Live data from Hacker News

Firefox 38 released

mozilla.org

111–120 of 133 posts

Re: Firefox 38 released

#111
post #57

Earlier quoted context omitted.

I'll second Silhouette's comments that the desirable world you'd like to live in was never an option. The problem is simple: the major copyright owners insist on DRM and the inconvenience has not been enough to get many people to stop buying all but the most encumbered content. Sure, the usability was worse. That didn't stop many people from doing whatever they needed to play the video — it just trained a generation…

That traditional DRM was inconvenient and prone to user error is the entire point. It's supposed to be unpleasant. That somehow making it more convenient and adding a standards-endorsed API to facilitate its activation will somehow assist in combating it, is a nonsensical proposition. Furthermore, there is a separation of concerns aspect here. Why are web standards writers under any obligation to serve the interests…

> That somehow making it more convenient and adding a standards-endorsed API to facilitate its activation will somehow assist in combating it, is a nonsensical proposition.

That is nonsensical but if you were to read my comment, you'll note it's not a proposition I made.

This really isn't hard: 1. Consumers are happily paying for DRMed content 2. The big media companies are not willing to consider releasing content without DRM 3. Nobody likes maintaining plugins or the lower video quality they entail 4. Apple, Google and Microsoft made it clear that they were going to solve #3 by implementing whatever Netflix, YouTube, Hulu, etc. need to 5. The W3C and Mozilla accepted #4 and used what power they do have to push the process into a public forum. Mozilla has been particularly active to increase user awareness and make it more obvious when your actions are being restricted at a content owner's bequest.

There was no step where someone waves a magic wand and Hollywood stops demanding DRM.

With or without a W3C spec, most desktop users and nearly all mobile users were going to have a browser with DRM playback features. That means there's no step where Mozilla makes EME content harder to use and the reaction is something better than users dropping Firefox for Chrome/IE/Safari.

Again, if you care about this issue the question to focus on is how changing #1. As long as people keep paying for DRMed content, none of the other parties will have the incentive or ability to change.

Re: Firefox 38 released

#112
post #104

The Readinglist feature seems to have disappeared from the Desktop build. I really liked using it in Nightly and on Android. I briefly looked at Bugzilla and can't figure out its future. Is it really being replaced with a tie-in to a closed source US based startup company, Pocket? Can any devs comment?

This worked, so I imagine its being silently developed

http://www.ghacks.net/2015/02/07/mozilla-starts-to-push-read...

Re: Firefox 38 released

#113

Earlier quoted context omitted.

I understand your frustration, but I think you're complaining that you didn't get an option that was never realistically on the table in the first place. Your respect for the W3C matters a lot less to them than millions of people being able to watch content produced by a billion dollar industry, which much of that industry simply isn't willing to make available without DRM-style safeguards at the present time. Yes, w…

> I understand your frustration, but I think you're complaining that you didn't get an option that was never realistically on the table in the first place. Your respect for the W3C matters a lot less to them than millions of people being able to watch content produced by a billion dollar industry, which much of that industry simply isn't willing to make available without DRM-style safeguards at the present time. I do…

Thanks for the support. I didn't actually see that post go negative -- it's well into positive territory as I write this -- but it isn't that surprising to me.

There are a lot of people in tech, and particularly in web-related tech, who are very enthusiastic, but whose admirable enthusiasm is not always matched by their realism or level of experience. Any time you challenge an idealised view that something that's being done today is inherently better than something that was done yesterday, you tend to get some resistance. This tends to go double when the reasons for the challenge are based on pragmatic concerns rather than simply trying to use the newest and shiniest tech, as in this case.

There have been many examples over the years: the old CSS-vs-table-layout debate, progressive enhancement/graceful degradation, general hostility towards any sort of plug-ins, general hostility towards DRM schemes (or charging for access to anything, for that matter), "evergreen" browsers vs. IE, A/B testing vs. just about anything else, and recently more variations involving JS or CSS frameworks than I can even count any more. And of course $deity help you if you think flat design is mostly poorly executed rubbish and the worst general trend in design and usability for a generation, because Apple, Microsoft and Google all love it so it must be good! ;-)

So whether or not it attracts some downvotes, I think it's important for someone to challenge new assumptions in these kinds of cases. That's how we figure out what really works, because it stands up to scrutiny. It's also how we shine a light on people who are "moving forward in reverse", however good their intentions or interesting their ideas, and try to steer the industry a tiny bit closer towards something more productive.

