Live data from Hacker News

Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

mozilla.org

11–20 of 67 posts

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#11

I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…

Why would this make you think Firefox is less secure? They've publicly disclosed they've fixed an issue. That's what you want .

I didn't say that this specific link made me think Firefox is less secure. Advisories are great and everyone should do them.

But as someone in the security community (not browsers), I've heard Chrome is a much harder target.

Would love for someone actually aware of the browser security scene to let me know if otherwise.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#13
post #6

I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…

Do you really think Chrome is safer than Firefox?

Anecdotally, yes. Would be great to get information on the contrary.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#14

Earlier quoted context omitted.

Why would this make you think Firefox is less secure? They've publicly disclosed they've fixed an issue. That's what you want .

I didn't say that this specific link made me think Firefox is less secure. Advisories are great and everyone should do them. But as someone in the security community (not browsers), I've heard Chrome is a much harder target. Would love for someone actually aware of the browser security scene to let me know if otherwise.

They have a larger and better funded security team, but Chrome is also a large target and gets exploited all the time as a result.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#15

I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…

To me, not having an integrated translator in android Firefox is a deal-breaker

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#16
post #15

I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…

To me, not having an integrated translator in android Firefox is a deal-breaker

Oh yeah, this was a huge annoyance when I was in another country.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#17

I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…

I agree with you entirely. My third reason to stick with Firefox is to vote with my feet regarding browser engine diversity.

This keeps getting repeated and I still haven't heard a convincing argument on why that's a good thing. Chromium/Blink is opensource, has two megacorp contributors (Microsoft and Google) - it's a far cry from MS IE monopoly. Plus Apple has WebKit.

Firefox just adds incompatibility to the mix of things you have to support, frankly I'd switch to Firefox if they decided to build it on top of Chromium.

When they were actively working on Servo and had devtools team I could see the potential, but after they sacked those - what's the point ? Market share is shrinking so compatibility is going to get worse, devtools are worse, performance/stability is worse in my experience.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#18

Earlier quoted context omitted.

I agree with you entirely. My third reason to stick with Firefox is to vote with my feet regarding browser engine diversity.

This keeps getting repeated and I still haven't heard a convincing argument on why that's a good thing. Chromium/Blink is opensource, has two megacorp contributors (Microsoft and Google) - it's a far cry from MS IE monopoly. Plus Apple has WebKit. Firefox just adds incompatibility to the mix of things you have to support, frankly I'd switch to Firefox if they decided to build it on top of Chromium. When they were act…

When Google wants a feature implemented in Chromium, it gets implemented, pretty much regardless of how buggy it is. When I want a feature implemented and Google wants it not implemented… tough luck.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#19

Earlier quoted context omitted.

This keeps getting repeated and I still haven't heard a convincing argument on why that's a good thing. Chromium/Blink is opensource, has two megacorp contributors (Microsoft and Google) - it's a far cry from MS IE monopoly. Plus Apple has WebKit. Firefox just adds incompatibility to the mix of things you have to support, frankly I'd switch to Firefox if they decided to build it on top of Chromium. When they were act…

When Google wants a feature implemented in Chromium, it gets implemented, pretty much regardless of how buggy it is. When I want a feature implemented and Google wants it not implemented… tough luck.

Is that different with Firefox? I haven't been paying attention in a while now but I constantly read complaints about UI changes - and Firefox has it's share of experimental features that ended up being exploited or abuse (asm.js comes to mind).

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#20
post #8

I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…

I'm not sure there's that much difference in browser security. There were tiny nits where Chrome was somewhat stricter that I was aware of (e.g. handling of nosniff header), but most of that has been fixed at some point. Mozilla was somewhat slower with some security improvements like site isolation, but eventually catched up. Memory safety is a general problem, but all browsers have it. "We urgently fixed this use a…

This is slightly outdated now, but here's the GrapheneOS explanation for why they don't recommend Firefox, and why they bundle Chromium-based forks instead.

https://grapheneos.org/usage#web-browsing

It's basically universally agreed among security people that Firefox is less secure than Chrome. It's up to you to decide is it's likely Mozilla's caught up in the (year?) since this was written,. Or if they'll ever be able to catch up, with their current funding, compensation packages, the size of their workforce (750 employees?), their hiring attractiveness to top security researchers, and their management priorities.

Post reply on HN