Web Browsers

4 posts

discord2 min readCurated summary

Every Voice and Video Call on Discord Is Now End-to-End Encrypted

Discord now uses end-to-end encryption by default for nearly every voice and video call, without requiring users to opt in. The rollout, completed in March 2026, relies on the open DAVE protocol and spans desktop, mobile, browsers, consoles, bots/apps, and the Social SDK. Discord says encryption was introduced without reducing call quality or performance, though Stage channels remain exempt. ## Building DAVE Across Platforms - Discord began experimenting with voice and video E2EE in 2023. - The DAVE protocol was introduced in 2024 as an open, audited encryption system. - Support was expanded to: - Desktop and mobile - Web browsers - PlayStation and Xbox - Discord bots and apps - The Social SDK - The protocol and its implementation are publicly available and open source. - Trail of Bits externally audited the design and implementation. - Discord expanded its bug bounty program to cover DAVE. - The team collaborated with Mozilla to fix a Firefox issue that interfered with encrypted calls. ## Reaching Default Encryption - Since early March 2026, E2EE covers calls in: - Direct messages - Group DMs - Voice channels - Go Live streams - All clients must support DAVE before joining a call. - Discord is removing unencrypted fallback code, after which calls will no longer be able to downgrade to unencrypted connections. - Encryption operates transparently, preserving expected call quality and latency. ## Why Stage Channels Are Excluded - Stage channels are intended for large-scale broadcasts, AMAs, live events, and town halls. - Their broadcast-oriented architecture differs from personal voice and video conversations. - Discord therefore continues to exclude them from E2EE. ## Future Privacy Work - Discord will continue maintaining and improving DAVE, including its open protocol and bug bounty program. - The company has no current plans to add E2EE to text messages. - Many Discord text features depend on server-side access to messages, so supporting encryption would require substantial redesign. Discord’s recommendation is effectively to treat DAVE as an ongoing privacy foundation rather than a finished project: voice and video calls are now protected by default, while the protocol remains open to inspection and continued improvement.

Read original(opens in new tab)
cloudflare3 min readCurated summary

Moving past bots vs. humans

The distinction between bots and humans is becoming too blurry to serve as the foundation of web protection. Browsers, accessibility tools, proxies, and AI agents can all behave differently while representing legitimate users, while human activity can also be malicious. Website owners should instead focus on intent, behavior, resource usage, and trust. ## The Web’s Original Balance - Browsers act as user agents, mediating between people and websites. - Websites rely on browser conventions to: - Present content correctly across devices. - Support purchases, logins, media, and accessibility. - Deliver advertising and control user experiences. - The web has historically balanced publisher interests with user freedoms through browser standards, extensions, and accessibility requirements. - AI agents disrupt this balance by fetching raw content without rendering pages like browsers. - Publishers often cannot tell whether a request supports one private summary or large-scale model training, making traffic and monetization less predictable. ## The Client-Server Model - Clients request resources from servers, which respond with the requested content. - Websites can scale through additional servers, caching, and CDNs. - The model’s openness allows many types of clients to interact with servers without requiring servers to understand their internal software. - That flexibility creates uncertainty: servers generally cannot see whether a response is: - Rendered for one person using a browser. - Automatically collected, archived, indexed, or reused by another system. ## Why Bot Management Exists - Websites must decide which requests they can afford to serve when capacity, CPU, or cost limits are reached. - Randomly dropping requests is possible but risks blocking legitimate users. - Access controls are also used to: - Separate attacks from normal traffic. - Manage non-malicious load. - Prevent data extraction and fake account creation. - Limit ad fraud and automated actions. - Web clients are unauthenticated by default, so services infer identity and intent from partial signals such as request volume and IP addresses. - A high-volume IP may indicate abuse, a VPN, or multiple users sharing one address, making simple bot-versus-human classifications unreliable. ## Toward Intent and Behavior-Based Protection - The important questions are whether traffic represents an attack, whether crawling is proportional to returned traffic, whether a login from a new country is expected, or whether advertisements are being manipulated. - “Bots” encompass two separate concerns: - Whether known crawlers should receive access when they provide little traffic or value in return. - Whether emerging clients behave unlike traditional browsers, affecting systems such as private rate limits. - Automation detection remains necessary, but protection systems should be designed for a future where automation is common among both legitimate and malicious actors. Website protection should evolve from identifying “bots” to evaluating intent, behavior, proportionality, and risk. The goal is not to determine whether a client is human, but whether its activity is expected, sustainable, and trustworthy.

