Firefox 153.0 Beta

15 hours ago (firefox.com)

> Firefox now verifies and displays Qualified Website Authentication Certificates (QWACs) in accordance with eIDAS regulations.

Interesting that they just buried this in the middle without even a screenshot, considering how hostile Mozilla has been to the proposal in the past[0].

Considering that they previously made quite strong arguments that implementing QWAC would undermine security by completely bypassing the existing CA trust process and violate user's privacy by leaking browsing activity to third parties: what changed?

It does seem to fit into a wider movement, though. Mozilla previously explicitly considered WebUSB, WebHID, and WebMIDI as "harmful" as they lacked an effective mechanism against hostile websites tricking users into permanently compromising their hardware. This switched to "neutral" without addressing the underlying issue, seemingly just to satisfy some users asking for parity with Chrome out of a convenience argument. Same with Firefox happily jumping onto the AI bandwagon, and only backtracking after major public outcry.

Not to be dramatic, but Firefox seems hellbent on rapidly turning into a reimplementation of Chrome, completely ignoring its raison d'être. Will there be any traditional user-serving browsers left a few years from now?

[0]: https://s3.documentcloud.org/documents/21330628/mozilla.pdf

  • > Firefox seems hellbent on rapidly turning into a reimplementation of Chrome

    You can rest assured that Mozilla will never copy Chrome's updating the mouse coordinates during dragstart, drag and dragend events.

    "the spec doesn't specify what the properties should be set to, just that they should be set and we currently set them to 0."

    https://bugzilla.mozilla.org/show_bug.cgi?id=505521

    16 years and no sign of a resolution. I look forward to celebrating the day that bug becomes old enough to split a six pack with me.

    Edit: It was first filed on July 21, 2009 so it will soon be 17.

  • > Will there be any traditional user-serving browsers left a few years from now?

    One can hope that by then Ladybird has landed. There was some rumblings about an alpha release come 2027 so "few years" might actually be achievable if the speed remains constant.

    • I’m waiting for the Gemini people to (re-)discover HTML 3.2 or 4.0. Maybe this then becomes a slightly bigger movement as all current browsers should support it and there are plenty much smaller/more efficient browsers available from back in the time.

  • So that's basically state legalized and enforced MITM and scamming framework (unless I'm mistaken about tech details)? Yay for progress, I guess... :(

  • > This switched to "neutral" without addressing the underlying issue, seemingly just to satisfy some users asking for parity with Chrome out of a convenience argument.

    Well... millions of Chrome users played guinea pigs for WebUSB and the security issues proved to be theoretical in the end, while (particularly in the Arduino/ESP32 community) more and more people were pissed off at the lack of these features in Firefox.

  • Mozilla’s executives don’t want to get arrested. It’s one thing to tell the Kazakhs to stuff it. Quite another to tell the EU, especially if any of them like overseas vacations.

    • Which is why these kinds of ultimatums NEED to be fought against, and aggressively. There ought to be NO room for any government to tell an open source project which features they must--or cannot--implement. Allowing this sort of thing is how you kill open source software. (Which may actually be their goal...)

      But, if Mozilla wanted to acquiesce, they could release an EU-only version instead of weakening the trust/security of their browser for everyone.

      Also, imagine the backlash that would happen if some part of the United States executive branch demanded the same thing the EU is demanding here.

    • If they are solely doing it for legal reasons, I would expect some form of malicious compliance - like an accompanying blog post explaining how it'll be marked as "Firefox is legally required to tell you the EU considers this page safe. We disagree. [Learn More]" and that the mark will only be shown to EU users.

      Complying to the exact letter of a stupid law to avoid getting sued is understandable. Voluntarily complying to the broadest interpretation without any pushback is not.

      2 replies →

> It is now possible to merge multiple PDFs by dragging a PDF into the PDF sidebar.

> It is now possible to add images as new pages within PDFs using the Firefox PDF editor.

I have always found it odd that browsers are also PDF editors increasingly.

  • It's odd and I'm not sure I love it compared to a nicely-done dedicated viewer (macOS Preview, SumatraPDF, whatever comes with GNOME or KDE).

    That said, I'll pick the in-browser tools over Adobe Reader every time.

    • > nicely-done dedicated viewer

      The problem is the edge cases. PDF has lots.

      In $DAYJOB-1 we used PDFs as part of the official feedback process for technical documentation: subject-matter experts sent their comments as PDF annotations. Most FOSS viewers can't show them.

      Form filling also is a tricky area. Conversion, searching, accessibility tools (screenreaders often can't read PDFs), comments, annotations, editing, all these and more are significant functional weaknesses for the free viewers.

      That's setting aside the really fancy stuff, like 3D objects, video, media content, etc.

      Even so PDF viewers are big and complicated things so smaller distros pick up tools from alien desktops -- e.g. KDE's Okular, which I find fugly but can handle comments, or GNOME's weird crippled UI in Evince or Papers, with no menu bars etc., but which is Gtk so you find it in many Gtk desktops.

      It wasn't hard for the Firefox viewer to outdo 90-95% of the free viewers because the free viewers only do the dead basic stuff, and that kept Acrobat Reader alive on other OSes -- even though the last Linux one is version 9, from 2008.

      1 reply →

    • That's not a fair comparison. The first one gives you space to stretch your legs, the other once stretches your legs on a medieval rack.

    • I prefer the Firefox PDF viewer personally, and now that it can do all this I uninstalled the default Ubuntu PDF reader recently. It made me think and I uninstalled the image viewer app too. For both I'd rather use Firefox.

