Retaking the web browser, one small step at a time
andregarzia.com
andregarzia.com
Case in point which I'm fighting with at this very minute: HTTP. I want to access a site over HTTP, not HTTPS. I know it supports HTTP. I have used HTTP in the past. But my browser insists that I want HTTPS instead, despite my manually typing http://
HSTS is an abomination, directly ignoring the user's command to do what the site wants instead. As if I'm some kind of bystander of my computer, instead of the user.
Edit: And for mobile even more obscure.
Your argument makes sense in one narrow circumstance which is not the typical HSTS setup: if the server is serving the site with plain HTTP on port 80 (and not just a redirect to the HTTPS version of the page), and also has a HTTPS version with HSTS headers. (So that the first time you visit the HTTPS version, your browser will insist on taking you to that version every time.)
I'm really tired of using a computer and feeling like a passenger rather than the driver.
https://superuser.com/questions/1721511/firefox-allow-http-u...
https://support.mozilla.org/en-US/kb/https-only-prefs#w_enab...
There’s plenty of reasons to be mad at big corporations. But for now at least, Firefox still supports your right to make bad life choices on the internet.
Some components of Public Key Infrastructure itself use unencrypted HTTP for this very reason. See Online Certificate Status Protocol (OCSP) - a method for distributing Certificate Revocation Lists.
Many Linux distributions operate package repositories in this manner. It allows caching of packages through a variety of methods.
Generally, CDNs can distribute signed HTTP content without requiring a customer to share a private key as would normally be required by HTTPS. So long as confidentiality is not a requirement.
The IETF, Google, and Cloudflare have been developing standards for it.
https://www.ietf.org/archive/id/draft-ietf-httpbis-message-s...
https://wicg.github.io/webpackage/draft-yasskin-http-origin-...
Parent post didn't expliticly ask for browser context only.
Mitm attacks seem incredibly dangerous in a package repo. Signing only gets you so far - and they probably don’t protect you from downgrade attacks.
There's no benefit to saving a file on a floppy disk, but if I tell my computer to copy a file to my floppy drive, I don't expect it to say "No, can't do that. You should be using a USB flash drive--they're better in all ways!"
But I'm asking you: Why do you want to use unencrypted HTTP? Surely there must be some reason you want to do that, right? You (and others) clearly care a lot about this. I'm sure you're not an idiot. Help me understand your point of view here?
At the end of the day, I worked around all of this browser helpfulness by using Firefox and re-enabling TLS 1.1 in Firefox's settings. I never actually managed to force any browser to use http:// despite trying many proposed solutions in this thread and on the web.
But all that aside, it doesn't really matter why I want to use unencrypted HTTP. I am commanding my computer to do it, and I expect it to carry out my command. My computer is a tool. It should do what I want it to do, even if that might hurt me. If I type in sudo rm -rf /usr, I expect it to do what I tell it to do. Not ask "Why do you want to do that?"
But after a bit of reflection I now think that in this specific case there's nothing bad about using http. Services are offered on a first come first serve basis to a large but closed group of valid users. Key is that there are a bunch of real world processes that follow the initial trigger with no practical way for any other party to benefit.
The site is extremely simple but blazingly fast.
What is the benefit to turning https off?
I think there's a fix for this in firefox and its forks, browser.fixup.fallback-to-https or dom.security.https_first maybe... at least they used to allow you to disable that sort of thing.
NOT automatically, but with an accommodation that asks the user if they're _expecting_ to talk to a device such as a "Modem" or "ISP Router" when making that request, and offer to do what's necessary to connect.
With Google’s manifest v3 debacle, it’s clear we need to fight continuously and ruthlessly to keep the web for the people.
Google should be broken into several companies.
A breakup would be good for shareholders. Google would be worth more as separate companies, because currently they're giving away hundreds of billions of dollars in value for free.
They'd also have to be more nimble, which would increase fitness instead of being an overfed goldfish in a tiny pond.
A breakup would oxygenate the field for competition and innovation. Right now, Google is killing all the competition with their platform pricing power.
Engineers would be better compensated too, as more firms would have to compete for talent.
