Live data from Hacker News

Viewing profile — csagan5

csagan5

HN member
Joined
Wed, Oct 11, 2017, 3:43 PM UTC
HN karma
130
Public activity
47 items

About csagan5

[ my public key: https://keybase.io/csagan; my proof: https://keybase.io/csagan/sigs/BJt7pxe-NFXRcQ217NRpx-1UEf0QYmkkygPCXN3E1VA ]

Recent public activity

  1. story
  2. story
  3. story
  4. comment
    Comment #25257829

    /e/ uses all of Bromite's patches as well; I asked them to mention this in the About section, since it is basically a rebranded Bromite that they are shipping.

  5. comment
    Comment #24235073

    ungoogled-chromium[1] and Bromite[2] have had a patch to disable this for a while now [1] https://github.com/Eloston/ungoogled-chromium/blob/14fb2b0/p... [2] https://github.com/bro…

  6. comment
    Comment #23287613

    Nobody can uncritically take his side but what you are implying here is that we should consider him "less" because of an unrelated story.

  7. comment
    Comment #23253297

    In Chromium it might not be blocked just because of an oversight (or because there was no consensus), see my other comment (and its parent): https://news.ycombinator.com/item?id=23…

  8. comment
    Comment #23253264

    Interestingly enough they are already blocking these attacks for background requests, see https://github.com/chromium/chromium/blob/83.0.4103.53/third... Perhaps they simply forgot…

  9. comment
    Comment #23253193

    Exactly, port scans on my public IP address are not an attack, but crossing the boundary to my localhost and private networks is malicious behavior.

  10. comment
    Comment #23253184

    There is an open Chromium bug for this: https://bugs.chromium.org/p/chromium/issues/detail?id=378566 I hope they consider it still valid and not close it. These are the blocked por…

  11. comment
    Comment #23226458

    That's a good approach; the other alternative is to use F-Droid client, but it comes with its own bugs. https://www.bromite.org/fdroid

  12. story
  13. comment
    Comment #22915976

    > About security fixes, yes, between end of 2019 and today, new problems emerged in Chromium (not specific to Kiwi though), and there is some work to backport. Should it have been …

  14. comment
    Comment #22914748

    You have not answered to the user's concern whether his browser is up to date with all the security fixes found in Chromium after v77.

  15. comment
    Comment #22914720

    I did not mention Bromite at all, what are you talking about? There is no FUD here, let me write down some facts for you: * users install Kiwi which does not contain all the securi…

  16. comment
    Comment #22912323

    Kiwi: it is severely outdated and you installed it before it was open source.

  17. comment
    Comment #22910846

    And you trust instead a closed-source browser which has not been updated in months? Aside from the trust component I suggest you to use an up-to-date browser because of the securit…

  18. comment
    Comment #22910831

    Since there is no commit history I would also like to know which Chromium version this is based on, so that a diff can be made.

  19. comment
    Comment #22910821

    It had a GitHub repo ( https://github.com/kiwibrowser/android ) described as "source code used in Kiwi", but it was just a Chromium codebase thrown there without the actual patches…

  20. comment
    Comment #22421232

    It is not and has never been, see https://github.com/kiwibrowser/android/issues/12#issuecommen...

  21. comment
    Comment #22240160

    It could be argued that a similar violation is present (since March 2019) in Chromium for the Widevine CDM provisioning request, see https://github.com/bromite/bromite/issues/471 B…

  22. comment
    Comment #22240085

    The poster is the author of Kiwi browser, which unfortunately is closed source [0], but I have reason to believe he is familiar - as I am for the Bromite project - with all the (so…

  23. comment
    Comment #22239797

    Credits to the ungoogled-chromium project [0] for the patch [1] which is also used in Bromite since 15 February 2018 to prevent this type of leaks; see also my reply here: [2] [0]:…

  24. comment
    Comment #21927709

    Edit: the article has been kindly edited, thanks to the author

  25. comment
    Comment #21922772

    > /e/ has modified the source code of various parts of AOSP and Chromium web browser to stop informing Google (and the NSA as a consequence of CLOUD Act) of user activity. The arti…