Live data from Hacker News

Ask HN: What would you want in an ideal web browser?

news.ycombinator.com

151–160 of 250 posts

Re: Ask HN: What would you want in an ideal web browser?

#151
No antifeatures / downgrades. I am aware that this is a fuzzy concept. However, a few specifics:

* Think very hard before adding things to make sure that they actually need to be in the core browser. Looking at you, FF Hello.

* Don't baby the user. Everything should be configurable. And existing options should not be changed on upgrades. And general solutions are (always) better than centralized services. Looking at you, Firefox "You cannot install unsigned extensions, period".

* Don't introduce "features" that hurt the end user. Looking at you, Pocket "you now are bound by the terms of Pocket's user agreement when you run FF".

* Don't try to do cat-and-mouse games. Looking at you, Firefox "we must try to prevent malware on the user's computer from taking over FF".

* Don't assume that everyone has the newest and best computer. Looking at you, Firefox "electrolysis tripling memory usage is fine, right?".

* Don't couple security updates with anything else. Looking at you, Firefox "you must downgrade to australis or else your browser will be unsecure aah!".

Re: Ask HN: What would you want in an ideal web browser?

#152
post #145
post #120

- works on X, the terminal and Android (yeah, that's a tall order, but it sure would be nice to have the same keystrokes available in X and on the terminal, and the same information available everywhere) - securely shares passwords across multiple hosts (emphasis on 'securely,' unlike Chrome and Firefox) - blocks ads - blocks JavaScript, but makes it very easy to selectively enable it - supports , and (hey, you did a…

Wait, what's insecure about Chrome password syncing?

Find a chrome users unattended computer

open a tab to chrome://settings/passwords

Click on a saved password and click "show"

Write down their site / password info. They'll never know you have their login data, no access logs or warnings.

Note that the people freaking out the most about this are incredibly uncreative, because they think this is the only way an unattended computer can be powned, usually combined with weird beliefs about "Security" being a boolean value. Obviously, if you have physical access, you stick a keylogger on there, steal the whole DB of passwords at the binary file level, take over the whole operating system, etc. Also for extra comedy the people most likely to be outraged stereotypically have the same password for all saved sites (LOL) so you really only need to write down one password for that user, and also stereotypically its a variation of "1Password" or their kids name, etc.

Re: Ask HN: What would you want in an ideal web browser?

#153
post #30

A browser where the security updates aren't married to "interface enhancements". Just give me the security updates for the version I have, because I don't want your designer's latest idea of what a browser should look like, and unwanted new features forced down my throat with the security updates. Choice about what new features to install - much like Windows updates, would be nice. At the very least provide ways to k…

Keep a separate UI and backend component and this should be trivial.

Unless the security update is a change to the UI.

Such as, make it easier for people to visit self-signed certificate websites, instead of the disaster that it is now.

Ive had friends not able to get by the "error warning" pages to see the photos on my self-hosted and self-signed encryption on my own site.

Id rather have everybody being able to MITM my self-hosted site, than only government agencies (because why would I pay for a ceritiface when any NSA compliant CA can then MITM that same "secure" connection, its false advertising on behalf of browsers, that somehow a CA signed certificate is worth more than self signed).

Re: Ask HN: What would you want in an ideal web browser?

#154
post #152
post #145

Earlier quoted context omitted.

Wait, what's insecure about Chrome password syncing?

Find a chrome users unattended computer open a tab to chrome://settings/passwords Click on a saved password and click "show" Write down their site / password info. They'll never know you have their login data, no access logs or warnings. Note that the people freaking out the most about this are incredibly uncreative, because they think this is the only way an unattended computer can be powned, usually combined with w…

Just tried it and it asked for my admin password (Mac OSX).

Re: Ask HN: What would you want in an ideal web browser?

#155
post #147
post #117

Earlier quoted context omitted.

That was a long time ago and even mailing lists and BBS had ads. You can see it already on sites like Reddit and Buzzfeed, users block ads so the only solution is paid content hidden as user content. Be happy that, for now, it is more lucrative to separate the ads from the content, because the alternative is even worse. In some ways, this last shred of free journalism we all enjoy online is because of those big ugly…

Let me counter that with: As long as the quality of online journalism is measured by clicks and ad impressions, its purpose is not journalism.