The hulking behemoth is bad for everyone, including Google itself.
No we’re not. It’s okay for regulators to fix our mess in the meantime (though I wouldn’t get my hopes up), but we should teach others to see the imbalance and regain the power. This is the fight we should be fighting, and it’s the only sustainable way to go.
When you’re building products, make sure you treat your users like real people, with respect.
At every level of the stack, from firmware to OS to application to cloud, let the user own their device, and their data.
Any amount of contribution, no matter how small, helps. Get your coworkers or classmates aware of the issue. It won’t be a monumental contribution, but it all counts.
- a db
- a db browser
- a {bookmarks,browser,etc}-to-db tool
For instance,
- sqlite
- datasette https://datasette.io/
- pocket-to-sqlite https://datasette.io/tools/pocket-to-sqlite
Furthermore, you could integrate e.g. Claude with this, by creating a lightweight model-context-protocol server that lets Claude browse through datasette. You would probably want to throw in a vector db in-between somewhere, so you could get semantic search over bookmarks to work nicely.
Are you on Safari? If so even switching to Chrome would have helped, and if you are have more than a hundred tabs than use Firefox.
>Bookmarks suck, search sucks, saving browser sessions sucks
Completely agree as it has been the case for the last 25+ years since Tabs were invented.
I keep the Tabs opened as more like a ToDo-List. Saving me from going back and forth so I understand your frustration. Having drop down list in Chrome and Firefox allows you quickly Garbage collect from unused tabs. Which is already much better than the old days as this is a fairly recent additions. ( May be pass ~5 years )
Tree-Tabs sounds good in theory but in practice over the past 15+ years or so most of the tree tabs implementation dont work for me. Mostly an UI issue. Category of Tabs or sometimes called Tab Group seems to be the closest thing. I actually quite like Tab Groups on Chrome, and surprisingly Firefox over the years have tried many implementation but nothing like what chrome has offered ( at least by default )
I use Tab groups on both Safari and Chrome, one group for HN, one group for RSS feed. These two groups keep nearly 80-90% of new tabs generation for me already. So while it is not perfect it is a lot less of a mess than what I had. The rest are random thoughts that came up into my mind and I need some tabs research into it.
The only way you have true inactive Tabs is if you restart Safari. On recent Chrome and for Firefox they have been doing it since Project MemShrink and at least 10 years. So for those who close their browser windows every now and then or shut down their computer at the end of the day they may be fine. ( Still possible for force reloading of Tabs on Safari though )
They suck so bad lol. I bookmark something planning to look back at it the next day. I actually end up looking at the bookmark a year later thinking "oh ya, that".
NOOOO problem. Simple solution. In one word, text. Two words, text editor. E.g., this Hacker News thread is at:
https://news.ycombinator.com/reply?id=42988455&goto=item%3Fi...
Sooooo, have that URL and the title of this thread in a simple, old-fashioned, file, text file, maintained with my favorite editor. Then, when want to revisit this thread, use the editor's excellent text search facilities to find the URL, and then, via a simple editor macro I wrote, one keystroke, and, bam, boom, have the Web page displayed via my pre-selected Web browser.
Text. Keep nearly everything important in just text. Source code of .NET for my startup's Web site? Text, never anything but text. Visual Studio? No thanks: Did I mention text? Posts at Hacker News? Text, both for my posts and those of everyone else. File system directory tree? Uh, again the T-word, with the tree from the Rexx function SysFileTree. In the editor, can sort on date, size, name, etc.
*stoutner privacy browser, apk on fdroid
The elephant in the room: Chrome is owned by Google and Chromium is only a stripped down version with no independent development, Apple/Safari is paid by Google, Firefox is paid by Google.
We could argue design decisions aren't directly dictated by Google in regards to Safari and Firefox, but we're also not seeing any major decision that straight goes against Google's interests.
The most we've seen from Safari is manual element removal, and on iOS only.
There are lots of ways to improve bookmarking, content recall etc on the web. Nobody is willing to pay for them.
1. Users don't pay for them. I found lots of startups with the same idea that had pivoted, mostly into dedicated research tools for academics.
