Hacker Newsnew | past | comments | ask | show | jobs | submit | necovek's commentslogin

> ...this is Microsoft we are talking about.

Exactly!

More seriously, it not just about building a compliant web browser engine, it is about tracking the dominant browser engine which introduces their own "standards" along the way too.

Microsoft could have easily continued to invest in maintaining their browser engine, but it would have to be comparable to what Google is doing, and yet they'd always be perceived as "behind" due to non-dominant position they have.

I'd say strategically they do not want to invest in tech that's not winning (in marketshare), so when they are not dominant, they'll instead adopt and extend (not just web browsers, look at WSL too).


One thing to keep in mind is that your brain's hardware heavily influences your experience and thus your brain's development.

Eg. whether you are male or female, tall or short, your limbs can make you run fast or not, your eyes can see well or not... all of these influence your experiences, your brain development, and who do you feel "you are". Try really removing all of your sensory inputs from your past, your body ability and disability, and do you think you end up the same person?


> Websites instead of apps on mobile is something that basically always sucks

I find it's the opposite: on my computer, I want native apps, but on the phone, it is very hard to manage a large collection of single use apps because I do not have a keyboard to quickly navigate between them.


If you are on an iPhone you can add a website to the Home Screen and it functions as a dedicated app essentially and the opened instance is treated separately from safari

Uhm, I am saying that I do not want a 100 apps (website-based or native) on my phone because this is hard to manage without better human-computer interfaces like a big screen and physical keyboard.

So I am not sure how making a web page into an app actually helps me?

When they are a web page I frequent, typing a few letters in the browser URL bar gives me the URL to click on and get there.


You can type into the search bar to search for apps on your phone. I don’t really bother with things on my home screen

At least on my up-to-date Pixel phone, home screen search bar only searches the web (by default).

It is the same on Android.

I'll just throw this out here: https://www.webosbrew.org/rooting/

I believe I did have to connect it to the network to get it to some web page or other, but after that I had full control of it.

My LG TV is a bit older, though (2021 or so).


"I have a PinePhone with phosh, which is neither Android nor iOS — where can I get the app?"

Obviously, it still won't get you anywhere except maybe hasten the return as it is not compatible to your environment.


The point GP was making is that DNS-record based ACME mechanism for verification of ownership implies trust in the domain name owner (or really, anyone who can edit records in the domain zone), making the issuance of a certificate actually superfluous.

DNSSEC is probably not even used, though I never checked.

Eg. as a domain owner, you will put a cryptographic hash into your DNS zone so a CA can validate you have control over it, and then issue a different cryptographic hash derived from their private key, and browser will use their public key to validate this cryptographic hash (TLS cert) is valid.

So we could simply push public key into a DNS zone, and browsers could use it to decrypt the traffic encrypted by the private key from the server hosted under that DNS name: no CAs needed, similar to SSH except the DNS-ownership-implied-trust component.

"Extended validation" certificates involved a lot more (in theory, checking true ownership, business address, physical presence, etc), but nobody really cares about these, and with the push to automated renewal and 45-day expiration dates by 2028, it's going to make even less sense.

Edit: I realize now that you may be referring to the fact that MITM DNS server can inject a different public key in there and thus DNSSEC is required — you are absolutely right, and this is a good and important point.


... but then, as they point out, you have to trust DNSSEC, and that's pretty fraught --- probably more fraught than trusting a CA.

IIRC, Netscape 4.* series was the last in the proprietary line of Netscape Navigators (though 4.* had a broader name like "Communicator" or something, since it included more than just the browser — but "3.0 Gold" was the one I remember most fondly as my first true good browser).

After that, open source efforts to rebuild the entire browser and mail client took years as XUL and Gecko were being built as very generic reusable components, opening up the space for competition to spring up. On top of that, Microsoft leveraged the Windows moat, including IE 3.0 and later 4.0 as the basis of Windows "97" (95 something-something) and 98, along with ActiveX push. By the time legal systems caught up with the practice of bundling a browser into a dominant OS, Netscape and Mozilla were toast.

Everything from there on was an uphill battle, and when KHTML was turned into WebKit by Apple, and adopted by Google for Chrome, there was also an open source engine (or two) supported by infinite money.

That's at least how I remember it, but you are welcome to fact-check me on any of those since this is now 20-30 years ago.


It becomes tricky fast.

There is obviously a fine that could bankrupt the company: this would be a clear signal "do not do this".

There are also many cases where people have been doing everything they should have been, and still got hacked (zero days, for instance).

Now, I do not think people should only be slapped on the wrist in that case: it still needs to be significant so companies carefully decide to store only the data they really do need!


One could say that simply incentives are wrong so people turn negligent and/or are out of their breadth on a topic.

But is there someone accountable for it being so? Are they malicious? Who is ultimately to blame?


I would say that maintaining legacy systems as a software engineer is effectively "using bugs to make money" and very much an "economically legitimate activity".

If old systems had no bugs/issues, companies could do without the maintenance burden altogether (which includes even systems not being evolved/extended).


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: