|
|
|
|
|
by GoblinSlayer
18 hours ago
|
|
>and will be perpetually ignored in all discussions about cross-browser compatibility If violence doesn't solve your problems, you use not enough violence. Also if you don't implement web standards, it's doesn't mean that nothing works. Adblock and noscript break web standards, but people use them just fine, they actually make web work better. >A massive project like that will have massive code complexity, which leads to enormous number of security holes. Presumably much of that is in network protocols like heartbleed, which has little to do with something like html parsing or google fonts. Also this is in fact a reason for a new browser engine: Chrome and Firefox lost security, because no matter how much they fix, they still have holes. >If you don't use Rust, then security would be so bad it's not even funny. Proofs? |
|
Today, IE6's 95% would be less than 10%. So you'd need to implement several times more features than IE6 had to be even remotely close to the status of unworkable mess that webdevs are better off not supporting.
Low-level exploits like heartbleed are quite rare actually. The vast majority of security bugs in Chrome and Firefox are in unsafely handling edge cases in parsing HTML and other media types, not isolating script execution enough, and bugs in runtime interfaces (cookies, local storage, mic&cam APIs, location APIs, etc.) Realistically, there's no way to avoid these bugs - browser engine has too much inherent complexity, statistically you're bound to mke amistake every so often. Moreover, IIRC about half of those bugs are caused by buffer overflows and similar memory bugs. So by using Rust, you can expect to have half as many security holes than you'd have otherwise. The number is still in the thousands either way.