HTML5 hole in major browsers... well, except for Firefox


Recommended Posts

The glorious future of the mighty Flash killer. Welcome, welcome. We've been expecting you. With all your ridiculously stupid troubles, too.

I know! Flash have never EVER have holes and security faults!

...

...

...

Shall I continue?

not trying to flame or anything, just my two cents....this serves to prove that nothing is flawless....instead of jumping the gun and trying to drop flash/flex and so on to adopt html5, one should wait until the platform matures enough and standards are set in stone.

^ Well, then perhaps we shouldn't have moved into this house yet... and set the old rented apartment ablaze with such a profound sensation of accomplishment? Gosh knows it may start to rain fish and the roof may not hold as well.

  • Like 3

one should wait until the platform matures enough and standards are set in stone.

If the effected vendors had actually paid attention to the spec that specifically has recommendations to stop this from occuring, naturally this wouldn't of happened.

Props to Mozilla for actually paying attention.

Mmm, yes.

Please, tell me more about how everyone should use Webkit instead of following open web standards. :whistle:

Given that the problem affects Trident and Presto as well that's a pretty stupid comment to make.

Given that the problem affects Trident and Presto as well that's a pretty stupid comment to make.

No, you just think it's stupid because you're a "Google shill", to borrow your own terminology from other threads.

This not only proves that open web standards and adherence to them is important, but that having a single rendering/layout engine is a bad thing.

So explain to me how it's Google's fault when Webkit (which Google do not actually make just FYI) is not the only browsing engine that is subject to the flaw?

So explain to me how it's Google's fault when Webkit (which Google do not actually make just FYI) is not the only browsing engine that is subject to the flaw?

You need to read the OP and maybe find an email for Feross Aboukhadijeh, he is the one that discovered it.

So explain to me how it's Google's fault when Webkit (which Google do not actually make just FYI) is not the only browsing engine that is subject to the flaw?

Oh, so Webkit isn't the holy grail of openness that you made it out to be in the Opera thread after all? Or is it just because this doesn't work in Google's favour?

They ship Webkit in both binary and source form, they contribute to the Webkit project, and they were supposed to be the so-called "champions of the open web". So yes, they're just as much at fault for shipping a broken, non-standard implementation as Opera and MSFT.

Funny how people twist your words here when you aren't prepared to sell your soul to Microsoft isn't it.

Chrome is open (ish, chromium), webkit is open. Never did I claim that software being open excludes it from carrying bugs or design faults. And given the other browsing engines it effects, it's clearly something that's common practice in the industry.

Funny how people twist your words here when you aren't prepared to sell your soul to Microsoft isn't it.

Chrome is open, webkit is open. Never did I claim that software being open excludes it from carrying bugs or design faults. And given the other browsing engines it effects, it's clearly something that's common practice in the industry.

Because supporting open web standards means you're a Microsoft supporter, amirite? (Mozilla would of been far more apt)

You argued in favour of Webkit dominance, and now you don't even have the integrity to stick to your own words. Pathetic.

Another misconception. I still think it would be good if they all worked towards the same goal instead of having to compete with each other, I also accept that no software, proprietary or open source is completely free from flaws. If you want to warble on about integrity how about putting your money where your mouth is and not twisting my words? ;)

Another misconception. I still think it would be good if they all worked towards the same goal instead of having to compete with each other, I also accept that no software, proprietary or open source is completely free from flaws. If you want to warble on about integrity how about putting your money where your mouth is and not twisting my words? ;)

"Flaws"

You mean ignoring the large, red-backgrounded section of the localStorage spec that specifically warns about this "flaw"? Hah!