Re: Firefox 38 released

#114
post #104

The Readinglist feature seems to have disappeared from the Desktop build. I really liked using it in Nightly and on Android. I briefly looked at Bugzilla and can't figure out its future. Is it really being replaced with a tie-in to a closed source US based startup company, Pocket? Can any devs comment?

This worked, so I imagine its being silently developed http://www.ghacks.net/2015/02/07/mozilla-starts-to-push-read...

Worked for me too. Thanks for the pointer.

Re: Firefox 38 released

#115
post #72

Earlier quoted context omitted.

> If you have local malware that changes the GMP DLLs thereafter, the malware might as well change Firefox itself. Well hopefully firefox itself is signed. This is exactly what signing is designed to prevent.

For software that runs as non-admin, authenticode is very much about checking delivery -time integrity. If you have admin-level malware, it can replace signed software (that gets run without admin privs and doesn't have UAC at launch) with unsigned lookalikes.

Not if the computer is configured to only run signed code, which is an option on Windows.

Re: Firefox 38 released

#116
post #108

Earlier quoted context omitted.

> I do think calling those plug-ins non-standard is a bit of a joke, given that Flash had 90+% market penetration for years Flash was also proprietary. It's closed-source, patent-encumbered, and has a single implementation. It's completely under the control of Adobe. https://en.wikipedia.org/wiki/Open_standard > For those users, a lot of major sites still "don't work properly" today because of Apple's arrogance. As A…

Even though Apple was right in the end, I think calling Apple "arrogant" is quite on the mark. It is they who denied opening up MobileSafari for 3rd party plugins (yet it supports 1st party plugins; in earlier versions you could even iterate the navigator.plugins property and see quicktime there). I remember seeing Adobe hinting heavily that they even had a working flash plugin (for jailbroken phones?) going internal…

> It is they who denied opening up MobileSafari for 3rd party plugins

...how is that arrogant? They wanted to only allow standard technologies? What is wrong with that?

> yet it supports 1st party plugins; in earlier versions you could even iterate the navigator.plugins property and see quicktime there

It had "quicktime" as a "plugin" but I believe that just launched the video player. Similarly, Apple replaced YouTube video embeds (Flash) with the video player. No plugins there.

> I remember seeing Adobe hinting heavily that they even had a working flash plugin (for jailbroken phones?) going internally.

Yes, Adobe did. It didn't work very well.

> I bet the real reason for blocking flash player in Mobile Safari was to block all the flash based ad banners of the day. It would have degraded battery life and the user experience quite a lot.

Flash period would ruin battery life. Similar to why iOS has no multitasking.

Re: Firefox 38 released

#117

Earlier quoted context omitted.

> I do think calling those plug-ins non-standard is a bit of a joke, given that Flash had 90+% market penetration for years Flash was also proprietary. It's closed-source, patent-encumbered, and has a single implementation. It's completely under the control of Adobe. https://en.wikipedia.org/wiki/Open_standard > For those users, a lot of major sites still "don't work properly" today because of Apple's arrogance. As A…

Flash was also proprietary. It's closed-source, patent-encumbered, and has a single implementation. It's completely under the control of Adobe. Perhaps, but I'm not sure how any of this is different to the various media extension proposals/standards we're starting to see more recently. And at least before, if you wanted to serve video from your web site, all you had to do was get one of the numerous Flash video playe…

> Perhaps, but I'm not sure how any of this is different to the various media extension proposals/standards we're starting to see more recently.

Encrypted Media Extensions is an open standard. The small DRM plugins that use it aren't open, but the core standard is. You've moved from a closed, proprietary system for the entire application, to a closed system for just the DRM and nothing else. That's huge progress.

> Please forgive me if I don't take their word for it. The thing is, Flash has run -- and reasonably well -- on numerous other mobile devices, even some from quite a few years ago

No it hasn't. "Flash Lite" worked, but slowly, and it couldn't do anything useful. The killer app for Flash was largely video and games, both of which don't work well in Flash on phones.

> Even if they had been true for early generations of smartphones and tablets, the performance of these types of device was always expected to increase significantly over time, as indeed it has.

