Live data from Hacker News

The likely end of DownThemAll

downthemall.net

41–50 of 142 posts

Re: The likely end of DownThemAll

#41

I don't know if it's very smart to limit one of the most distinctive features of Firefox, the powerful add-ons available. Erodes the differences between Firefox and other browsers. If Firefox is going to be just another Chrome, people will just use Chrome.

The truth is Firefox already lost most of its market share to Chrome, so "powerful add-on" doesn't seem to be a strong enough selling point to retain users. It is, however, a big liability. In terms of security but also stability and performances. The way extensions work in Firefox is a bit crazy, it's like opening your belly and say "here, change whatever you want". It's the equivalent of a desktop OS where any inst…

> The way extensions work in Firefox is a bit crazy, it's like opening your belly and say "here, change whatever you want".

...and my god it has been awesome. Certainly more awesome than any instability it may cause.

> It's the equivalent of a desktop OS where any installed application runs in kernel

Most major operating systems give extension capabilities to enhance them in deep ways. My Windows install has ClassicShell as a start menu replacement and DisplayFusion for multi-monitor taskbars. I have explorer plugins for Zip files, Git, and Subversion. Any one of those tools can crash and take down the whole desktop process.

What you're describing isn't a modern power user OS -- you're describing iOS. A safe secure place where nothing interesting happens; only exactly what Apple has already imagined you could want.

> Not only a bad written extensions can have disastrous consequences

My browser crashes? Hardly disasterous! And then I can just uninstall any unstable extensions.

Re: The likely end of DownThemAll

#42
From a technical point of view, what is DownThemAll? It seems like it looks at the structure of the current web page, identifies all links, and then downloads them (in some cases using range requests, as with '90s-era download accelerators), with options for pausing and resuming downloads and renaming them in certain ways.

What prevents this from being done using a Chrome extension to look at the page structure and render some UI, plus a bit of native code using the native messaging API to actually store the files on disk?

https://developer.chrome.com/extensions/nativeMessaging

"Developer frustration" is a more-than-valid reason, but I'm trying to understand if this is a claim that no software like DownThemAll can possibly be written without Mozilla introducing purpose-built extension APIs.

Re: The likely end of DownThemAll

#43
post #34

Earlier quoted context omitted.

There's already GNU IceCat. Pale Moon is quite popular among Windows power users, I've read.

Ridiculous. I've never heard of power users using Pale moon. it seems like the current `hot fad' in comparison to products like SeaMonkey, which power users have always used since the de-coupling of the Mozilla Suite (netscape suite) in 2005. my personal thoughts on pale moon can be found here[0]. [0]: https://www.reddit.com/r/firefox/comments/3ay037/pale_moon_t...

I still use Firefox, but I looked at the status of some of the forks after today's news. It seems that Pale Moon, at the very least, is a true fork, but I don't have a whole lot of confidence that it would be right for me. In particular, it seems that they take a _very_ old-school approach to media on the Web [1], they really only bother with XUL addon compatibility [2], and an attitude that they should only open-source what is legally required of them [3].

There's nothing wrong with these views, but they don't work well for me. I just want my browser to work, with the extensions I like, and until now the way to go about that has been to stick with regular Firefox. Looks like that might not work for very long either.

[1] "Media support is a regularly-discussed topic for Pale Moon users, [...] This is, however, not a goal of Pale Moon because of the inherent shift of focus from document content to media content." https://www.palemoon.org/roadmap.shtml

[2] "If you still like to develop JetPack add-ons for Pale Moon, you will likely have to make a completely separate extension specific for Pale Moon targeting." Ibid.

[3] "There is no requirement or even reason why I should be forced to also release helper applications that are in no way tied to browser operation as Open Source as well." http://forum.palemoon.org/viewtopic.php?f=4&t=7818

Re: The likely end of DownThemAll

#44
post #6

At this point, would it make sense to fork Firefox?

I think that's what the Pale Moon ( https://www.palemoon.org/ ) folks were doing some time ago. I'm pretty sure they support most of the original firefox extensions without the signing etc.

Too bad there's no Mac version.

Re: The likely end of DownThemAll

#45
This seems like a classic case if thinking people use your software for the core features you develop. I hate to break it to you but people don't use windows for the control panel. Firefox and other browsers have become development platforms and many of their "users" don't use their platform for its 'control panel,' they use it for some useful tool built on top of it.