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • AltSendme 0.4.1 by Razvan Serea AltSendme is a minimal, cross-platform application designed for fast, secure, and private peer-to-peer file transfers. It allows users to send files or entire directories directly between devices without relying on cloud servers, accounts, or any personal information. Everything is encrypted end-to-end using modern protocols like QUIC and TLS 1.3, ensuring both strong security and low-latency performance. Transfers are verified with BLAKE3 for data integrity, and interrupted downloads automatically resume, making the experience reliable even on unstable connections. You can transfer anything—images, videos, documents, and more. Integrity checks are performed on both ends, so your files are automatically verified for correctness during both sending and receiving. AltSendme works seamlessly across local networks or long-distance links, capable of saturating multi-gigabit connections for extremely fast delivery. With built-in NAT traversal and encrypted relay fallback, it connects devices almost anywhere. The app integrates with the Sendme CLI and will soon support mobile and web platforms. Fully free and open-source, AltSendme offers a lightweight, privacy-first alternative to traditional cloud-based services, removing size limits, upload costs, and unnecessary data exposure. AltSendme 0.4.1 changelog: Release Highlights Self-hosted relays: Run your own iroh relay so transfers don't rely on public infrastructure. Includes a full deployment template in deploy/relay/ with Docker Compose for a VPS and configuration examples for production use. Fly.io support: One-click deploy template for Fly.io, including a quick-start config (fly.dev.toml) for testing without a custom domain, plus production setup with Let's Encrypt and your own hostname. Relay settings UI: New Settings → Network panel to choose how AltSendme connects: automatic public relays, custom self-hosted URLs (with optional auth token), or disabled. Test connections, verify latency, and see live relay status in the footer. Disable relays: Turn off relay servers entirely when you only need same-network transfers (e.g. LAN). Direct connections only. No relay hop required when devices can reach each other. Android graduates from beta: Android is now part of the regular release cycle alongside desktop. APKs ship with each version (universal, arm64, and armv7). Other improvements Private relay access control via shared auth token Relay fallback notifications when a custom relay is unreachable Broadcast mode toggle in sharing settings Android release build fixes (split-per-ABI APKs, universal APK preservation) UI polish: mobile safe-area insets, dropzone layout, transfer progress animation Bug fixes for minification-related serialization issues and system tray icon loading What's Changed feat(relay): add relay status functionality and settings UI (a120cdf) feat(relay): implement custom relay server configuration and verification (51276c7) feat(relay): add configuration for private relay access and enhance observability features (48fbabf) feat(relay): enhance relay URL validation, display connection status (d4fffa0) feat(relay): add RelayChangeGuard component and enhance relay-related translations (16ba514) feat(broadcast): add toggle setting for broadcast mode in sharing UI (ca6d977) fix(relay): correct QUIC discovery port, pin image, templatize fly.dev (52a2ba5) fix: More broken serialization due to minification (67491a9) fix(android): preserve true universal APK across per-ABI builds (e9f256f) fix(ui): conditional safe-area insets padding on mobile (1182f0e) refactor(transfer): CircularRing component animation fix (944572b) chore(android): drop x86 and x86_64 release APKs, keep universal+arm64+armv7 (34ada0b) Download: AltSendme 0.4.1 | ARM64 | ~9.0 MB (Open Source) Download: AltSendme for MacOS | Android Links: AltSendme Home Page | GitHub | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • You are mostly right about the ephemeral nature of it. As I mention in the article, if you dont add a second device or take a backup of your account before uninstalling it, then yes you will lose access to your account. That said, in terms of actual user experience when you sync multiple devices your message history carries across and there's also a Saved Messages chat like there is on Telegram to send messages and attachments between your installs. But yh, what you point out are correct and its not trying to emulate Messenger or Telegram.
    • OK so SearXNG is a meta search engine that you can install locally or use via a public instance. It scrapes other search engines which you choose and then sorts the results. Not as complicated as multiple relays
    • The only difference here is that you think you came up with these reasons. You didn't. These age old fearmongering lies (that were NEVER true) were funded by and the anger stoked by Putin through proxies like Farage (and later in the USA, Trump) and filtered down through the skinheads, Neonazis, etc. until it reached the uninformed, ignorant, and gullible -- never realizing they were being played for fools against their own best interests. Even now, despite all of the EVIDENCE proving that Brexit was a terrible mistake for ALL citizens of the UK and that its supporters were tricked by Putin's proxies into sabotaging their own nation, you're still here defending these well-known lies as if they were ever true. Not only are they not true. They NEVER were. So, when are you going to realize that you were lied to and actually get angry at the liars and charlatans who lied to you, instead of blaming the innocent people they lied to you about?
    • Dupe of "Microsoft further improving Windows 11 Taskbar with latest builds", published <20 minutes apart
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      495
    2. 2
      +Edouard
      225
    3. 3
      PsYcHoKiLLa
      152
    4. 4
      Steven P.
      75
    5. 5
      FloatingFatMan
      71
  • Tell a friend

    Love Neowin? Tell a friend!