News: 1607190968

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Happy silver jubilee to JavaScript, king of the web at 25 and still hanging on to its crown, for now

(2020/12/05)


JavaScript turned twenty-five years old on Friday, if you count from December 4, 1995, when Netscape Communications and Sun Microsystems [1]first announced the technology.

The programming language's creator, Brendan Eich, presently CEO of browser biz Brave Software, [2]considers May 1995 to be when the project – [3]10 days in the making – was born. But when first conceived, JavaScript was called Mocha and subsequently LiveScript before the trademarked JavaScript name surfaced seven months later.

At the time, Sun co-founder and VP of research Bill Joy described JavaScript as a "the most effective method to connect HTML-based content to Java applets." But in the years that followed, improvements in JavaScript, the language's better integration into browsers, developments like Google's V8 JavaScript engine, and Java applet issues related to compatibility, security, and API versioning combined to [4]end the plug-in model .

JavaScript, properly described as an implementation of the ECMAScript specification since it became a standard in June 1997, has become the primary language for web-based applications. Over the past few years, it has consistently ranked among the most popular programming languages in the world.

[5]Douglas Crockford , a veteran JavaScript developer and author who [6]proposed the JavaScript Object Notation (JSON) specification, told The Register in an email that while Netscape may be dead and gone, JavaScript continues to rule the web.

JavaScript-based address bar spoofing vulns patched in Safari, Yandex, Opera [7]READ MORE

"JavaScript's cobbling together of functions and malleable objects was brilliant," he said. "It also has heaped on top a big load of crap, which increases each year with every revision of the ECMAScript standard."

"But the core language remains good, and has propelled JavaScript to become the world's most important programming language," he said. "The World Wide Web would have been supplanted years ago had it not been for JavaScript's ability to work about the web's limitations and defects."

In an email to The Register , Ben Vinegar, VP of engineering at web performance monitoring biz Sentry and author of JavaScript books, argued that JavaScript's ubiquity has been the key to its success.

"Today JavaScript runs on every computing device, server (and serverless) platform, and most importantly the browser," said Vinegar. "The barrier to getting started with JavaScript is as simple as starting Chrome and trying out some code on the developer console."

"And more importantly, nearly every software company today is shipping software to browsers," he said. "Facebook, Google, Microsoft – no matter how wildly different their backend infrastructure may be, regardless of whatever language they use on the backend, they are shipping complex UIs written in JavaScript to be executed in the browser."

Vinegar pointed to Microsoft Office, which a decade ago ran only as native desktop software, mostly for the Windows operating system. Office now can be invoked in the browser under the Microsoft 365 umbrella, thanks to a lot of JavaScript.

JavaScript is likely to remain popular for years to come, though it may have reached its highwater mark. Other technologies have emerged that may be better for certain tasks. One of these is [8]TypeScript , a Microsoft-backed superset of JavaScript that adds support for static typing.

Vinegar, however, is skeptical that TypeScript can supplant JavaScript.

"TypeScript confers many advantages, but it loses on ubiquity," he said. "That example of opening up my browser’s developer console and executing JavaScript: I can’t do that with TypeScript. You need to download and install the TypeScript compiler, fiddle with your application’s build scripts, compile your TypeScript files to JavaScript, then run that in the browser (or another runtime like Node.js)."

Vinegar said until there's native support for TypeScript in the browser and other runtimes, he doesn't see things changing. "It’s really, really hard to beat 'just works out of the box,'" he said.

Even so, Vinegar said he believes JavaScript's popularity may ebb over the next five years as WebAssembly matures. WebAssembly, or wasm, provides a way to convert code from various languages like C++, Go, and Rust into a binary format that can be executed by a stack-based virtual machine in the browser. As such, wasm modules can be run in conjunction with JavaScript code, allowing scenarios where JavaScript hands processor-intensive tasks off to wasm code for greater speed and efficiency.

Vinegar said browser-based apps that rely on compiled WebAssembly and not so much on JavaScript have already begun to appear. He pointed to Figma, a browser-based design-collaboration tool written in C++ and converted to wasm so it can run in the browser.

"I think JavaScript will always be there, but you could see a future where it’s 20 per cent of the code people are writing, and the remaining 80 per cent shifting to other languages that compile to Web Assembly," he said.