    • It's better than any of them for random bullshit you've found somewhere on the internet since it provides a far stronger security boundary than any standalone pdf reader. For trusted documents, I agree.

  • PDF got attached to the browser when the browser needed a printing mechanism that worked in JS. PDF.js was the best approach. Creating PDFs is also part of the same approach. And merging PDFs is part of the same approach. PDF is now a first class child of the web.

  • I think it's a function of the endless tussle between browser-as-an-OS and the OS they run on. For example, I absolutely hate that there's no option in Firefox to only use the OS print dialog. Instead I am force to click print, then click "use system print dialog" every time. I seems to remember reading a bug report where Firefox deemed this intentional and wontfix. After all, if you leave Firefox to print something, maybe you won't ever come back and start using your print dialog to surf the web!

  • Does it work with the DRM stuff that can be in a PDF?

    I have a PDF that I can't view at all.

  • Many URLs start with http(s): and end in .pdf. If we define web browser as http browser rather than html browser, then viewing PDFs fits the concept. My web browser also displays plain text, video, audio, etc., so http browser seems accurate and html browser plainly inadequate.

    And regardless of logical fit for geeks (who understand the paragraph above), users clicking a .pdf URL may find it much more convenient if it just opens in their browser like any other http page, rather than downloading, opening in another window, getting lost between the MDI browser and separate SDI of the PDF file, etc. Why not treat PDF as just another web format?

    To me, more strange is Firefox adding PDF editing features to its core, rather than as add-ons. Users can't edit HTML or any other media without extra tools. Many pdf reader apps can't do some of these things (afaik). Why invest developer time in PDF editing?

- extremely stupid question but please entertain me here a bit

- why dont any of the modern browsers open and load pages instantaneously anymore, why does it take seconds?

- is this because of backward compatibility support where you are supporting html, css and JS features all the way back to the 90s

- apart from gecko and v8 why dont we have browser engines?

- are you familiar with anyone building an entire browser engine from scratch? how many WhatWG specifications would they have to support

- with all the GPT hype of late, why havent we seen a single GPT yet capable of building a browser engine from scratch supporting the last 20 years of html, css and js specs?

  • > why dont any of the modern browsers open and load pages instantaneously anymore, why does it take seconds?

    Right click > Inspect. Go to the "network" tab, reload the page. Maybe do the same on the "performance" tab.

  • > with all the GPT hype of late, why havent we seen a single GPT yet capable of building a browser engine from scratch supporting the last 20 years of html, css and js specs?

    Macsurf is a browser project for Mac OS 9 leveraging LLMs[1] to do this. Tbh it makes sense for this given how time-consuming (absurd? Though the fact it exists tickles me) it'd be otherwise for essentially a single person to support the scope of web tech it does for such an incredibly niche userbase.

    [1] https://news.ycombinator.com/item?id=48339534

  • > why dont any of the modern browsers open and load pages instantaneously anymore, why does it take seconds?

    If we are talking about a blog page, just a static html - it should take some ms. No problem here.

    But if we are talking about some heavy pages and fetch requests to other places, well...

    Or simply a page with f 10Mb header image.

    >apart from gecko and v8 why dont we have browser engines?

    gecko (Firefox), blink (chrome and friends), webkit (Safari, Kagi and some other, mostly linux distro browsers) are the only stable ones. Servo and Ladybird are on the way, but it will take quite some time for them to mature.

    >are you familiar with anyone building an entire browser engine from scratch?

    Ladybird. No idea about specifications.

    >with all the GPT hype of late, why havent we seen a single GPT yet capable of building a browser engine from scratch supporting the last 20 years of html, css and js specs?

    Well, aside from the fact that this will be a one expensive project - you (someone) will have to test this code anyway. Also this: https://ladybird.org/posts/changing-how-we-develop-ladybird/

  • > apart from gecko and v8 why dont we have browser engines?

    You mean apart from Gecko and Blink (v8 is a JS engine, not a browser engine.)

    But we do, for open source engines we also have WebKit and NetSurf and some others.

  • Chrome (which I don't use) provides a really good profiler that can give you answers down to the milliseconds on what's happening during page load and also actions. Web tech provides so much functionality but web dev often don't bother optimizing their sites. I'm not saying browsers are blameless, but at least you get good tools that'll give you hints.

They note containers as a new feature. Does this mean containers are shipping with the base installation, instead of as an extension?

  • Yes. Containers will be enabled by default in the regular release without the need to install the extension or flip a preference in about:config.

    It's also planned to integrate the ability to assign a website to a specific container. There's no information available on the other extra features from Multi-Account Containers like VPN/Proxy per container for the moment.

    You can follow the development on bugzilla https://bugzilla.mozilla.org/buglist.cgi?component=Container...

> Containers let you keep separate parts of your online life (work, shopping, personal, banking) logged into different accounts in the same browser window, but keep your cookies and ad tracking isolated inside each container.

What's new here? Containers have been an add-on, at least, for a long time? Is it integrated into core Firefox for the first time?

> Quickly pick and copy a color from any page by typing "pick color", "color picker", or "eyedropper" in the address bar and selecting the "Pick a color" quick action.

This seems like add-on or developer tools territory. Maybe that's what quick actions are? Does Firefox really want to add non-essential widgets to maintain, support, and integrate going forward? Maybe this one is necessary for some reason? I have a global color-picker that works in every application; I expect many who need one have the same.