By the time Flash could run well on the iPhone, the web had largely gotten rid of Flash and it was fast becoming a legacy technology, so there was no point in supporting it.

> If the performance would still be a problem on today's iOS devices then presumably Apple's users would opt for other implementations instead

The performance is now irrelevant because the web has moved on from Flash.

> browsers are a constant security and stability headache.

Yes, they are! But adding an extra attack surface for those two fronts is never a good idea if you can avoid it.

If you can avoid adding a binary blob to your browser that has frequent security issues, why wouldn't you do so?

> As I said before, there seems little reason to expect better results just because someone shifts things like video rendering and DRM technologies to a slightly different bit of low-level, native, closed source, patent-encumbered, even-the-browser-devs-don't-see-it code written in an error-prone language by the same kinds of development team that wrote the plug-ins.

No video rendering is done by EME, and EME doesn't and probably never will run on the iPhone.

Re: Firefox 38 released

#118

Earlier quoted context omitted.

Flash was also proprietary. It's closed-source, patent-encumbered, and has a single implementation. It's completely under the control of Adobe. Perhaps, but I'm not sure how any of this is different to the various media extension proposals/standards we're starting to see more recently. And at least before, if you wanted to serve video from your web site, all you had to do was get one of the numerous Flash video playe…

> Perhaps, but I'm not sure how any of this is different to the various media extension proposals/standards we're starting to see more recently. Encrypted Media Extensions is an open standard. The small DRM plugins that use it aren't open, but the core standard is. You've moved from a closed, proprietary system for the entire application, to a closed system for just the DRM and nothing else. That's huge progress. > P…

You've moved from a closed, proprietary system for the entire application, to a closed system for just the DRM and nothing else. That's huge progress.

Is it, really? You're still supporting DRM, because that's the basic requirement here. You're still therefore running unknown, closed source code that is prima facie working against your interests as a user. You still have an extra potential attack vector for malware. Sure, the scale may (or may not) be smaller, but qualitatively it seems the key facts are still the same.

The killer app for Flash was largely video and games, both of which don't work well in Flash on phones.

Flash on phones only really lasted for about two years, and given that the earliest phones somewhere around 2010 were running something like 1GHz low-power processors, it's not entirely surprising that the initial performance wasn't great.

The game was basically over by mid-2012 and Jelly Bean, but by that time, there had been quite a few reasonable investigations into how many of the reputed performance problems were real, and how many were either out-of-date or just plain false. Various video hosting sites that had been reported to perform badly in earlier criticism were debunked, with evidence that the other junk on the sites was causing more of a problem than the Flash video itself and that similar Flash videos could play just fine on devices of the 2011-2012 era. Likewise claims that Flash seriously reduced battery life didn't stand up to careful scrutiny over several days of investigation in some cases; battery life was generally found to be reduced, by sometimes by no more than a few minutes.

And that was with mobile technology from 3-5 years ago, which of course had quite a bit less processing power and lower battery life than the modern equivalents.

By the time Flash could run well on the iPhone, the web had largely gotten rid of Flash and it was fast becoming a legacy technology

When did Flash ever run on the iPhone?

The performance is now irrelevant because the web has moved on from Flash.

Given the number of sites I run into that still don't work properly on an iPad, I have to disagree. Maybe the sites you visit regularly have moved on, but there are a lot more sites using Flash than YouTube and other similarly large video sites with similarly large budgets to update their sites and convert their content to the brave new world of HTML5 video.

If you can avoid adding a binary blob to your browser that has frequent security issues, why wouldn't you do so?

Because I have concerns beyond just security. I don't run a browser so I can be secure. I run a browser so I can browse. When you take security so far that you break the basic functionality of your system, you aren't so much securing it as... breaking the basic functionality of your system.

In any case, with the new model using media extensions, we still will be adding binary blobs to the browser, and as I've said before, I see no reason to expect that these ones will somehow not turn into security vulnerabilities sooner or later the same way just about every other web technology in history has.

Re: Firefox 38 released

#119

Earlier quoted context omitted.

