The name is OpenLara (https://github.com/XProger/OpenLara ) and you can try out the WebGL build directly on your web browser on: http://xproger.info/projects/OpenLara/ . The web version works amazingly well on my Pixel 7a with touch controls (you have to click on the ā€œgo fullscreenā€ button) using Firefox as a browser.

0 points
*

Yet, it is a very not-really-good idea to run stuff on a web browser. Web browsers are a notoriously insecure, slow platform with controls (ā€œBackā€, ā€œReloadā€, ā€¦) which are not optimized to run applications.

edit: I did not expect that the ā€œmodern webā€ crowd would now come here to berate (and downvote) me for the sacrilege of not unconditionally considering web browsers to be the very best piece of software for every purpose. My fault, sorry. Iā€™m out of here, this is pointless.

permalink
report
reply
0 points

Is this true for PWAs for mobile too? Iā€™m a security noob, but Iā€™ve noticed the (few) PWAs I use on iOS seem to be using and sending a lot less telemetry stuff compared to their app counterparts. They seem faster too.

permalink
report
parent
reply
0 points

ā€œPWAsā€ are still less efficient than native apps. There are many disadvantages - and one advantage (ā€œitā€™s easy to make oneā€).

permalink
report
parent
reply
0 points

Tell that to Google with Google Docs, Microsoft with Office365, etc. The web applications are starting to become a thing in a big way.

permalink
report
parent
reply
0 points

When exactly has ā€œlarge companies do thatā€ become a good reason instead of a warning?

permalink
report
parent
reply
0 points

I agree. Every company Iā€™ve worked for recently has been migrating to web based applications, which has DEFINITELY been fun.

permalink
report
parent
reply
0 points

I donā€™t think that ā€œfunā€ should be the only relevant aspect, especially not with network-facing applications managing personal data.

permalink
report
parent
reply
0 points

Nowadays web browser are so much more then that, with tools like webasm, web usb, web bluetooth, gamepad API, web gpu and all that we are far away from the slow platforms with limited controls of the olā€™ days.

The list of modern API is almost endless https://developer.mozilla.org/en-US/docs/Web/API

permalink
report
parent
reply
0 points

Exposing your hardware over JavaScript sounds dangerous to me, to be honest. But well, Iā€™m sure that nothing bad could ever happen.

we are far away from the slow platforms with limited controls of the olā€™ days.

Web browsers are still much slower than your kernel.

permalink
report
parent
reply
0 points

I never said that it would be save, I purposely left that out. I am not a fan of Webapps and Games running in Web browsers myself, at all.

But it can be a valid option, for everyone not as paranoid as me

permalink
report
parent
reply
0 points

Web browsers are a notoriously insecure

Compared to what?

permalink
report
parent
reply
0 points

Compared to native platforms.

permalink
report
parent
reply
0 points
*

Okay, I have to admit that thatā€™s leaving me a bit nonplussed. Assume for a moment that I am concerned about the security implications of running an open-source Tomb Raider engine implementation. How exactly are you proposing running this in a more-secure fashion?

If I run an executable on my platform ā€“ say, an ELF binary on Linux ā€“ then normally that binary is going to have access to do whatever I can do. Thatā€™s a superset of what code running inside a Web browser that Iā€™m running can do.

Are you advocating for some form of isolation? If so, what?

EDIT: And Iā€™ve got another question for you. Letā€™s say that youā€™re worried about security of browser APIs. How do you avoid this? Because if your browser is vulnerable to some exploit in its WebGL implementation, not clicking on a link explicitly labeled as going to a website that uses 3D ā€“ which is what you appear to be urging people to do ā€“ isnā€™t going to avoid it. Any site you browse to ā€“ including those not labeled as such ā€“ could well expose you to that vulnerability.

EDIT2: In another comment, you say that you want to trust the ā€œkernelā€ instead of the browser. Okay, fine. There are a whole class of isolation mechanisms there. What mechanism are you proposing using? Remember that you are needing to give access to your 3d hardware to whatever software package is involved here, and the Linux kernel, at least, doesnā€™t have a mechanism for creating virtual, restricted ā€œchildā€ graphics devices. The closest I can think of on Linux you can get at a kernel level there would be pass-through from a VM to a dedicated graphics adapter, which probably isnā€™t going to be an option for most people and I have doubts about being a carefully-hardened pathway compared to browser APIs.

permalink
report
parent
reply
0 points

Let me get this straight, you think running something in a browser with its sandboxed design, is somehow less secure than downloading executables off of GitHub?

permalink
report
parent
reply
0 points

Yes, because browser sandboxes will NEVER be as secure as kernel sandboxes.

permalink
report
parent
reply
0 points

(Run the browser in the kernel sandbox)

permalink
report
parent
reply
0 points
*

I can check and validate the code I download from GitHub before I compile and run it. And I can be sure that the binary I compiled will always be the same. All that is not true with web apps, I canā€™t check the code before running (maybe I could with JavaScript but not with WebASM) and as the code gets delivered on the fly it always could be changed either on the server or by a third person in transit (TLS is not a impenetrable barrier, not with a default trusted authentication provider list that huge in all browsers).

That alone puts browser based application in a much higher risk category.

And when it comes to binaries: I can analyse those before running if I wanted to, again something I canā€™t with dynamic delivered code in the browser.

permalink
report
parent
reply
0 points

Whatā€™s the biggest code base you have ever reviewed? Whatā€™s the most recent TLS vulnerability you have encountered, as opposed to the last vulnerability in other parts of your OS? Code being swapped by the server, maybe, but are you saying you do a code review every time you update a package or dependency of some other project? This is only less secure in some inconceivably convoluted chain of events that no practical person could enact. No sane person does what youā€™re saying. Everyone has to trust someone else with code blindly at some point.

permalink
report
parent
reply

Games

!games@sh.itjust.works

Create post

Video game news oriented community. No NanoUFO is not a bot :)

Posts.

  1. News oriented content (general reviews, previews or retrospectives allowed).
  2. Broad discussion posts (preferably not only about a specific game).
  3. No humor/memes etcā€¦
  4. No affiliate links
  5. No advertising.
  6. No clickbait, editorialized, sensational titles. State the game in question in the title. No all caps.
  7. No self promotion.
  8. No duplicate posts, newer post will be deleted unless there is more discussion in one of the posts.
  9. No politics.

Comments.

  1. No personal attacks.
  2. Obey instance rules.
  3. No low effort comments(one or two words, emoji etcā€¦)
  4. Please use spoiler tags for spoilers.

My goal is just to have a community where people can go and see what new game news is out for the day and comment on it.

Other communities:

Beehaw.org gaming

Lemmy.ml gaming

lemmy.ca pcgaming

Community stats

  • 6.3K

    Monthly active users

  • 3.7K

    Posts

  • 19K

    Comments

Community moderators