6 ms·
The fact that this can now be run in a browser on a laptop rather than a high end gaming rig is indeed amazing.
by lagerstedt 6y ago
The fact that this can now be run in a browser on a laptop rather than a high end gaming rig is indeed amazing.
- pjmlp 6y agoIt was already possible in 2011, but alas politics. https://www.youtube.com/watch?v=UQiUP2Hd60Y https://www.youtube.com/watch?v=UQiUP2Hd60Y https://adobe-flash.github.io/crossbridge/ https://adobe-flash.github.io/crossbridge/
- jjoonathan 6y agoFlash had more issues than "politics."
- pjmlp 6y agoYeah lets see how many security issues we get to see in WebAssembly sandboxes once researchers set their sights on them, given that they already found a couple on JS engines.
- BubRoss 6y agoYou bring this nonsense up in every webasm thread and every time it is explained to you that webasm does no IO and is contained in the same environment as javascript. Every time you either bring up details that have nothing to actually do with webasm or you say something vague about possible security problems in the future. If you have real criticism based on real information, let's see it.
- pjmlp 6y agoYou mean the same JS engines that already have several entries on the CVE database? Yeah, really safe.
- BubRoss 6y agoCan you link one that has to do with webasm? Are you saying that you think javascript is less secure than flash?
- pjmlp 6y agoIndeed, https://www.contextis.com/en/blog/webgl-a-new-dimension-for-browser-exploitation https://www.contextis.com/en/blog/webgl-a-new-dimension-for-... https://react-etc.net/entry/exploiting-speculative-execution-meltdown-spectre-via-javascript https://react-etc.net/entry/exploiting-speculative-execution... https://www.virusbulletin.com/virusbulletin/2018/10/dark-side-webassembly/ https://www.virusbulletin.com/virusbulletin/2018/10/dark-sid... https://www.cvedetails.com/vulnerability-list/vendor_id-20412/Webassembly.html https://www.cvedetails.com/vulnerability-list/vendor_id-2041... https://i.blackhat.com/us-18/Thu-August-9/us-18-Lukasiewicz-WebAssembly-A-New-World-of-Native_Exploits-On-The-Web-wp.pdf https://i.blackhat.com/us-18/Thu-August-9/us-18-Lukasiewicz-...
- BubRoss 6y agoAll of these are speculation about the future. Most have nothing to do with webasm at all. The first is about webgl (that has nothing to do with webasm) The second is about using javascript with intel speculative execution exploits. The third is grasping at straws, saying that call center scams would be more obsfuscated, even though javascript or asm.js can be just as obsfuscated, if not more. The fourth is about crashes in the webasm JIT The last is about -theoretically- executing arbitrary javascript. Heavens no. What is the real reason you have some crazy crusade against webasm? You go to great lengths to grasp at any straws you can. It isn't that big of a deal. It is a more direct way to JIT cpu intensive parts of a web page. Get over it. Incredibly, the alternative is to run actual native instructions by downloading a binary.
- pjmlp 6y agoSurvivor of the anti-PNaCL, Java and Flash crusade I guess.
- modeless 6y agoWasm has been here for years already. There's no flood of issues waiting for some cue to be released. It's no worse than any other part of the browser; probably better than some. Besides, modern browsers don't rely solely on one sandbox anymore. There are many levels of protection now.
- pjmlp 6y agoCPUs were deemed unexploitable, until researchers had a better look into them. The only thing that makes WebAssembly safer than its predecessors, is that most security researchers haven't yet bothered with it.
- hjanssen 6y agoWhich is already true for any type of software. Bugs exist everywhere. Of course you finde some if you put in the effort. That is not something that marks the quality of the code.
- na85 6y agoNot all ideas were created equal. Parent's contention (one I agree with) seems to be that the contemporary browser-as-app-deployment-platform paradigm is a bad idea.
- modeless 6y agoI didn't say Wasm is unexploitable. You're attacking a straw man. Wasm vulnerabilities are worth real money. Bug bounties are tens of thousands of dollars to hundreds of thousands as part of exploit chains. If people aren't finding many, your explanation will have to be a little bit better than "they haven't yet bothered".
- pjmlp 6y agoCurrently there are better rivers for panning, but rest assured they will come. https://i.blackhat.com/us-18/Thu-August-9/us-18-Lukasiewicz-WebAssembly-A-New-World-of-Native_Exploits-On-The-Web-wp.pdf https://i.blackhat.com/us-18/Thu-August-9/us-18-Lukasiewicz-...
- jchw 6y ago... the issues with Adobe Flash are quite a bit more varied than “politics.” At best, it was always a drag on mobile platforms, reducing battery life and hogging resources, and at worst it’s pretty much best known now for its security issues that ultimately helped further its demise. If you want to go a step further, in 2011 you could also have probably delivered your game as an NPAPI extension and got pure native code instead. You could deliver these via extensions, even in Chrome.[1] Native Client also came to fruition in 2011, and Firefox chose not to support it. I doubt many would chalk that up to just politics, either, but I think it’s fair to compare. [1]: https://developer.chrome.com/apps/npapi https://developer.chrome.com/apps/npapi
- pjmlp 6y agoApple speech I guess. It was perfectly fine on any Symbian and Android device I got to play with, and much better than J2ME ever was.