> Perhaps, but I'm not sure how any of this is different to the various media extension proposals/standards we're starting to see more recently. Encrypted Media Extensions is an open standard. The small DRM plugins that use it aren't open, but the core standard is. You've moved from a closed, proprietary system for the entire application, to a closed system for just the DRM and nothing else. That's huge progress. > P…

You've moved from a closed, proprietary system for the entire application, to a closed system for just the DRM and nothing else. That's huge progress. Is it, really? You're still supporting DRM, because that's the basic requirement here. You're still therefore running unknown, closed source code that is prima facie working against your interests as a user. You still have an extra potential attack vector for malware.…

> Is it, really? You're still supporting DRM, because that's the basic requirement here. You're still therefore running unknown, closed source code that is prima facie working against your interests as a user.

On far, far less websites, however. One or two video streaming services have DRM. Banner ads in most pages will not be using EME.

> You still have an extra potential attack vector for malware.

This is true, but one with a smaller surface area. One that might not even be installed, in many cases.

> Flash on phones only really lasted for about two years, and given that the earliest phones somewhere around 2010 were running something like 1GHz low-power processors, it's not entirely surprising that the initial performance wasn't great.

1GHz is slow, now? Wow, Flash must have sucked even more than I thought.

> Various video hosting sites that had been reported to perform badly in earlier criticism were debunked, with evidence that the other junk on the sites was causing more of a problem than the Flash video itself and that similar Flash videos could play just fine on devices of the 2011-2012 era. Likewise claims that Flash seriously reduced battery life didn't stand up to careful scrutiny over several days of investigation in some cases; battery life was generally found to be reduced, by sometimes by no more than a few minutes.

Links? I'd be highly sceptical of this claim: software video decoding is not good for battery life, for example. Of course if it's H.264 I'm sure Flash would use the hardware support, but why would you use Flash in that case?

> When did Flash ever run on the iPhone?

Never, but I mean by the time that the iPhone was powerful enough that getting Flash to run on it might be reasonable.

> Given the number of sites I run into that still don't work properly on an iPad, I have to disagree.

Most of the web has moved on. There are still plenty of sites that don't work with mobile devices and require plugin downloads to be used modern browsers, it's true, but it's a number that is continually decreasing.

> Because I have concerns beyond just security. I don't run a browser so I can be secure. I run a browser so I can browse. When you take security so far that you break the basic functionality of your system, you aren't so much securing it as... breaking the basic functionality of your system.

Flash support isn't "basic functionality". It's a bonus. Mobile devices can't and shouldn't support browsing every website made for a PC in existence, they just need to support most reasonably well, and that they do. After all, PCs still exist.

Mobile devices also don't support simulating right-clicks, Java applets, the Unity web player, ActiveX controls, and so on.

> In any case, with the new model using media extensions, we still will be adding binary blobs to the browser,

Smaller ones with much more limited scope, used in far less places, and which you can blacklist without breaking a lot of websites.

Re: Firefox 38 released

#120
post #74

Earlier quoted context omitted.

You should be ashamed of doing the work of adding EME to Firefox. Please don't add it to other platforms. Remove it from Windows. If the work will be long and hard there are better uses of your time than working to ensure that "streaming providers" can oppose Mozilla's vision of an open web.

Don't criticize Mozilla. The users have spoken and the vast majority don't care about DRM on streaming media. They just want to watch YouTube, Vimeo, Netflix, etc in their browser and have it work. Google, Apple et al put their full weight behind DRM and patent-encumbered formats, so Mozilla has to go along with it to stay relevant. If you don't want EME on principle, an alternate version of Firefox without EME is av…

The users have spoken and the vast majority don't care about DRM on streaming media.

{{citation-needed}}

They just want to watch YouTube, Vimeo, Netflix, etc in their browser and have it work.

YouTube works fine now. Netflix is a temporary aberration most of the world has never heard of or used. It's not the browser's job to support broken, predatory businesses. We spent 15+ years waiting and just achieved flashless and open video... let's use it.

Google, Apple et al put their full weight behind DRM and patent-encumbered formats, so Mozilla has to go along with it to stay relevant.

{{citation-needed}}

Edit (out of posts): Yes, pay per view is a broken model. You are correct that Mozilla sticking to its guns risks a reduced user base. However, Mozilla blindly following other browser vendors removes its fundamental value and USP. The reality is that the internet wants not just 'open', but also meaningful choice. Many of us believe that Mozilla has, in this case, missed the boat.

Post reply on HN