What else would you like it measured by? Paid subscriptions? Because we all know how that goes.

The breadth of online journalism we see today is precisely because of those ads everyone claims to hate. It allows anyone to quickly join the pot and lets the market decide their value. Without ads we'd be stuck with the 4 fuhrer model we had for the last 100 years.

Re: Ask HN: What would you want in an ideal web browser?

#156
post #91

Earlier quoted context omitted.

Why ad blocking? You know the internet runs on ads right? Without the ads all you'll see is paywalls and backchannel press releases.

Without the ads all you'll see is paywalls and backchannel press releases. And Hacker News.

Where people complain about paywalls, leading some to paste the entire article into a comment?

Re: Ask HN: What would you want in an ideal web browser?

#157

Less nannying. Yeah, browser manufacturer, I know you want me to use HSTS and you want me not to browse to HTTPS sites without certificates and all that. That's fine. I can understand that (for example) Google wants to be the only org that can track where I'm browsing, not my ISP or the NSA. But for the love of dog, give me an option to turn all that nannying shit off as and when I want to. My computer, my connection…

Firefox gives you the option to turn all of that off. I saw this the other day on Hacker News: https://github.com/dfkt/firefox-tweaks/blob/master/firefox-t...

To the best of my knowledge and reading of the provided link there's currently no way to disable "weak ephemeral Diffie-Hellman key in Server Key Exchange handshake message. (Error code: ssl_error_weak_server_ephemeral_dh_key)" type errors.

Its impacting me on an intranet-ish site that doesn't need https level security but the admins set it up incompetently. If they had set up https correctly, that would be a waste of time but it would be OK. If they had run the whole thing on http that would have been OK because there is no (... known ...) sensitive data on that site. But no they had to do a halfway job.

There may be market space for a bifurcation. Merely being able to render html doesn't mean all html rendering has to be done by one app, much like .ps or .pdf does not work best with the "one true app to rule them all". I could see a market with a iron clad virtualized one virtual (OS?) image per corrupt and insecure domain, and a hippie flower child browser for intranets and local files that blindly trusts everyone but by design won't talk to non RFC1918 ip addresses or maybe it blindly trusts the user not to do anything too stupid.

Re: Ask HN: What would you want in an ideal web browser?

#158

I want a web browser that let me open multiple accounts of a similar site at once.

You get 1 alternate session w/ Incognito or Private Browsing modes. Internet Explorer has File | New Session. Otherwise, it's down to extensions:

https://addons.mozilla.org/en-us/firefox/addon/multifox/

https://chrome.google.com/webstore/detail/multilogin/nccllfn...

Re: Ask HN: What would you want in an ideal web browser?

#159
post #152
post #145

Earlier quoted context omitted.

Wait, what's insecure about Chrome password syncing?

Find a chrome users unattended computer open a tab to chrome://settings/passwords Click on a saved password and click "show" Write down their site / password info. They'll never know you have their login data, no access logs or warnings. Note that the people freaking out the most about this are incredibly uncreative, because they think this is the only way an unattended computer can be powned, usually combined with w…

I didn't know that the chrome://settings/passwords page existed until I read your comment. I actually just checked it out, and when I clicked the "Show" button on the password box, Chrome made me re-authenticate with my Windows password before it would show the password.

I don't know if this is a new feature, only available on Windows, etc., but it seems like this may be less of a concern now.

I did find it weird that I had to re-authenticate with my Windows password and not the password that Chrome is syncing passwords with, but it's better than nothing.

Re: Ask HN: What would you want in an ideal web browser?

#160
post #152

Earlier quoted context omitted.

Find a chrome users unattended computer open a tab to chrome://settings/passwords Click on a saved password and click "show" Write down their site / password info. They'll never know you have their login data, no access logs or warnings. Note that the people freaking out the most about this are incredibly uncreative, because they think this is the only way an unattended computer can be powned, usually combined with w…

Just tried it and it asked for my admin password (Mac OSX).

It may vary depending on version.

Sites that are heavily automated / packaged / locked down will not be up to date.

I can verify it works fine on linux 44.0.2403.107.

I have access to a 41.0.2272.101 on windows that is extremely heavily locked down and centrally distributed but I don't use that out on the internet, it would be non-trivial to test.

Post reply on HN