Read original(opens in new tab)
figma3 min readCurated summary

Six Memos for the Future of Digital Creation | Figma Blog

The article presents six Figma “memos” about the future of digital creation in 2025. Drawing on the tradition of influential workplace memos, it argues that documenting observations, strong opinions, and emerging opportunities can stimulate dialogue and change. The themes range from creative coding and broader definitions of design to emotional differentiation, handmade websites, and generalist careers. ## The Memo as a Tool for Shaping the Future - Figma frames the memo as a concise way to communicate ideas, critique strategy, and encourage organizational change. - The article references influential examples, including Bill Gates’s advocacy for graphical interfaces and Stewart Butterfield’s “We don’t sell saddles here” memo for Slack. - Memos can be strategic, metaphorical, playful, or reflective documents that preserve how thinking develops over time. - Figma’s six contributors use the format to examine trends across design, development, product, writing, analysis, and community work. ## Developers Should Embrace Creative Coding Again - Modern browsers now support capabilities that often exceed those available in conventional design tools. - Developers are encouraged to move beyond templates and standardized production workflows. - The memo calls for renewed experimentation with the web as a creative medium. - Creative coding is presented as a way to explore the browser’s full expressive and interactive potential. ## Expanding the Definition of Design - The second memo argues for a broader understanding of what design encompasses. - Its inclusion reflects the article’s wider focus on how digital creation crosses traditional professional boundaries. ## When to Leave the Product Roadmap - The third memo examines when teams should move beyond planned roadmap work. - It suggests that product development may require responding to unexpected opportunities rather than following predetermined priorities exclusively. ## Emotion as a Competitive Advantage - The fourth memo identifies emotion as an emerging source of competitive differentiation. - As digital products become increasingly similar in function, how they make people feel may matter more to their success. ## Making Space for a Handmade Web - The fifth memo advocates preserving room for distinctive, human-made experiences on the web. - It contrasts this idea with increasingly standardized, templated, and automated digital production. ## The Rise of the Generalist - The final memo focuses on the growing importance of people who work across disciplines. - Its inclusion reinforces the article’s view that future digital creation will depend on collaboration between design, development, product, writing, and other fields. The article’s practical recommendation is implicit: observe emerging patterns, write down strong ideas, and share them. Memos can turn informal workplace thoughts into conversations that influence products, teams, and the broader direction of digital creation.

Read original(opens in new tab)
figma2 min readCurated summary

Can we reach beyond the echo chamber? | Figma Blog

The Browser Company’s Arc browser aims to rethink everyday browsing by drawing inspiration from outside the technology industry. Karla Mickens Cole and Nashilu Mouen argue that products become distinctive when they reflect many creative influences rather than copying existing conventions. Their approach to AI emphasizes subtle, useful experiences that blend naturally into users’ lives instead of adding AI merely as decoration. ## Designing Beyond the Tech Echo Chamber - The team deliberately looks to literature, film, art, and nature for inspiration. - Mouen cites writers such as Zadie Smith and Toni Morrison, asking how technology can be “in tech, without being of tech.” - The browser is treated as a large creative canvas with room for experimentation and play. - The team’s diverse perspectives contribute to a brand built from “many voices.” ## Reinventing Familiar Browser Conventions - Arc challenges established patterns, including the traditional placement of browser tabs. - The team’s recurring question is “Why not?”—a mindset that encourages them to reconsider assumptions. - Arc’s unboxing experience drew on: - Movie title sequences - The opening atmosphere of A24 films - The visual phenomenon of sunspots - These outside references help the product feel meaningfully different, not simply functionally new. ## Making AI Feel Natural - The Browser Company wants AI to solve practical problems and blend into ordinary browsing rather than overwhelm users with conspicuous AI branding. - Cole compares the desired approach to flowers: - They can appear unexpectedly and make an experience feel special. - They suggest care without being disruptive. - They reflect AI’s ongoing “seasons of growth.” - The team sees AI as something to plant thoughtfully within the product experience, not apply indiscriminately. ## Rapid Experimentation - The team prototypes quickly and evaluates which AI ideas genuinely improve the product. - Mouen notes that they had explored more than 30 applications in the previous month alone, indicating an experimental process in which some concepts will work and others will not. - Their view of AI is therefore practical and seasonal: its impact depends on the context and the moment. The article’s central recommendation is to build technology with influences beyond technology itself. For AI in particular, thoughtful integration, experimentation, and emotional subtlety may create more valuable experiences than adding obvious, standardized features.

Read original(opens in new tab)