Gngr – A new browser championing privacy
gngr.info
gngr.info
But maybe this is a good idea and maybe there is a need for a secure by default browser.
What I don't quite like is the 'low level languages are dangerous' paragraph and then implementing the thing in Java/on the JVM. As far as I'm aware the security record of that platform isn't exactly stellar as well and especially older versions are widely reported to be vulnerable to exploits (admittedly usually using applets as a vector here).
Is the JVM really a great (or decent) choice, if security is the main concern? I truely don't know, so .. honest question here.
Yes, historically, there have been major concerns about security of the JVM platform. Applets (which we don't support) have been a big vector. Also, as per my understanding, there was a transition period when Oracle took over the reigns from Sun, during which security patches were not released as frequently as vulnerabilities were discovered. However, the frequency of patches has increased in recent times.
Moreover, OpenJDK has emerge as a complete open-source implementation of Java. So, atleast in theory, it should be possible for the community to fix the holes and not rely on a single company.
So in my opinion, Java isn't inherently worse than a lower level language. (I'm not 100% convinced it's better, though.)
2 - Written in Java and running on the JVM
3 - Written by unknowns attempting to tackle arguably the most difficult software endeavor currently feasible
4 - Have absolutely nothing to show for all their talk right now
Keep an eye on servo, disregard this nonsense.
So they want to disable by default every website online? I'm all for innovation but why not just invent a completely new browser that is a better runtime for apps if you're going to disable every website anyway?. Heck, pick a more easily optimizable language than javascript as the default scripting language, have built in GPG so we can throw away passwords, force HTTPS everywhere, use a non-centralized dns like namecoin - why not just go all the way here?
Even if you want to login, vote, comment, and post, all of that can be done without Javascript (though you do need to at least temporarily enable cookies).
I am really grateful to HN for making this design choice. Javascript is superflous for 99.9% of websites. It's an unfortunate design choice to use it anyway.
I wish I could say that I hope website creators would move away from Javascript and other "dynamic" (ie. turing-complete, overpowered) technologies. But it's clear that's not going to happen.
In light of that, privacy and security tools will have to adapt and somehow find a way to protect their user's privacy and security despite having Javascript enabled.
Right now, the best hope I see for something like that is having light-weight disposable VMs/jails/containers and sandboxes. At least that could limit the damage that Javascript does to a single tab or session.
For web sites, yes. For web applications though (of which there are more every day), it's definitely not.
We actually do want to implement some of those ideas (and other similar ones)! But we don't believe it is necessary to ditch the existing standards for that. There can be a transitionary period and this (or any other browser) could be a test-bed for new ideas.
That ... is not minimalistic. Speaking as a person whose browser sends `User-Agent: browser` and `Referer: https://news.ycombinator.com/` (that is, dynamically the root of the requested site). I have never seen anything break because of user-agent, and only a few things because of referer (and more than a few things break when I do send correct referers). I do agree with the going all the way part though; web browsers seem to view security as a afterthought to be bolted on after the fact.
2. Needs more thought from my side, but my immediate response is: this could be solved with better UIs for managing a website's permissions. Perhaps websites could ship metadata about the kind of permissions they require (similar to a mobile app) and the user could "approve" them with a single click (like an app).
Well, have fun kids!