- jjoonathan 6y agoOne time I accidentally left SpinControl.app on for a week and went about my business (SpinControl, RIP, was an app that logged stack traces any time an app didn't flush its event queue for more than a few seconds -- i.e. caused a beachball). A week later I came back and checked it to find something truly astounding: with hundreds of logged spins, 100% of them were due to flash. Usually in Safari, but sometimes in other embedded webkit contexts. You would expect a few spins to creep into that list from other causes, and indeed I triggered one with a mail index rebuild just to be make sure it was watching more than the browser process, but no, SpinControl was working fine. 100% of the beachballs in the last week were due to flash's suckiness, to say nothing of power usage or security. Flash's performance issues, at least on the mac, were very real. Good riddance. > much better than J2ME ever was. If you lower the bar to the ground anyone can jump over it.
- jchw 6y agoiPhone never had Flash I don’t believe. I was an Android user at the time and the only way Flash on my device could be described is in terms of locomotive incidents. Flash games and applications almost worked, although virtually none of them were responsively designed, and they mostly worked pretty poorly with touch controls, and unlike HTML there was no way to reasonably work around or improve this at the browser level, because it was just a big proprietary black box. Worse than this was sites that used Flash in non-essential ways like ads. If you had Flash enabled on a blog or other site that just happened to pop up a flash ad, it would make the whole page janky, greatly hurting pan and zoom functionality and killing your battery life for no benefit. Worst of all, Flash frequently crashed my browser and sometimes even caused the entire phone to reboot. Phones now have better CPUs and GPUs and I am relieved beyond words that Flash is totally dead now. It was never ideal for what it was most popular for (videos, streams) which only became apparent after the alternatives stabilized. But even for games and other software, I just don’t think the NPAPI browser plugin model was worth keeping. Would the problems with touch usability and accessibility be resolved at some point? Maybe I don’t know - I presume Adobe Air was able to do it for native apps, although my experience with Adobe Air apps was also not very good. J2ME may have been not the most thrilling platform, but I’d not be surprised if it had a better security track record at the end of the day. I disabled Flash before most people, and was using a userscript to use the then-new and buggy <video> tag for YouTube. I still, before that point, had been personally hit by a Flash 0day, and a couple of my friends got hit later by a malicious Mediafire Flash payload. There was a period of time where it felt like there was a new use-after-free in Flash every month. And when you look at all of the functionality stacked into this unsandboxed blackbox to keep it competitive and alive, I don’t feel it’s terribly surprising. I don’t enjoy everything about the bloated platform that is the modern web, but the design of it is a lot more sound. It’s designed more as a platform than a product. You get a lot of totally brand new functionality, like WebRTC, that just wasn’t really going to happen with Flash. Flash had to die. It wasn’t a part of the web platform, it was part of an Adobe product that was shoehorned into web browsers. If it has a good legacy, I reckon it will mostly be from nostalgia fueled denial.
- gnulinux 6y agoIt's intellectually dishonest to imply de-adoption of flash was just "politics". Flash had all sorts of problems, we should be happy we managed to get rid of it. Back in the day I was too cynical to think one day we can do so.
- pjmlp 6y agoNot at all, it remains to be proven that WebAssembly is any better. I eagerly wait for the first batch of CVEs.
- BubRoss 6y agoHtml5 and modern javascript already replaces flash as a target. I don't know if the tools are the same. Webasm isn't necessary for that, its use is accelerating cpu intensive parts of a web page.
- pjmlp 6y agoExcept it is not. https://www.leaningtech.com/pages/cheerpx.html https://www.leaningtech.com/pages/cheerpx.html https://www.leaningtech.com/pages/cheerpj.html https://www.leaningtech.com/pages/cheerpj.html https://www.qt.io/blog/2018/05/22/qt-for-webassembly https://www.qt.io/blog/2018/05/22/qt-for-webassembly https://platform.uno/ https://platform.uno/ https://dotnet.microsoft.com/apps/aspnet/web-apps/blazor https://dotnet.microsoft.com/apps/aspnet/web-apps/blazor
- BubRoss 6y agoI don't know what point you are making here. These projects could have been done by compiling to asm.js - webasm isn't what makes them technically possible, it just makes them faster, smaller and parsed faster. You have been told all of this before.
- pjmlp 6y agoJust like you have been told before that WebAssembly is nothing new beyond politics, all the way back to 1961.
- cromwellian 6y agoWhat about 2010 without flash? We ported the Java version of Quake2 using GWT in 2010 https://youtu.be/aW--Wlf9EFs https://youtu.be/aW--Wlf9EFs
- pjmlp 6y agoEven better.
- bgorman 6y agoThis is a 20 year old game.
- jcelerier 6y agois it ? quake 3 is a 1999 game. It's closer in time to MS-DOS 6.22 (1993) than to Windows 10 (2015)... and it's not even reaching 60fps on my 1080...
- deleted 6y ago[deleted]
- jeffhuys 6y agoI hits 60 fps steadily on safari & chrome on my macbook.
- deleted 6y ago[deleted]