Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Indeed, but wouldn't such a plan start with building on a firm foundation that isn't going to get EOL'd and no longer support security updates after three months?

Why? Why does it matter if 4 is EOL when 5 is available? Instead of obsessing about having security updates, why not just expect updates. If you're willing and able to test and deploy a new browser every 3 months, what does it matter if they call it 4.2 or 5.0? Test and deploy the new browser and stop worrying so much about the version number.

> If anyone is about to pipe up with how they only release useful changes and the community testing is sufficient to prevent regressions, please keep in mind that both Firefox and Chrome have each outright broken both cosmetic rendering details and basic functionality recently, in minor/point releases that you wouldn't normally expect to change user-observable behaviour at all, plus of course there are many widely and less widely reported compatibility issues.

So don't deploy on day 0. Breaking changes can be, and sometimes are, introduced in minor version increments. If you need to test, you need to do so whether you're going from 5 to 6 or 5.1 to 5.2.



> If you're willing and able to test and deploy a new browser every 3 months

I'm not, and I don't think a lot of other people are either. The version number is irrelevant. The frequency of releases is the problem here.

> So don't deploy on day 0. Breaking changes can be, and sometimes are, introduced in minor version increments.

OK, fine, but now everything is effectively a minor version increment in Firefox and Chrome, and anyone who doesn't update within 90 days is apparently going to lose all security updates. That is not a viable combination for any users who value a stable platform they can build on more than cutting edge toys.


> I'm not, and I don't think a lot of other people are either. The version number is irrelevant. The frequency of releases is the problem here.

A lot of people very clearly are willing to update every three months. A lot of users update Firefox regularly. And for people using Chrome, they get updates even more frequently. When the upgrading is painless, no one minds doing it.

As for corporations, if they aren't willing to roll out a new browser every three months, how often are they willing to do it? And how are they dealing with browser exploits in between these long cycles?

> OK, fine, but now everything is effectively a minor version increment in Firefox and Chrome, and anyone who doesn't update within 90 days is apparently going to lose all security updates.

So how is this different? If you are not willing to update, you're not getting security updates anyway.

> That is not a viable combination for any users who value a stable platform they can build on more than cutting edge toys.

This is either hyperbolic or delusional. You tell me which. I'm using the latest version of Chrome. I also have Firefox 5 installed. They both work on every site I've visited lately. The only exceptions are some internal corp sites that only work with IE, and those clearly didn't work with FF 3.6 either (also I think those were all recently upgraded or retired so they're no longer an issue, but I'm not certain).

If you want to build stable apps, then use the stable pieces of HTML/CSS/JS/whatever. No one says you have to use the latest feature that Chrome/Firefox/IE/Safari added. You can choose to build on a stable platform without running a 2-year-old browser.


> A lot of people very clearly are willing to update every three months.

...and a lot of people very clearly are not. So now what? We say, "this doesn't work for lots of people", you counter-point that it does work for a lot of people ... both statements are true and nothing has been accomplished.

> And for people using Chrome, they get updates even more frequently.

And for people using Internet Explorer, they get updates much less frequently. Guess which browser still has the lion's share of the market? (Hint: http://getclicky.com/marketshare/global/web-browsers/)

> When the upgrading is painless, no one minds doing it.

Right, and that's the rub! Upgrading is not painless! I think you, and I, and Silhouette are in agreement here: if upgrading were painless, no one would mind doing it. The problems seems to be that for you, "painless" means, "I have to download and install it", and for us, "painless" means, "we have to answer support calls about what happened to the bookmarks menu and why X page is no longer working even though it was two weeks ago and by the way the back button looks different and I don't think I like this new version..."

> If you are not willing to update, you're not getting security updates anyway.

Nobody's objecting to security updates!

This very statement is so indicative of what the problem is here: that security updates are being conflated with application updates. Security updates are fine! Corporate IT will almost always roll out a revision change, no problem!

Microsoft's Update Tuesdays? Usually OK!

Service Packs? Let's wait!

Now Mozilla's got a huge troll face on and is saying, effectively, "Hehehe, here, have an update ... it might be a security update, it might be a service pack! Enjoy!"

> This is either hyperbolic or delusional. You tell me which.

See, now here's where I want to make this personal now.

Don't pull that shit. Just because you don't understand someone else's problem, doesn't mean their problem is insignificant. OK?


> ...and a lot of people very clearly are not. So now what? We say, "this doesn't work for lots of people", you counter-point that it does work for a lot of people ... both statements are true and nothing has been accomplished.

Now nothing. I never said there weren't a lot of people on the other side. I was responding to Silhouette's comment: "I'm not, and I don't think a lot of other people are either." He's not willing, and doesn't think many others are. That's incorrect, because indeed many others are. "I don't think a lot are" is not the same as "I think a lot are not". (Compare: "I don't think a lot of people are fans of Justin Bieber." vs "I think a lot of people are not fans of Justin Bieber." These are very different statements.)

> And for people using Internet Explorer, they get updates much less frequently. Guess which browser still has the lion's share of the market?

And? Are you advocating that Firefox should follow IEs lead? It looks like IE's lead is dropping almost as quickly as Chrome's share is rising.

> Right, and that's the rub! Upgrading is not painless!

It would be a hell of a lot less painful if it didn't involve a massive rollout of new software every 18 months. Chrome's always-updating model has proven to be painless for a lot of people.

> for us, "painless" means, "we have to answer support calls about what happened to the bookmarks menu and why X page is no longer working even though it was two weeks ago and by the way the back button looks different and I don't think I like this new version..."

So use IE and be done with it, or maintain FF 3.6 indefinitely yourself. If you want your browser to remain unchanged for very long periods of time, and Mozilla won't help you with the goal, I don't see what your other options are. I really don't see how Mozilla has an obligation here.

Also, if you upgraded frequently, the changes that arrived wouldn't be quite so large. When you follow the "big bang" software rollout technique, it's a lot of changes dumped on the user at once. If you roll out smaller changes, users have less to adapt to any any given time. Maybe just send an email telling them where the bookmarks moved to.

> Nobody's objecting to security updates!

My point was that you have to go through testing for security updates as well. I concede that you're less likely to have users calling to ask about why the bookmarks moved after a security update, though.

> Now Mozilla's got a huge troll face on and is saying, effectively, "Hehehe, here, have an update ... it might be a security update, it might be a service pack! Enjoy!"

That's hardly fair. What Mozilla is saying is more along the lines of "Here's the latest and greatest." And "It's too much effort to maintain a bunch of old branches indefinitely, so we're not doing that anymore."

> See, now here's where I want to make this personal now.

You want to make it personal because you took offense to something I said to someone else? How thin-skinned are you?

> Don't pull that shit. Just because you don't understand someone else's problem, doesn't mean their problem is insignificant. OK?

I did not say his problems were insignificant, and you need to stop getting your knickers in such a twist. I was responding to a specific statement: "OK, fine, but now everything is effectively a minor version increment in Firefox and Chrome, and anyone who doesn't update within 90 days is apparently going to lose all security updates. That is not a viable combination for any users who value a stable platform they can build on more than cutting edge toys." This is indeed hyperbolic (or possibly delusional). Minor versions with new functionality very clearly is a viable combination, because it's been working for Chrome for some time now.

The idea that you need everyone on FF4 for a year so that you can have a "stable platform" for development is ridiculous. If the move to FF5 is going to break everything, then you're already screwed, and your best bet isn't to dump a year into development for FF4, but to find a way to write apps that won't break every time the browser is upgraded. You cannot stay on FF4 forever (I hope), so at best you can postpone the problem and probably make it much harder to resolve in a year.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: