How to waste bandwidth, battery power, and annoy sysadmins
rachelbythebay.com
rachelbythebay.com
Basically Firefox loaded favicons 4x the number of tabs opened to that website. It would do this every time I opened or closed any tab.
https://aggressivelyparaphrasing.me/2022/12/12/why-does-my-l...
It was resolved a while back so maybe it’s similar symptoms but different root cause, or maybe it’s people using older versions?
> If I click enough, I’d eventually see HTTP 503 Service Unavailable.
That normally only happens when the reverse proxy has a timeout, which would normally only happen when the backend was completely overloaded.
Unless WP has an exponential delay, and the 503 is just the exponential delay becoming longer than the reverse proxy timeout? But why would the main page that the guy is loading say 503, when random non-critical parts like favicon.ico get a 503?
Unless the exponential delay is per IP address -- so all the misses to favicon.ico are actually slowing down the main connections past the reverse proxy timeout?
EDIT: Actually, no, they have graphs of the server actually spiking memory and CPU usage; you'd expect intentional exponential delay to reduce memory and CPU usage.
Over time, I found that BetterLinks was slowing down my site significantly (600ms) . It wasn’t like this when I first investigated. It became slow over the course of a year or so. I ended up replacing it with Simple 301 Redirects. I think this is a separate issue though, unrelated to my original overload, but looked very similar to when Firefox DOSed my site.
I experimented with CDNs to cache things reverse proxy style as a catch all. Eventually I caved and enabled Cloudflare CDN because QUIC.cloud kept having problems where a POP node kept hitting 403 Forbidden. I’d say the site is pretty functionally performant now.
I think most sites that claim Wordpress handles high loads really well have at least two layers of caching in front of it and are running on dedicated boxes. Remove both of those and suddenly it’s super easy to DOS.
Another common DOS exploit is to repeatedly spam the Forgot Password form, since there’s a lot of guaranteed processing with that and it’s not cacheable. I hid mine behind a captcha which helps a lot.
[1] https://github.com/mozilla-mobile/firefox-ios/issues/12113
[1]: https://github.com/fardog/fardog.io/commit/b2e3eac838ea25209...
That is, they are just skins
https://github.com/mozilla-mobile/firefox-ios/blob/bd589c194...
Firefox on iOS has about 200k lines of Swift. As a rough rule of thumb, everything that isn’t directly related to rendering something within the page or executing JavaScript is Firefox code not WebKit code. So bookmarks, syncing, tabs, etc.
On android, browsers can ship their own engines, and they do. There is actually some freedom on android.
Don't make your customers pay for your sloppy habits is a good policy to have.
— https://datatracker.ietf.org/doc/html/rfc7231#section-6.5.4
I get that not every client is well behaved, but you'd hope that Firefox would be, given Mozilla's presence in web standards.
(Which, tbh makes me think this issue is the "on iOS" bit, given it's Firefox. I presume Apple still has their "only Safari's rendering engine" rule in place for... ...reasons)
I also think it's pretty weird to defend thoroughly defect software with "waste ful, sure, but hardly that big a deal".
This attitude is why so much software is garbage, and why people with limited connections or hardware can't have a good time on the internet.
>In this case, [X] would improve things more quickly than [Y].
Maybe so, but more importantly why are you phrasing this like it's an either/or choice?"We, the developer community, contain multitudes." Clearly we can (and should) do both.
Besides the obvious benefits at the higher community level of organization, deploying both solutions will result in even less bandwidth and power wasted from this specific bug than using either solution by itself.
I opened the Github issue linked. For us it represented, at times, thousands of requests per second across multiple users. And that was with affected users getting IP-banned temporarily.
Some of which were 404s which you typically absolutely do not want cached. Or 405s (on HEAD /favicon.ico for example). Or 429s. Or 403s.
Browsers are expected to: 1. Use the favicon specified in meta if any (we do have one, /favicon.svg) 2. Respect cache headers (immutable + multi-months max-age) 3. Not make completely random requests to things they should ignore (such as OpenGraph tags)
Yes CDNs do help with these kinds of issues, but they absolutely do not fix them all. Which is why even though we have a pretty damn elaborate setup in that regard we were being annoyed by the issue.
