Live data from Hacker News

I discovered a browser bug

jakearchibald.com

71–80 of 137 posts

Re: I discovered a browser bug

#71

I can echo his experience reporting browser bugs and provide my own reviews: Firefox - By far the best. Quick response, usually from engineers. If it's important the fix will be quick. Edge - No reply for months / years. When I've gotten replies back it's been to ask me to try with the current version. When I do and the bug still exists it goes back at the bottom of the queue it seems. Chrome - Somewhat of a mixed ba…

I reported a very serious one to Edge recently and the team told me they would "backlog it and might be on a future release".

Chrome had already patched it and Firefox never had it. (It was related to incorrect DOM spec implementation of document inheritance allowing cookie access from anywhere).

I'll do a full write up and blog it when I'm back from vacation but to summarize I was really unimpressed by the team at Edge and Microsoft Security.

Re: I discovered a browser bug

#72

I can echo his experience reporting browser bugs and provide my own reviews: Firefox - By far the best. Quick response, usually from engineers. If it's important the fix will be quick. Edge - No reply for months / years. When I've gotten replies back it's been to ask me to try with the current version. When I do and the bug still exists it goes back at the bottom of the queue it seems. Chrome - Somewhat of a mixed ba…

Did you include a 90 day public disclosure window?

Re: I discovered a browser bug

#73
post #47
post #37

Earlier quoted context omitted.

So a spreadsheet running in the client with javascript or WASM would be an application, but a spreadsheet running on the backend wouldn't? I'm not trying to be overly pedantic or combative here but making a distinction between client-side and server-side code seems arbitrary. I understand it in terms of managing privilege - you can't control what someone does on a remote server, and that code isn't running on your ma…

The entire point is managing privileges. Just because I type in yourdomain.com does not mean I want you to be able to start playing death metal from my speakers. What about typing yourdomain.com means I want you to break my back button? Show a popup rather than close the browser? Churn CPU cycles crypto mining or do just about anything beyond hand me a document? Display a flashing GIF? The current model is basically…

>Just because I type in yourdomain.com does not mean I want you to be able to start playing death metal from my speakers.

Given the way HTTP works, I think it kind of does. It means you want the server at yourdomain.com to send you whatever content that URL points to, if anything. Which, granted, given the complexity of the web now, does seem fraught with danger, but what alternative would there be? Profiling each site for embedded content, size and complexity and whitelisting the elements before rendering? Browsers already let you block scripts, disable images and autoplay, overwrite or disable stylesheets and mute tabs, that would seem to be sufficient.

>The current model is basically handing complete control over my machine to a third party that may be compromised by anyone any time I click a random link.

That's a good point, but separating "applications" from "documents" wouldn't solve that problem, since that's presumably the model the applications would still be using. Sure, static pages that aren't running client side code would be safe, but those pages already are safe.

Anything that could be done to make a separate application space run safely could be done to make them run safely on the existing web, couldn't it?

Re: I discovered a browser bug

#74

I can echo his experience reporting browser bugs and provide my own reviews: Firefox - By far the best. Quick response, usually from engineers. If it's important the fix will be quick. Edge - No reply for months / years. When I've gotten replies back it's been to ask me to try with the current version. When I do and the bug still exists it goes back at the bottom of the queue it seems. Chrome - Somewhat of a mixed ba…

Yeah that Chrome experience doesn't sound great. Fwiw I tend to put my test cases on jsbin or Glitch, but yeah, a Chrome engineer should know to put the page on a basic web server. If anyone runs into problems like this, feel free to bug one of the Chrome dev rel folks, such as me.

> If anyone runs into problems like this, feel free to bug one of the Chrome dev rel folks, such as me.

Hi, and thanks for being part of creating Chrome && reaching out here.

Now that I have a Chrome guy here maybe you can help with another annoying issues:

-QC internally at Google seems to be blissfully unaware of the fact that other browsers exists.

Examples:

- one glaring issue I'm running into in core Angular on a daily basis.

- Google Calendar performance is sometimes unreasonably slow in Firefox

- For weeks or months Google search results would drive once CPU core to 100% twice a minute.

Re: I discovered a browser bug

#75
post #66

Earlier quoted context omitted.

Yeah, this is a UI bug in devtools for a feature not a lot of people use. Plus web worker bugs always get pushed to the bottom of the queue for every browser. So I don't have any problem with how long my weird issues take to get fixed. It's more about comparing to Firefox where you usually get a quick response which at least conveys that the person on the other end understands what is being reported . I'm fine with t…

> Plus web worker bugs always get pushed to the bottom of the queue for every browser. Why is that?

It's pretty rare to use in user-code. It might be well used in libraries, but I guess the standard developer experience is using libraries not writing them.

Re: I discovered a browser bug

#76
post #10

Earlier quoted context omitted.

Microsoft used to have a group, Trustworthy Computing (TWC), that was where all the security expertise lived. TWC was destroyed in 2014. From the outside, it seemed like that was the point where the reporter/outside security engagement story stopped, because the people that held responsibility for it Microsoft wide were either fired or re-orged into a role where they didn't have broad authority any more. Now, you get…

One can see a rationale in not having a security group - every team should have security focus (eg by having expertise & champions within each group). You can't tack on security, you have to build it in.

I think you need both. Same as I think you need i10n and a8y at both layers.

Re: I discovered a browser bug

#77
post #5

Earlier quoted context omitted.

Sorry, but we need a Turing-complete language for ads and tracking. Preferably with JITting, and unfettered access to the GPU and other misc. peripherals like GPS, webcam, etc. In return you get free cat videos. You’re welcome.

…and with unfettered access to USB devices . WebUSB my ass.

How else are we going to tailor our adverts based on the music on your iPod Shuffle?

Re: I discovered a browser bug

#78
post #73
post #47

Earlier quoted context omitted.

The entire point is managing privileges. Just because I type in yourdomain.com does not mean I want you to be able to start playing death metal from my speakers. What about typing yourdomain.com means I want you to break my back button? Show a popup rather than close the browser? Churn CPU cycles crypto mining or do just about anything beyond hand me a document? Display a flashing GIF? The current model is basically…

>Just because I type in yourdomain.com does not mean I want you to be able to start playing death metal from my speakers. Given the way HTTP works, I think it kind of does. It means you want the server at yourdomain.com to send you whatever content that URL points to, if anything. Which, granted, given the complexity of the web now, does seem fraught with danger, but what alternative would there be? Profiling each si…

[deleted]

Re: I discovered a browser bug

#80
post #67
post #47

Earlier quoted context omitted.

The entire point is managing privileges. Just because I type in yourdomain.com does not mean I want you to be able to start playing death metal from my speakers. What about typing yourdomain.com means I want you to break my back button? Show a popup rather than close the browser? Churn CPU cycles crypto mining or do just about anything beyond hand me a document? Display a flashing GIF? The current model is basically…

> The single greatest web innovation in the last 30 years was readability mode. For you. From what I see, everyone else seems to be enjoying the dancing and singing monkeys online.

the monkeys[1] are enjoying themselves, dancing and singing, at the expense of everybody else.

[1] web application pushers

edit: hn "syntax"

Post reply on HN