1. https://www.usenix.org/system/files/usenixsecurity24-ali.pdf 2. https://github.com/masood/inspectron
I keep getting distracted by side-quests. The last one was building an Electron Zoo, and the current one is doing accurate SBOMs for each electron version.
> users are exposed to known, already-patched security vulnerabilities
Then why only focus on major versions? Don't minor versions/revisions have security fixes?
I would definitely include the fact that "major" versions of Chromium are released every 2 weeks. For instance, Vivaldi is on version 146.0.7680.218 that released this Tuesday [1], only 5 days ago.
[1] https://chromium.googlesource.com/chromium/src/+/f97d14f8a0a...
[1] https://developer.chrome.com/blog/chrome-two-week-release
https://chromium.googlesource.com/chromium/src.git/+/main/do...
Firefox's dev tools have an Accessibility tab where you can see warnings about low contrast and simulate different forms of color blindness.
Using any other color scheme would just confuse everyone instead of only colorblind people... how would that be any better?
A point-in-time view is interesting but it's less useful than a graph over time.
Would be fun to add the version shipped in LG smart TVs (hint: it's ancient)
Edit: approximately like so:
curl -sS -X POST -H 'Content-Type: application/json' -d '{"request":{"protocol":"4.0","updater":"CometUpdater","updaterversion":"0","os":{"platform":"win","version":"10","arch":"x64"},"apps":[{"appid":"{42e10078-e377-4166-965f-c14ad958a146}","version":"0.0.0.0","updatechecks":[{}]}]}}' https://www.perplexity.ai/rest/browser/update2 | sed "s/^)]}'//" | jq -r '.response.apps[0].updatecheck.nextversion'This is really, really bad ...
Edit: Ok, almost all of us. There are some non-Google browsers such as firefox, but Google dished out money to Mozilla for many years, which made real competition impossible.
People choose to download Chrome over firefox, to ditch their custom browser engine (microsoft & opera) in favor of chromium.
We've centralized development effort on a large open source project.
Why exactly is this really really bad?
I find the safari situation bad because I can't use various web standards, it's closed source, etc, but the chromium one doesn't bother me. I just install firefox.
Yet another reminder, lawmakers US/EU/Anywhere else, should force all browsers to actively block fingerprinting.
That won't happen.