But also Firefox on iOS should be not-completely-broken.
Would you kindly refrain from blaming users for what clearly is a bug in the application?
Firefox on android is amazing with its plugin support, though I still prefer their pre-2021 UI
I keep thinking I should switch to Firefox but the current ux is just so comfortable
The internet is unusable on mobile otherwise. But go on and let google continue to 'wow'you with their amazing ad tech.
Firefox on android IS AMAZING.
Meanwhile chrome/chromium is the one which is most likely to cause me GPU driver crashes, but that's because I use it for fun VR and "let's see how big I can make textures" experiments. Generally it manages a higher frame rate than FF in that context with stability as tradeoff.
Yes, is not as bad as it was in the 90s or 2000s, but is still a common issue
I use Firefox mobile daily, I occasionally have to switch to Chrome for some things. I choose to continue using Firefox Android because of the ability for greater privacy.
Firefox android is slow and buggy.
It is especially terrible if you are not in the habit of closing open tabs and just open new ones. As a concrete example, it often seems to run out of memory, causing issues such as Reddit not being able to load videos. They tried to fix this by more aggressively moving older tabs to an 'inactive' tab area, but it didn't work.
It at least feels badly written, saying that as an experienced developer myself. However, I know browsers are one of the hardest things to make, so perhaps it is just averagely written. But it is nowhere near Chrome's level of competence.
The new UI is awful too, I still hate a lot of design decisions and feel it was a bad mis-step. The old UI was just better. Again, I emphasise I use the browser daily and I say this with plenty of time to get used to it.
I just closed a bit over 2,000 tabs on my old phone because I was switching phones. I recall reading a couple of other comments here in HN and seeing a couple of comments in reddit of other people having thousands of tabs open.
Slow and buggy has NOT been my experience.
I use uBlock Origin addon though, maybe that's the difference? I bet resource-hogging ads could be an issue.
Edit: I also had "studies" turned off. Perhaps you were in a study that was testing something that caused those issues? (That's why I don't like default "studies" or A/B testing.). Or maybe something else (physical or software) on your phone is damaged/defective, perhaps even your installation of the Firefox app got borked?
I do wonder how you know you closed 2,000? The UI displays an infinity symbol over 99 tabs. If you had so many open, most of those would have been moved to inactive. The inactive tab section doesn't have a count and has a button you can click to close all.
Makes me sort of wonder whether you are actually using it.
Trying to "share" all of them will crash Firefox, so I manually select 100 and share those, then close those, repeat 20 times (which is how I know how many tabs I had open).
They even market it: https://brave.com/brave-ads/
The worst thing about the iPhone is the web browsing experience in Safari. It's awful. The ads totally ruin it. The rest of the phone is fine, I still prefer Android but that's most likely just because it's what I started with.
To address this, we will measure Telemetry Coverage, which is the percentage of all Firefox users who report telemetry. The Telemetry Coverage measurement will sample a portion of all Firefox clients and report whether telemetry is enabled. This measurement will not include a client identifier and will not be associated with our standard telemetry.
Even if you turn telemetry off it will still call home
https://blog.mozilla.org/data/2018/08/20/effectively-measuri...
They are the same thing, until you get to the upper levels, that own the place ie 'take full responsibility'. We are fa-mily. Until the shit hits the fan.
It is. It does avoid some of the tracking/ad content, so I guess it does do some things somewhat differently. But if it's such a scourge, add a favicon.
BTW, I've never seen this, and I regularly use Firefox on iOS to test.
* Tabs get stuck frequently, and can only be revived by closing, then undoing close.
* Can no longer access about:config in release builds
* Bookmarks got demoted in favor of Pocket, can no longer set bookmarks as default home page
* URL autocompletion got dumbed down, first on mobile and then also on desktop
* etc.
* Never had this tabs problem
* I can see about:config
* Bookmarks are fine and there's no mention of Pocket. Bookmarks show up ON the homepage, but yeah not being able to set a bookmark / any URL AS a homepage is a bit of an annoying feature lack
* URL completion works as I expect it to, although it does bug me how it strips the protocol from the URL so I have to manually type in `http://` for plaintext sites even when I've visited them before; depending on who you ask that is considered a "security feature" but kinda annoying. Other than that, I start typing in a URL and it shows me suggestions from my history followed by option to use my preferred search engine to search it.
