Agreed. It's been hard to watch how much vitriol was pointed at Mozilla for their reasonable position. The C++ decoder was simply unsafe and they would not implement it until a memory-safe decoder was available.
Imagine if the fanatics got what they wanted immediately and then major vulnerabilities were introduced and there was a huge backlash against JXL. It could have set things back way more
and then major vulnerabilities were introduced and there was a huge backlash against JXL.
Has that ever stopped any of the previous unsafe stuff?
Seems like this would be the same - we'd just see faster adoption of the better format without browser limits
Comments
Agreed. It's been hard to watch how much vitriol was pointed at Mozilla for their reasonable position. The C++ decoder was simply unsafe and they would not implement it until a memory-safe decoder was available.
Imagine if the fanatics got what they wanted immediately and then major vulnerabilities were introduced and there was a huge backlash against JXL. It could have set things back way more
Has that ever stopped any of the previous unsafe stuff? Seems like this would be the same - we'd just see faster adoption of the better format without browser limits
Arguably killed WebSQL and Java applets, for some past examples. Currently it's why WebUSB is not getting picked up by Safari/Firefox.
Java applets were massively harder to secure than an image decoder and died in a very different era.
I don't remember security being an issue with WebSQL. The big complaint was about getting locked too tightly to SQLite's implementation details.
I see the security issues with WebUSB as not wanting to step into a minefield, which is pretty different from adding one more C++ library.
Notably, it did not stop webp and avif.