Live data from Hacker News

Ask HN: Firefox vs. Chrome security

news.ycombinator.com

31–40 of 73 posts

Re: Ask HN: Firefox vs. Chrome security

#31

From Peter Bright at Ars: "And security remains a pressing concern, prompting the use of new techniques to protect against exploitation. Some of the rebuilt portions are even using Mozilla's new Rust programming language, which is designed to offer improved security compared to C++. While today's release represents a major step forward in the browser's performance and reliability, work on Quantum continues. One major…

One major weakness of Firefox, relative to Chrome and Edge, is its use of sandboxing and process isolation to limit the impact that security flaws can have. Next year Mozilla will be working to improve these areas.

Firefox has been shipping with a sandbox for a while, let alone e10s. Is that an old post?

Re: Ask HN: Firefox vs. Chrome security

#32

Firefox has been a low-priority target for a couple years due to its waning user-base. In fact, Firefox wasn't even at Pwn2Own 2016 because hackers didn't think it was worth their time[0]. Hopefully with Quantum and a resurge in popularity, it'll become a target of white-hat hackers again. [0] http://www.eweek.com/security/pwn2own-hacking-contest-return...

Coincidentally it not being worth their time coincided with Mozilla not sponsoring the contest any more. You can make of that what you will.

Re: Ask HN: Firefox vs. Chrome security

#33
post #29

Google has (always) gathered information about Chrome -- and Chromium -- users by default , including every keystroke typed into the "omnibox". Not easy to disable, either. This seems to be a recent Firefox policy change: all editions of Firefox is now collecting data, such as telemetry, information gathering, usage data. (URL's? Form data?) This is all opt-out instead of opt-in now, and you're asked only after insta…

brave and opera both sit on top of chromium so idk about those

Re: Ask HN: Firefox vs. Chrome security

#34

Firefox has been a low-priority target for a couple years due to its waning user-base. In fact, Firefox wasn't even at Pwn2Own 2016 because hackers didn't think it was worth their time[0]. Hopefully with Quantum and a resurge in popularity, it'll become a target of white-hat hackers again. [0] http://www.eweek.com/security/pwn2own-hacking-contest-return...

I heard a different story. Firefox was not at the contest because it was not in the same league as the others browsers (and not in a good way). See the last sentence of your link "We wanted to focus on the browsers that have made serious security improvements in the last year"

A rather arbitrary claim with nothing to back it up. For sure, Firefox made more security improvements in 2016 than it did in some of the years where they did feature it.

Re: Ask HN: Firefox vs. Chrome security

#35
post #29

Google has (always) gathered information about Chrome -- and Chromium -- users by default , including every keystroke typed into the "omnibox". Not easy to disable, either. This seems to be a recent Firefox policy change: all editions of Firefox is now collecting data, such as telemetry, information gathering, usage data. (URL's? Form data?) This is all opt-out instead of opt-in now, and you're asked only after insta…

Firefox does NOT do any this, as far as I know. What is the source of this FUD?

A public discussion was started to get to know how people felt about privacy conserving telemetry collection that would be opt out by default. There was massive negative feedback (duh). The feature did not ship in 57.

https://medium.com/georg-fritzsche/data-preference-changes-i...

"instead we always collect LESS data on Firefox release."

Re: Ask HN: Firefox vs. Chrome security

#36
post #31

From Peter Bright at Ars: "And security remains a pressing concern, prompting the use of new techniques to protect against exploitation. Some of the rebuilt portions are even using Mozilla's new Rust programming language, which is designed to offer improved security compared to C++. While today's release represents a major step forward in the browser's performance and reliability, work on Quantum continues. One major…

One major weakness of Firefox, relative to Chrome and Edge, is its use of sandboxing and process isolation to limit the impact that security flaws can have. Next year Mozilla will be working to improve these areas. Firefox has been shipping with a sandbox for a while, let alone e10s. Is that an old post?

It is not a binary choice; there are sandboxes and then there are sandboxes. For example, a VM is a stricter sandbox than a container is a stricter sandbox than a chroot is better than nothing.

Re: Ask HN: Firefox vs. Chrome security

#37
post #31

Earlier quoted context omitted.

One major weakness of Firefox, relative to Chrome and Edge, is its use of sandboxing and process isolation to limit the impact that security flaws can have. Next year Mozilla will be working to improve these areas. Firefox has been shipping with a sandbox for a while, let alone e10s. Is that an old post?

It is not a binary choice; there are sandboxes and then there are sandboxes. For example, a VM is a stricter sandbox than a container is a stricter sandbox than a chroot is better than nothing.

For sure. But he doesn't go into any details where he think the advantage would lie, which I think conflicts with calling it a "major weakness".

Re: Ask HN: Firefox vs. Chrome security

#38
post #8
post #4

Earlier quoted context omitted.

Apparently about a third of browser security vulnerabilities can be traced to memory safety issues. So, yes.

But how many of them come from the rendering engine?

For example, NoScript disables webfonts because parsing font files (which is among the jobs of the rendering engine) is done in decades-old, convoluted C code.

Re: Ask HN: Firefox vs. Chrome security

#39
post #35
post #29

Google has (always) gathered information about Chrome -- and Chromium -- users by default , including every keystroke typed into the "omnibox". Not easy to disable, either. This seems to be a recent Firefox policy change: all editions of Firefox is now collecting data, such as telemetry, information gathering, usage data. (URL's? Form data?) This is all opt-out instead of opt-in now, and you're asked only after insta…

Firefox does NOT do any this, as far as I know. What is the source of this FUD? A public discussion was started to get to know how people felt about privacy conserving telemetry collection that would be opt out by default. There was massive negative feedback (duh). The feature did not ship in 57. https://medium.com/georg-fritzsche/data-preference-changes-i... "instead we always collect LESS data on Firefox release."

> The feature did not ship in 57.

But CliqZ did ship for some German users, randomly chosen. Which tracks your entire browsing history, and sends it to a company that’s most known for its tracking products.

After this, Firefox deserves to be treated as just as much spyware as Chrome.

Re: Ask HN: Firefox vs. Chrome security

#40
post #29

Google has (always) gathered information about Chrome -- and Chromium -- users by default , including every keystroke typed into the "omnibox". Not easy to disable, either. This seems to be a recent Firefox policy change: all editions of Firefox is now collecting data, such as telemetry, information gathering, usage data. (URL's? Form data?) This is all opt-out instead of opt-in now, and you're asked only after insta…

Brave browser from Brendan Eich, Mozilla co-founder
Post reply on HN