All in all, I've not really felt FF (even nightly) be particularly different or unstable to using chrome.
Second comment I've made in this thread where I'm replying (ever so helpfully) "Huh, but it works for me" so I'll stop now :-). I promise the Mozilla Foundation aren't bribing nor blackmailing me.
Considering I didn't even realize it said Pocket the first time around, I think bookmarks are more prominent over Pocket, so I don't see bookmarks being demoted in favor of Pocket.
Collections are still there, but they've made it easier to use regular bookmarks too, so now Firefox for Android just has two versions of bookmarks in it for some reason.
Entirely unrelated to Pocket, as far as I know, except in the general sense of Mozilla having bad ideas related to bookmarks.
How? For me the closest thing I can get is "recent" bookmarks, but if you didn't bookmark a page recently it shows nothing at all, not even a link to all bookmarks, on the new tab page
I can't speak to the problems behind the scenes though, and they certainly merit attention.
I can't imagine she is working for them all.
I thought it was basically Firefox with another HTML rendering engine (and I guess javascript runtime).
Having a path-specific favicon actually sounds like a feature.
https://developer.mozilla.org/en-US/docs/Web/HTML/Attributes...
Can you provide at least a couple of use-cases for a path specific favicons?
<meta favicon=./user_favicon.ico>
or something.Do this require a browser probing every path with /favicon.ico?
I understand what you tried to retort just to retort, but I've had asked for the actual use-cases, not the mock ones and purely hypothetical.
The use case is this: I drop the icon in a folder and never look back. It just works. Why would I want an additional approach?
> These can be solved by
> <meta favicon=./user_favicon.ico>
> or something.
There is nothing to solve, it already works, the line has no advantages but it does have "or something" disadvantages.
Your memory is no doubt better than mine but you didn't remember how the tag worked. <meta> is for information about the document <link> is to describe relationships with other things. You've also left out the quotes.
<link rel="icon" type="image/x-icon" href="/favicon.ico">
This is the correct way of having an extra line of code that does nothing.For fun someone thought it a good idea to also have rel="shortcut icon" I'm picturing a room full of applauding people. (Who had nothing better to do)
image/x-icon isn't really correct, x- is for experiment, it should be type="image/vnd.microsoft.icon"
Browsers accept anything in the attribute. They also support not having a type. But if our goal is to have superfluous lines of html we should definitely go with the correct IANA mime type registered in 2003.
Redundant link headers also sounds fun!
Maybe in the future there will be new fixes for problems no one has?
Is that also the correct behavior for trying to identify a favicon for something like docs.oracle.com/javase/8/docs/api/org/xml/sax/helpers/DefaultHandler.html
Though they aren't common enough that it needs to be a built-in, especially as you can already specify a page specific icon via a link tag in your page's head which every up-to-date stable browser has had support for since 2010 or before (ref: https://caniuse.com/?search=link-icon).
Can I see them?
Generally: Any circumstance where you might want the icon to change per section/page/app rather than per (sub)domain. Do you want me to enumerate all possible combinations of web server configuration and tick the ones that applies to?!
For one: perhaps you host several tools off the same domain name, either literally on the same web server or via a proxy arrangement. As I said, these circumstances aren't all that common, and when they turn up I doubt the right favicon being use is going to be something you'd care about overly, but I wouldn't be surprised to find there are circumstances where it is important enough to someone.
I use Firefox as a quick lookup because the tabs crash often and it hardly ever saves the websites I was on when re-opening. So far I have crashed safari and lost all my tabs once ever. Firefox focus does a pretty good job too for quick lookups.
This is an exhorbitant exaggeration. They are duplicated requests for a favicon. Not only is that a tiny resource, most of these requests are 404ing which is cheap. And even if it isn't 404, your favicon is a tiny static asset, it should either be served by CDN or in the server's filesystem cache anyways.
Are we talking about not putting annoying sysadmins to good use? Or are we talking about, you know, makin sure they don’t cause nobody no trouble again, boss?
It makes a debouncing. It compares the result with the previous to be sure it is OK. /s