Even Eich, JavaScript's maker, [9]recently modified his often-vindicated dismissal of JavaScript rivals – "Always bet on JS" – to accommodate the impact of WebAssembly: "Always bet on JS (engines, where wasm runs)." ®

Get our [10]Tech Resources



[1] https://web.archive.org/web/20070916144913/http://wp.netscape.com/newsref/pr/newsrelease67.html

[2] https://twitter.com/BrendanEich/status/1334966006813319168?s=20

[3] https://js25.org/

[4] https://blogs.oracle.com/java-platform-group/moving-to-a-plugin-free-web

[5] https://www.crockford.com/

[6] https://tools.ietf.org/html/rfc4627

[7] https://www.theregister.com/2020/10/24/browser_address_spoofing/

[8] https://www.theregister.com/2020/08/20/typescript_4_0/

[9] https://twitter.com/brendaneich/status/1237173900850552832

[10] https://whitepapers.theregister.com/

karlkarl

One day browsers won't provide an embedded JavaScript interpreter or even HTML DOM. Instead they will provide a WebAssembly VM and it will be up to the developer to provide the JS / HTML language / implementation they want.

This will be great in a few ways:

1) Finally developers can choose what language they want for the frontend stack.

2) Things like Internet Explorer 6 compatibility stacks could be provided for those companies still tied to it.

I think the main question for me is: Will web browsers come by default with a basic JavaScript / HTML implementation for "compatibility with legacy websites" or with that ultimately get completely stripped out.

logicalextreme

Anybody still tied to IE6 needs to quit the "using computers in any part of the business" game.

Office 365 is worse than LibreOffice

IGnatius T Foobar !

Vinegar pointed to Microsoft Office, which a decade ago ran only as native desktop software, mostly for the Windows operating system. Office now can be invoked in the browser under the Microsoft 365 umbrella, thanks to a lot of JavaScript.

It's funny how all the people who whined about OpenOffice and LibreOffice not being "good enough" to operate in a Microsoft Office dominated world, because "document conversion is not good enough", now crow about how great Office 365 is, when the same conversion between the desktop and web versions is far worse.

Re: Office 365 is worse than LibreOffice

werdsmith

I’ve never heard a single person outside Microsoft Marketing crow about “how great Office 365 is”

Good news and bad news

Daedalus

Good news: JavaScript allows almost anybody to program for the web.

Bad news : JavaScript allows almost anybody to program for the web.

How many unmitigated disasters can be blamed on this language? How much bork results from its ubiquitous use? How many web sites are in a state where nobody quite knows how they work, or if they are error-free? Oh look, you have -32768 days left on your licence. Your address is NaN Grafton Street. etc. etc.

Not that PHP, Python etc. are any better. Let's hear it for interpreted languages. We don't need no steenking compilers!

Re: Good news and bad news

veti

You can fuck up in any language of your choice. And compilation isn't any kind of magic bullet, either. Remember "if it compiles, ship it"?

I wrote my first Javascript in 1999, which from this article makes me feel like an early adopter, although it was already pretty ubiquitous by then. It was a personality quiz that took a user's selections, did a bit of scoring, and gave a popup with their result. All good fun. But what was revolutionary about it, for me, was that I didn't need to run any code on the server, meaning I didn't have to pay extra for the hosting - everything happened in the browser.

I think we may owe it partly to Javascript that you can now download and use so many languages, compilers and IDEs for free. 25 years ago, people charged for those things.

Re: Good news and bad news

logicalextreme

[1]Wat

[1] https://www.destroyallsoftware.com/talks/wat

Ozan

JavaScript is fine language as long as you use it for what it is: a glue in web pages. I never understand why people used it for things like nodes.js

Version 1.0

Just deleted a couple of JavaScript virus deliveries from the mail server quarantine queue. Nothing odd, it's normal.

Javascript's biggest problem

Duncan Macdonald

Is the way that users are forced to run untrusted code written by unknown people to make almost any use of the Web. People have to rely on antivirus packages and browser sandboxing to protect them.

If JavaScript was server side only then it would be far less of a security problem. (The people hosting the bad code would be the ones to suffer.) As it is, unless users are computer literate enough to make proper use of tools like NoScript and AdBlockPlus, anyone using the web runs code from unknown authors with unknown security holes. (To make it worse - dynamically chosen adverts mean that a page that was perfectly OK one minute may well serve up malware the next.)

JavaScript belongs with VBScript and ActiveX as hazardous ideas.

(To get an idea of how difficult it is for a web user to tell if a page has malicious JavaScript, try using the view page source option (available in many browsers) and look at the amount and complexity of the JavaScript on Google's home page. (Over 370 lines some of which are over 1300 characters long!!! ))

In my opinion client side scripting was and remains a bad idea. Allowing dynamically chosen adverts to include their own unverified scripts turns a bad idea into a STUPIDLY BAD IDEA.

werdsmith

Absolutely love wasm and emscripten, it is the embryo of something very promising.

inoculatte:
To take coffee intravenously when you are running late.