Live data from Hacker News

Chrome's turning 10, here's what's new

blog.google

61–65 of 65 posts

Re: Chrome's turning 10, here's what's new

#61
post #38
post #29

I doubt anyone gives a toss if Chrome is having a "10th birthday" except Google. Never liked how this browser forces updates down your throat including "new looks" without any choice. Feels like software I have zero control over, if every time I open it, a new version of itself downloads and installs without my permission. Google enjoys forcing itself on users regularly without consent. Which is creepy when put like…

>Feels like software I have zero control over, if every time I open it, a new version of itself downloads and installs without my permission. Just like all of the websites that you browse, you can't have control over the styles or the updates that someone pushes to their servers, forcing you to download the latest page and install the latest service workers without your permission.

A website is obviously something that changes according to third party wishes. I am visiting their domain from my machine using my browser.

Software I decide to install on my machine, is under my control. I could update it, re-install it, delete it, change it.

I don't appreciate this mindset that software is like a "website" that is controlled by someone else. If that's what you want, then that's your preference.

Re: Chrome's turning 10, here's what's new

#62
post #60
post #42

Earlier quoted context omitted.

Browsers have a huge, huge attack surface that is persistently exploited. Every single release contains a lot of nasty bugs fixed in various places. Not to single Firefox out here, but take a look at their release notes[1]. - 4 critical, 5 high vulns fixed in 61. - 2 critical, 7 high in 60. - 4 critical, 4 high in 59. Your feelings on not liking security updates 'forced down your throat' are kind of immaterial. They…

Nonsense. > Every single release contains a lot of nasty bugs fixed in various places. Oh please. "Nasty bugs fixed in various places"? You're not replying to your mum here. Nothing, ever, should be forced down anyone's throat. Your attitude is what is making software become some kind of time-locked online service, even when it's installed on our machines. I will update software when I choose to, not when some commer…

Thankfully for the world this kind of nonsense, naive and borderline militant stance against your own security has not caught on.

And yeah I would describe multiple remote code execution vulnerabilities that can be triggered with pretty much no user interaction as 'nasty'.

You can find out just how vulnerable you are if you'd like, just find whatever crusty Firefox (or better yet a crusty fork!) version you are running here[1] and take a look.

1. https://www.cvedetails.com/version-list/452/3264/1/Mozilla-F...

Re: Chrome's turning 10, here's what's new

#63
post #62
post #60

Earlier quoted context omitted.

Nonsense. > Every single release contains a lot of nasty bugs fixed in various places. Oh please. "Nasty bugs fixed in various places"? You're not replying to your mum here. Nothing, ever, should be forced down anyone's throat. Your attitude is what is making software become some kind of time-locked online service, even when it's installed on our machines. I will update software when I choose to, not when some commer…

Thankfully for the world this kind of nonsense, naive and borderline militant stance against your own security has not caught on. And yeah I would describe multiple remote code execution vulnerabilities that can be triggered with pretty much no user interaction as 'nasty'. You can find out just how vulnerable you are if you'd like, just find whatever crusty Firefox (or better yet a crusty fork!) version you are runni…

What you're saying is these world class engineers can't develop a browser without giant security holes and vulnerabilities popping up every week. Sounds like a con job and intravenous koolaid drip you've volunteered yourself to.

Security updates should be separate to whatever cosmetic product enhancements, feature additions or removal they push everyone to swallow. It's a basic principle to separate those concerns. The whole reason everyone advocates modular architecture is so we can update one area without it screwing over something else. Apparently "new look tabs we think you're going to love" can't be uncoupled from fixing a "critical security vulnerability". Anyone who fails to question that is drunk on kool-aid.

You can be run over by a bus if you don't look both ways. Quick... everyone must install proximity alarms up their rear ends immediately, no opt out possible.

Microsoft, Google, etc as a result see higher uptake of their new product offerings getting installed on machines much sooner than if the fear and urgency wasn't underlined.

Windows now seems to allow software vendors to silently install updates, and re-install "update processes" that persist even when you explicitly remove them via msconfig, and opt out of them via the app's settings. Dropbox and others now behave like malware. That's on Microsoft for allowing this aggressive and silent update enforcement.

Keep the fear levels high, and user control options low because it's good for business. We'll sell it as "good for security".

I run recent versions of browsers, and obviously care about security. I just don't panic about being on some nightly cutting edge version out of fear of being compromised by the "critical" security holes built into the product cycle. I look both ways before crossing road. Those who don't shouldn't impact my freedom to cross the road without help from a mandatory rectal alarm.

Re: Chrome's turning 10, here's what's new

#64
post #63
post #62

Earlier quoted context omitted.

Thankfully for the world this kind of nonsense, naive and borderline militant stance against your own security has not caught on. And yeah I would describe multiple remote code execution vulnerabilities that can be triggered with pretty much no user interaction as 'nasty'. You can find out just how vulnerable you are if you'd like, just find whatever crusty Firefox (or better yet a crusty fork!) version you are runni…

What you're saying is these world class engineers can't develop a browser without giant security holes and vulnerabilities popping up every week. Sounds like a con job and intravenous koolaid drip you've volunteered yourself to. Security updates should be separate to whatever cosmetic product enhancements, feature additions or removal they push everyone to swallow. It's a basic principle to separate those concerns. T…

There is so much wrong in this monologue I'm not even sure where to start.

Then I realized, why start at all.

Re: Chrome's turning 10, here's what's new

#65
post #64
post #63

Earlier quoted context omitted.

What you're saying is these world class engineers can't develop a browser without giant security holes and vulnerabilities popping up every week. Sounds like a con job and intravenous koolaid drip you've volunteered yourself to. Security updates should be separate to whatever cosmetic product enhancements, feature additions or removal they push everyone to swallow. It's a basic principle to separate those concerns. T…

There is so much wrong in this monologue I'm not even sure where to start. Then I realized, why start at all.

Pointless. Next time say nothing if you have nothing.
Post reply on HN