many years based on the data they collected running their proxy service: https://web.archive.org/web/20140704014910/http://www.operas...
> [...] I would like some day to make something similar to Opera Mini on my own [...]
That would be great! Unfortunately I think today's websites might make this even harder than when Opera Mini was popular, but the original could handle some amount of JavaScript server-side execution surprisingly well.
Also, your post just made me try Opera Mini again – unbelievably, it still seems to be working on my iPhone! The app does not look like it's available anymore, but there must have been an update recently enough to still allow it to run on my device without obvious UI stretching or Apple incompatibility/deprecation warnings.
I see so many use-cases for browser isolation but haven't found a well-working option that doesn't need a full-time admin to set it up, isn't call-for-pricing or doesn't have streaming quality issues.
I did look at Browserbox some time ago and found it very promising, but alas the quality/performance (compression) was too subpar for non-tech users, even when run locally on the same machine.
Also if you want to check out a video of whether the quality is good enough for what you want, here: https://www.youtube.com/watch?v=CaOnMCqVmTQ&feature=youtu.be
> The NC license permits "use by any charitable organization, educational institution, public research organization, public safety or health organization, environmental protection organization, or government institution is use for a permitted purpose regardless of the source of funding or obligations resulting from the funding."
But on reading the license, personal noncommercial use is fine too. It would have helped me if that info had been in the readme!
I hope I make that clear in readme, it’s important.
[1] https://forum.playcanvas.com/t/browse-the-web-in-webxr-vr-hy...
What are they smoking???
What I want is unrestricted access for my code, and that the sites keep the sandbox.
What I do nowadays is start a server that has basic auth and zero cors, that I can send commands to from my scripts, like, fetch me this resource without cors, or download this to this folder, etc.
So, ex, if site A opens a tab on site B (and so gets a reference to it), site A can read and modify anything on that page. Or, ads loaded in cross-origin items could read and modify anything on the containing page.
It's fine for testing, but don't log into any real accounts in this profile!
Localhost cannot (unless you set it up that way, which requires user action)
That’s why.
Once in production, sometimes you want the user's browser to serve these local files to itself, from blobs and/or the local file system, meaning a server or CLI isn't feasible.
This should be better from a privacy standpoint since files stay completely client-side, but CORS difficulties end up encouraging developers to push files to the server at least temporarily instead.
Isn’t this privacy tradeoff directly at odds with security? i.e. local access would also open the door to malicious sites accessing the local file system?
I can understand the dev-time frustration with CORS, but removing it just reintroduces a whole category of security issues.
Maybe there is something better, but whatever replaces it would need to include similar restrictions.
Look at docker for analogy. Sometimes you just need a volume to use locally, but you don't necessarily need to access files that already exist. Consider the use cases of /tmp/ as well, for instance.
But setting that aside, bypassing CORS to achieve this seems analogous to unlocking your front door/gate before leaving for the day in order to grant access to a delivery driver.
It’ll work, and the driver can deliver your package, but it’ll also let random and potentially malicious passers-by into your home without restriction, so who knows if your home will be intact when you return. A theoretically functional solution that doesn’t really work in the real world.
Some other solution that behaves more like a temporary file store sounds better, but the tradeoff I mentioned is specifically about CORS.
I get that you need the user to explicitly select the file but I don’t understand the need to upload to a server.
Couldn’t you ask the user to select the file and just use the file locally, e.g. with the File API? https://developer.mozilla.org/en-US/docs/Web/API/File
I guess things break when you need repeated access and when having to pick the same file multiple times would be bad UX.
In the case I was referring, we loaded files as blobs in the browser's local storage, allowing us to run a web worker as a persistent local cache server.
This involved managing Firefox's admirable response doctoring policies, though.
All other browsers would let a web worker modify the incoming response to a request before forwarding it to an iframe, but FF absolutely refused it and required that the modified response get constructed anew in its local context, meaning locally created or injected content could not be mistakenly trusted as origin content.
`serve ./` turns any directory into a localhost webserver
What OP obviously meant was a way to disable same origin policy checks.
It isn’t anything of the sort. If they think the problem is CORS, they are going to put all their effort into trying to figure out how to disable CORS. This will not help them in the slightest. What they want, in effect, is to have a configuration that is as if CORS is on all the time, which they would never think to do if they think it’s CORS stopping them from doing what they want.
> What OP obviously meant was a way to disable same origin policy checks.
Yes, and they showed absolutely no knowledge of the fact that the SOP even exists. They think it’s CORS doing it. Pointing out this is backwards and pointing out what is actually causing their problem is helpful, not pedantic.
Ah, it looks like they've MuleSoft'd ViewFinderJS: https://news.ycombinator.com/item?id=28015601
Add the most requested features to a commercial offering.
It has extra features and fewer limitations than a regular browser I suppose, but that’s what I gather.
To answer you: I believe these instrumentation/automation protocols/methods like Selenium/W3C WebDriver Protocol/Remote Debugger Protocol, do not themselves provide user interfaces for controlling their functions, but rather expose APIs.
BrowserBox itself uses such a protocol under the hood, but also provides a user interface (that funnily enough looks like a regular browser~~because I wasn’t creative enough to invent a better set of UX interactions/affordances than those already expressed in regular web browser, heh :)).