2. Browser makers don't pay for them, because if they make their bookmarking tools bad then people search more, and they get paid for search referrals. So making bookmarking or history search better hurts their own revenue.
Nobody is willing to pay. So, nobody gets improvements. If people start being willing to pay for their browser, you'll see them get better at stuff like this.
I feel like I've tried every tab/bookmark managing app/extension under the sun and none of them stuck. I've also thought about creating my own, but it feels like even I don't know what I'm looking for exactly. The main problem I have is that they all have too much friction compared to simply keeping the tabs open. It would have to be something deeply integrated into the browser.
Vivaldi has some really cool tab management features and it would be my main browser of choice, but with my amount of tabs, windows and extensions its UI performance degraded to the point of becoming unusable, whereas Chrome held up just fine. Granted it has been a couple of years since I last tried it so that might have improved since. I'd still recommend anyone with similar "power user" needs to give it a try. It's a pretty awesome browser.
Tab Groups in Chrome are actually surprisingly decent as well. They're pretty low friction, and open tab groups even sync across devices, including mobile, in (near) real time now, which is great. But I do have some issues with them causing me not to use them. For example, when you re-open a closed tab group it will instantly load all of the tabs inside of it, instead of keeping each tab unloaded until visited, like on startup. You also can't add tabs to a closed tab group. So you either always have to keep the tab group open, meaning they're not much more than a visual aid and only slightly more useful than bookmark folders, or store fewer tabs per group, making them even less useful. They also have the same "object permanence" issue as bookmarks, where it's simply too easy to forget about a closed tab group altogether once I close it.
Of course, Firefox also broke extensions on Android for several years, during which I mostly used a lightly tweaked Chromium build called Kiwi Browser.
Hmm, I didn’t really notice that. (I’m using Fennec F-Droid though, but it’s pretty close to the official Firefox build, with only a few minor tweaks.)
Could you tell me more about what was broken for you?
Third party builds differed, of course.
Personally, I’d just allow installing any extensions (from AMO at least) and put a big scary warning that this is unsupported (which was the reason they gave for the whitelist approach).
Firefox on Android still doesn't look like it has the ability to save pages. Chrome and Kiwi both have this feature, and Firefox used to have it via extension that triggered built-in, but unexposed, functionality.
I think Brave could be a pioneer here and add a further point of differentiation by allowing extensions.
Also on iOS, Orion supports both Chrome and Firefox extensions.
The author is playing with his own bookmarklets and extensions that will never be part of the browser, as it serves his own needs, not someone else’s.
For the browser to act as the user agent, it needs to be scriptable.
Everyone has favorite addons - if you’re looking to expand, here are mine for iOS Safari.
- Kill Sticky Scroll - hide dickbars and obnoxious overlays in front of the content. Use iOS Shortcuts app to create a new shortcut, set it to receive input from Share Sheet and add a “run javascript” then paste this js: https://github.com/t-mart/kill-sticky/blob/master/src/kill-s... (you’ll need to add a call to `completion()` to make it a valid Shortcuts js function)
- AutoPiP: automatic picture-in-picture when tabbing away from a playing video in Safari https://github.com/vordenken/AutoPiP
- Vinegar to use the native video player on youtube: https://apps.apple.com/us/app/vinegar-tube-cleaner/id1591303...
https://github.com/SebastianSimon/firefox-omni-tweaks https://github.com/black7375/Firefox-UI-Fix
userChrome tweaks can get you a long way – for example, I’ve reimplemented the Australis-like tabs (for the nostalgia sake, mostly) using that. Of course, the downside is those tweaks break with updates sometimes.
If you’re wokring on a userChrome tweak, you might want to enable devtools for the browser UI itself: https://firefox-source-docs.mozilla.org/devtools-user/browse...
I continue to think RSS Reader should be a function of browser and shouldn't require a third party web or app to do it. In modern days I wish that could be married with a personal LLM so I could ask question about things I have read but I cant find it easily.
There's a spotty history of this. Internet Explorer 7 had the ability to subscribe to RSS feeds: https://www.bnsf.com/customers/rss/browsers-ie7.html