To use a linux kernel term, this breaks userspace (might be a sign that browsers have some serious OS envy). This is particularly bad because if many of your users use your platform for a tool that only works on an old, unsupported version (think XP), you actually make the security situation WORSE since those users don't care about security, they care about the tools they need to get their jobs done. They are still going to use those tools and you have just left them hanging out to dry from a security perspective. Talk about passing the buck.

Re: The likely end of DownThemAll

#46

Something I just thought of... if these changes are presumably meant to keep malware addons out of the browser, then it's necessarily operating in an infected environment. (I.e. something already had the ability to do things in the context of the user without that user's permission, and we're just preventing it from doing this one thing via restricting what the user can do) In what way does this meaningfully secure t…

The problem these days is established extensions that get legitimately sold or their access data hacked, and malware rolled out to the users.

Or extensions which actually do their job, but after a delay, e.g. a month, deploy the malware payload.

Enforcing someone from Mozilla to take a look at the actual APIs used in the extension is a pretty reasonable way to prevent a lot of this.

Also, disallowing local installs of unsigned stuff is usually a good practice - lots of "download managers" is bundled with "premium" "extensions" turning out to be toolbars collecting and shipping off your data, replacing your ads etc.

Re: The likely end of DownThemAll

#47
post #42

From a technical point of view, what is DownThemAll? It seems like it looks at the structure of the current web page, identifies all links, and then downloads them (in some cases using range requests, as with '90s-era download accelerators), with options for pausing and resuming downloads and renaming them in certain ways. What prevents this from being done using a Chrome extension to look at the page structure and r…

Yup, it's basically a spider. The Anticontainer plug-in enhances it to fetch images that are a few steps away from the original page. Looks like it just needs unrestricted XHR, which greasemonkey and every other chrome extension already require. Maybe off-screen rendering, which could look like this: https://www.chromium.org/developers/design-documents/extensi...

Re: The likely end of DownThemAll

#48
post #42

From a technical point of view, what is DownThemAll? It seems like it looks at the structure of the current web page, identifies all links, and then downloads them (in some cases using range requests, as with '90s-era download accelerators), with options for pausing and resuming downloads and renaming them in certain ways. What prevents this from being done using a Chrome extension to look at the page structure and r…

The main reason people install it I thought is because

1. It allows downloads to start and stop. No more 90% of that iso then having to start again.

2. It opens up 4 thingies on the file and downloads simultaneously. So 4 times quicker if the website is restricting bandwidth per connection.

Re: The likely end of DownThemAll

#49
post #18

There is no piece of software in the world harder to secure than a browser. There's almost no other piece of software where compromises have higher stakes. Further, the verdict is probably in on whether browsers should use multi-process sandboxes, and how careful they need to be about privilege-escalated Javascript, which is an enormous loophole for runtime security measures like ASLR and DEP. Firefox's multi-process…

> If that's the short term cost of getting Firefox to the same level of security that Chrome is at, it seems more than worth it.

Without the extensions I perhaps see no point to FF. Is secure and dead worth it?

Plus is there evidence of issues around this in the wild? Is it worth the risk of being a possible FF killer?

Re: The likely end of DownThemAll

#50
post #21
post #18

There is no piece of software in the world harder to secure than a browser. There's almost no other piece of software where compromises have higher stakes. Further, the verdict is probably in on whether browsers should use multi-process sandboxes, and how careful they need to be about privilege-escalated Javascript, which is an enormous loophole for runtime security measures like ASLR and DEP. Firefox's multi-process…

>Electrolysis apparently breaks XUL extensions. This is wrong. It absolutely does not break XUL extensions per-se. Add-ons will require some (moderate for most add-ons) changes when accessing out-of-process web content. A lot of add-ons may not even require changes at all, because they either do not access web content directly in the first place, or the Cross-Process-Wrappers and shims mozilla already implemented wil…

I'll copy and paste my comment from earlier:

> Reaching into content windows is forbidden [modulo CPOWs] in multiprocess Firefox. That alone is going to break tons of addons. This necessitates a redesign. Since a major redesign is necessary anyway, it makes sense to future-proof the architecture so that addons will work in perpetuity. Ultimately, this ends up being friendlier to addon developers, since addons will break once instead of again and again as the architecture evolves.

Post reply on HN