The reason why I support Gecko and Ladybird’s engine is because I am opposed to monoculture, however. Even if Gecko (Firefox) is less secure than Chromium (Chrome, Edge, etc.), by not having a monoculture, a Chrome exploit will only take down the subset of people using the Chromium ecosystem, and not affect Gecko users. Alas, most people are in the Chromium ecosystem right now so that means malicious hackers only need to target one codebase.
It’s the same reason I wrote MaraDNS back in 2001—back then, there was only one open source DNS server[1,2] so I wrote another one.[3]
[1] Djbdns was around back then but wasn’t open source, which limited its adoption.
[2] MaraDNS was and is optimized for running at most a few dozen domains on a system running a bunch of other services, where one does not want the DNS server causing security problems for the server, and where the DNS server needs to be lightweight as possible.
> Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
What's the difference between "executing arbitrary code inside the sandbox via a crafted HTML page" and running whatever is in the <script> tag?
In the script tag you only have access to JS. This allows you to escape JS and have native code execution. It is still sandboxed by os-level primitives, but it is an escalation/first step in successful exploitation.
I see, so there are certain things that arbitrary native code could try do (let's say, try to execute a certain syscall) that native code produced by the JIT compiler wouldn't normally be able to attempt?
I know nothing about writing an image editor or graphics programming but maybe someone here can fill me in - would it be more or less difficult ("would it take more or less tokens" is probably the right question to ask these days) to replace the Windows-specific APIs with cross-platform alternatives (I guess Skia instead of Direct2D and something like Avalonia or Uno instead of Win32-based UI?) instead of re-implementing Direct2D?
However, I think without having the burden of legacy code and APIs it is a bit easier to accomplish. Probably paint.net has been targeting Windows platforms from the beginning and making it "Linux compatible" has not been a big effort but more a side effect of fixing some stuff and wine generally being awesome.
I personally would love to see commercial editors like Affinity Studio targeting Linux. While solutions like Krita and Gimp are great, it did not really click for me. I'm using Gimp, but somehow I often find myself seeking for how to do easy tasks that should be more intuitive.
> it really is also a tool to best codify spoken language of the Slavs (in a sense, it is trivially provable that Cyrillic script is better adapted even to languages which do not use it today, but have to resort to digraphs or glyphs with diacritics — some are thus not using it to distance from a particular influence instead
I've heard this claim many times but never the reasoning behind it - by what metric is "ш" superior to "š" and so on?
It's less pronounced with diacritics, but enter Unicode normal forms: you can represent š either as š, or s followed by a diacritic. When you want to compare two strings, you have to normalize them to ensure you are comparing apples to apples. I can guarantee most software is broken in that regard. For Cyrillic, it just works.
With digraphs (lj, nj, dž + sometimes dj for đ too), it's even worse. Even capitalization is ambiguous: sometimes it's Lj and other times it's LJ. Then you have words like konjugacija where nj is not a digraph.
Interestingly — and not many know this — Unicode includes separate codepoints for all of the digraphs too. While well-intentioned, it only makes the problem worse.
Digraphs are especially sucky when you try sorting strings in a phonebook order as LJ comes after L, so you've got ...LI, LK..., LZ, LJA... With exceptions, it is even worse.
> It's less pronounced with diacritics, but enter Unicode normal forms: you can represent š either as š, or s followed by a diacritic. When you want to compare two strings, you have to normalize them to ensure you are comparing apples to apples. I can guarantee most software is broken in that regard. For Cyrillic, it just works.
It's the same with Unicode encoding of Cyrillic letters - й (U+0439) can be written as й (и U+0438 + ◌̆ U+0306)
> Interestingly — and not many know this — Unicode includes separate codepoints for all of the digraphs too. While well-intentioned, it only makes the problem worse.
Based on your description it seems that the root cause of the issues is using two letters to represent the digraph - for example N (U+004E) J (U+004A) instead of NJ (U+01CA) - and the sorting issues would be identical if people typed Н (U+041D) Ь (U+042C)instead of Њ (U+040A).
What's the reason for the digraph being substituted by 2 letters in the first case more often than in the second case?
You are absolutely right that there are examples where Cyrillic as used by Slavic languages is not perfectly "clean" either, and it's certainly a lot more nuanced than my simplistic and absolutist claim.
Perhaps people misunderstood me: it is not a _technical_ property of Cyrillic (vs Latin) script per se, but a combination of historical setting and ability to adapt the script to the (smaller) group's language. This has led to Cyrillic scripts being _developed_ to be technically more suitable for Slavic languages, because where Latin script was used, there was not as much liberty (perceived or real).
I mean, either is just a set of pictograms representing parts of spoken words, and obviously, if developed similarly, there is no difference between them. But for Slavic languages they were _not_ developed similarly, which is my point.
So, it's not "trivially provable that Cyrillic is better suited to Slavic languages". But that "the symbols representtion we settled on in software has some difficulties disambiguatuong some, but not all cases of symbol use in a language, a problem that is not unique to Slavic languages, see Dutch IJ, Turkish ı/i, German ß etc."
Decoupling choice of script from "symbols representation" is a weird approach — this is how people type them out.
