1,060 karma · joined August 21, 2013
The canonical URL for how the address bar short cuts is https://support.mozilla.org/en-US/kb/address-bar-autocomplet...
Do you end up as someone pairing socks again or do you throw away half of your socks?
This should be somewhat easy to start and self-contained. If you want, you can easily extend it if you want things to become more fancy. E.g., hiding the secret constant. Implementing a challenge response protocol, limiting access to other global state (hardware dongle? ip address?) and so on.
You'll find that it is unnecessarily and necessarily complex unless you adopt a framework that makes design decisions for you.
There was a strong and long debate about the pros and cons. One of the strongest argument against was this here, including interoperability. I believe Cory Doctorow has also written multiple articles against DRM. I agree that DRM is generally bad.
However, the arguments for implementing it were the following: at least two other browsers will adopt the tech and that will allow it (per W3C process) to graduate from a Candidate Recommendation to a full Recommendation, making it part of the web platform.
On top, what would it mean for marketshare if people had to install a second browser just for watching movies? Would the non technical users accept and understand this without switching to a browser that they’d consider "actually feature complete"?
Isn’t this a security issue?
I guess back then, as a teenager I didn’t even know how much of a nerd I was :-)
The internal APIs also had to go. What else would you do?
You can call into the Windows APIs (there's a windows crate) and if you want to call into something that isn't there, `cbindgen` and friends are amazing.
Pick an IDE that you like. I really like PyCharm but vscode is also quite great.
To that extend you might even go further and have some specific visual clues per programming language. Whether that's different editors, editor profiles / themes depends on you.
The hope is to also cater to frontend frameworks enough that they will adopt it. There are already some conversations.
Browsers have a track record of being able to ship security bugs for severe issues within a day or two. Compare that to patching every individual website.
I’m collaborating on an attempt to shift the responsibility for XSS from the developers and towards the browser. The current stage focuses on getting the use case "insert HTML but without any scripts" right.
There’s a public specification and prototype implementations in Firefox and Chrome. You can play with it here https://sanitizer-api.dev/
We think that we’ve made the best of many different tradeoffs, but we’re also keen to hear wide feedback.