In effect, BrowserBox turns the browser experience into a client server application. And BrowserBox is to those instrumentation/automation APIs, as a front end Client is to a Web application API.
That’s a slight simplification because BrowserBox contains a significant server component, however, it’s a useful way to think about it.
Another solution might be to proxy your web traffic through a part of your controlled infrastructure. Also useful if the destination blocks requests unless the source is whitelisted. I use ssh port forwarding for this.
https://wiibrew.org/wiki/Internet_Channel
I mean...theoretically...if you could back-port the client to work on the old rendering engine this uses, sure. When I initially developed this in 2018, I was testing it on an iPhone 4!
So, at least for a time, it was able to run on very old tech.
Web scraping automations often get stuck on some thing like a captcha or the page has changed and BrowserBox Pro let you attach to that running chrome automation instance, see the actual page that it got stuck on, and inspect that in remote version of dev tools (even from mobile!). This could let you quickly investigate and diagnose the issue and come up with a fix, all live.
In fact, that’s how some of our customers use it.
Why so many license changes? Given the $1000 per seat license cost, I'm not sure this is a great look.
BSD: https://github.com/dosyago/BrowserBox/commit/a7a40268effd03d...
GPL: https://github.com/dosyago/BrowserBox/commit/1ef76981774d95e...
Commercial: https://github.com/dosyago/BrowserBox/commit/fe88bf64b38a311...
MIT: https://github.com/dosyago/BrowserBox/commit/c29af3f523a4d1c...
Commercial: https://github.com/dosyago/BrowserBox/commit/1ddc800fd230c01...
AGPL: https://github.com/dosyago/BrowserBox/commit/6060cdd29c576d3...
Mm, that’s correct.
> … I’m not a lawyer …
I’m not sure if they can, but i would prevent that if i could.
> … why license changes…
Ha, you may be right! I don’t know. I guess I was just duped about the other licenses and the types of protections they can offer. I wasn’t informed and, I don’t know, I guess I was just trying to figure out a business model.
> Probably should have licensed it properly from the get-go then
Haha yeah!
> they can and probably will just use old commits
I don’t know, maybe. some people might. there’s always gonna be some software piracy.
Are you a lawyer?
No, but I have learned a bit about software licensing to be able to meaningfully engage in making run of Minio, so this is real info.
Specifically, most open licenses have a clause like this:
(from GPL3) ...and are irrevocable provided the stated conditions are met ...
Which is the bit that means you can't decide after the fact that at this point in time the software was not licensed under GPL3, this is to protect from I guess license-entrapment, which is sort of what you'd like to do.
However, even when this irrevocability is unmentioned, there's US precedent[1] that consideration is exchanged in the use of a FOSS license, which TLDRLEGAL means that a license not mentioning irrevocability is likely revocable only for violation of its conditions.
More details: [2]
1: https://scholar.google.com/scholar_case?case=177761825741712... 2: https://opensource.stackexchange.com/questions/4012/are-lice...
Ok, that's cool.
> to be able ... run of Minio ...
What's Minio?
> ... irrevocability ... license-entrapment ... is what you'd like to do ...
Hahaha! You are making some provocative accusations there. You really believe they are true?
Looks like you are a bully who maybe needs validation of an angry answer, but you probably just innocently misinterpreting, right?
The situation is: I want people to use the product. We don't care to litigate them. There's no business model in that.
I never said it was.
> ... dishonest to pretend it was never oss ...
Dishonest? Ha! Who's pretending?
\__
With the piracy comment I see where you went wrong: https://news.ycombinator.com/item?id=35501855
You think I'm saying that people using old code with old licenses is piracy.
What I'm really saying is that there's always piracy... so who cares about old code, old licenses and people using it? Doesn't matter.
\__ But with your "dishonest ... pretending never oss" comment, I don't see how you got that wrong.
I mean, you're the one who's being dishonest and pretending there, it looks like:
The licenses are present in the commit history! I'm not being dishonest about, or hiding, or pretending about anything.
And I even confirm it above: https://news.ycombinator.com/item?id=35499733
> … formerly OSS …
Mm, that’s correct.
So I don't know where you went wrong there, and I don't know where people have got these crazy ideas from, but it's not my problem. So please don't blame it on me! OK?Thank you! :) ;p xx ;p
I thought the guy meant "to use the old licenses on the new code." Reading it again, I see. So, what I actually mean is, "I'm not sure if they can use the old licenses on the new code. But, I would prevent that if I could." Which is totally valid and I would do that--I can do that.
It seems somehow the other meaning has created lots of crazy ideas for people, and they've gone on a tangent, which you can see in the sibling thread here. It's not my fault, but I see how I haven't probably made it clear enough there: I'm sorry for not making it clear.
Ultimately, I think having those licenses in the past is a silver lining for customers, especially because people can access this old code, and it's not affecting our revenue with Pro or people who want to pay for the standard edition somehow. Because this old code and old licenses do not sync to the latest, don't give access to Pro, and it gives people a chance to have a taste and build on that. It's really just another part of the funnel.
And, I think the whole variety of licenses there is sort of a silver lining. So, I don't know where people got the idea that we're against having that or something like this. It's not like that. So, just understand.
Thank you!