Remix.run Logo
ChoosesBarbecue a day ago

For all the furore, I think the best outcome happened here. Both browsers used their weight to get a memory-safe implementation out, and now we can all benefit from a new file format with a significantly reduced attack surface.

zamadatix a day ago | parent | next [-]

Agreed. Much thanks to Mozilla for taking the wildly unpopular decision to shoot the early proposal down as well instead of supporting it just because it'd make people more mad at Chrome.

bholley a day ago | parent [-]

Thanks all. I'm really happy with how it all turned out.

culi a day ago | parent [-]

(^CTO for Firefox at Mozilla)

culi a day ago | parent | prev [-]

Agreed. It's been hard to watch how much vitriol was pointed at Mozilla for their reasonable position. The C++ decoder was simply unsafe and they would not implement it until a memory-safe decoder was available.

Imagine if the fanatics got what they wanted immediately and then major vulnerabilities were introduced and there was a huge backlash against JXL. It could have set things back way more

eviks 5 hours ago | parent [-]

> and then major vulnerabilities were introduced and there was a huge backlash against JXL.

Has that ever stopped any of the previous unsafe stuff? Seems like this would be the same - we'd just see faster adoption of the better format without browser limits

Macha 5 hours ago | parent [-]

Arguably killed WebSQL and Java applets, for some past examples. Currently it's why WebUSB is not getting picked up by Safari/Firefox.