Yes, problems are not unique to Slavic languages, but at least for _some_ Slavic languages, Cyrillic has been taken to the most simplified form that is _accidentally_ easy to process on a computer too.
But yes, I was a bit too absolutist, I agree — as ever, everything is more nuanced, so perhaps not "trivially provable", but in "closer to full differentiation in graphical representation while being simple and unambiguous to process on a computer"?
If a search engine (be it Ecosia, Qwant, DDG or Google) is used by someone who is running uBlock Origin, does it benefit the company running the engine or does the cost of queries with no chance of displaying an add to the user outweigh the benefit from the meager amount of data collected (IP address? Interest in given keywords? Some more data for tuning the search results?)?
Search engines should be run as utilities. Unfortunately we are now in the stage where utilities (and other must haves such as education) are run as private enterprises.
You say that, but I don't think you actually want that. Utilities are very good for important, slowly changing type things. They ossify into conservative, safe services. Which is good if we're talking about power generation and transmission or water treatment or whatever. Search is still changing way too rapidly.
We do, on the other hand, need better regulation regarding how individual data can be used, collected, and shared, particularly in the US.
Food production doesn't have the same dynamics as search does. There is little value in thousands of small search farmers each indexing their own acre of the Internet space. That's why it should be run as a utility, it's not about importance.
How soon are effects visible? Complete lack of food - days, chronic malnutrition - months or years. Lack of education - decades. Many people are not smart enough to think that far ahead.
Lack of education is also generally desirable to many people in power. Not just politicians who can more easily lie but also managers and execs. If the tax system is beyond most people's understanding, rich people are not gonna get taxed properly. If people can't do the math on how much value their work produces for a company, they are not gonna understand how big a chunk the people above them in hierarchical structures (like most companies) take out of it.
Unlike food, education (or lack of it) doesn't have universal definition. Because of that it's easy to stretch and manipulate. And it's been stretched and manipulated all the time cause possibility to indoctrinate young people creates immense political power. Like with free speech, non-uniform, not strictly state controlled (which implies private) education is a way to prevent state bureaucracy to concentrate too much power. That's not touching the fact that state hierarchies are well known for their inefficiency. Let's be fair, the reason people usually passionately bring education with politics in neighboring sentences is because it's widely accepted that our beliefs are right, and therefore people who stand against them are dumb, and maybe education can lead them (or at least their children) to our embrace! Funny thing, those "our beliefs" are often incompatible, and even opposite. Which makes me think that humanity doesn't work like that really
Current search trends, and which results get clicked for which queries, are still intrinsically valuable. Mostly for the search index signals as you mention, and other things like updating recrawl rates, etc.
Even for established players these have value because the index gets stale quickly for certain queries that many people care about a lot. Even though that value isn't fungible, or enough to break even if it were, it's the kind of value that keeps the search engine competitive.
Vivaldi has a (as private as possible, check their blog) whitelist for click attribution. My guess they refer to ads on search engines on their partner search engine.
> For example, the German "Ich sehe die Frau mit dem Fernglas" (I see the woman with the binoculars) is _unambiguous_ because "die Frau" and "mit dem Fernglas" match in both gender and case. If this weren't the case, it could be either "I see (the woman with the binoculars)" or "I see (the woman) with [using] the binoculars".
My German is pretty rusty, why exactly is it unambiguous?
I don't see how changing the noun would make a difference. "Ich sehe" followed by any of these: "den Mann mit dem Fernglas", "die Frau mit dem Fernglas", "das Mädchen mit dem Fernglas" sounds equally ambiguous to me.
Does visiting pages A and B on day 1 and visiting page A on day 2 also make the sentence true? I think that's the source of ambiguity (or maybe it's ambiguous to me only because English is not my native language).
The user has visited A and B on day 1, and A on day 2.
So the total page hits is (A, B, A). Remove duplicates and you have (A, B) which makes the sentence true.
The noun is not the issue but rather the scope of uniqueness:
>Now, given two log files (log file from day 1 and log file from day 2) we want to generate a list of ‘loyal customers’ that meet the criteria of: (a) they came on both days, and (b) they visited at least two unique pages.
It appears to me that the requirement could be interpreted as either:
"(visit on day 1) AND (visit on day 2) AND (total unique pages count > 2)"
a clearer way to put it would be "visited at least two unique pages in total"
or
"(visit at least two unique pages on day 1) AND (visit at least two unique pages on day 2)"
a clearer way to put it would be "visited at least two unique pages on each day"
I specifically mentioned mounting (https://rclone.org/commands/rclone_mount/ which may use some additional storage space depending on the caching configuration) whereas you seem to be talking about mirroring the data in the cloud and on other devices.
From what I understand it's their friendly interface that differentiates them from RClone mount. I've only read their documentation but otherwise I can't see any benefit and only the risk of getting involved with a less tested tool.
Yup, it's also very useful for doing stuff like checking archive integrity after upload (got bitten by it once when uploading some archives via FTP) and syncing with cloud - I've had a dedicated client remove files from my PC instead of the cloud after desync, rclone makes it easy to check what will be done and works with pretty much every service available.
I know this is old: https://madaidans-insecurities.github.io/firefox-chromium.ht...
but has the situation changed substantially in favor of Firefox?