Earlier quoted context omitted.
This is slightly outdated now, but here's the GrapheneOS explanation for why they don't recommend Firefox, and why they bundle Chromium-based forks instead. https://grapheneos.org/usage#web-browsing It's basically universally agreed among security people that Firefox is less secure than Chrome. It's up to you to decide is it's likely Mozilla's caught up in the (year?) since this was written,. Or if they'll ever be ab…
Related: Mozilla fired parts of their security team (though likely not the people directly responsible for securing the browser) - https://news.ycombinator.com/item?id=24128865 Quote from one of the tweets confirming it: "They killed entire threat management team. Mozilla is now without detection and incident response."
Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
31–40 of 67 posts
Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
#32Earlier quoted context omitted.
This keeps getting repeated and I still haven't heard a convincing argument on why that's a good thing. Chromium/Blink is opensource, has two megacorp contributors (Microsoft and Google) - it's a far cry from MS IE monopoly. Plus Apple has WebKit. Firefox just adds incompatibility to the mix of things you have to support, frankly I'd switch to Firefox if they decided to build it on top of Chromium. When they were act…
How much does Microsoft actually contribute to Blink's core really ? The benefit for Microsoft of Chromium Edge is they get to outsource development. Their interest is in making it run well, and so far they've largely left the web features to Google. If Firefox became a Chromium fork they'd be just another junior partner in name only; Google would still be running the show on policy. In fact, possibly worse, because…
They also wanted to get superior compatibility. While the old edge was quite a bit better than IE, it still feel short.
Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
#33Earlier quoted context omitted.
When Google wants a feature implemented in Chromium, it gets implemented, pretty much regardless of how buggy it is. When I want a feature implemented and Google wants it not implemented… tough luck.
Is that different with Firefox? I haven't been paying attention in a while now but I constantly read complaints about UI changes - and Firefox has it's share of experimental features that ended up being exploited or abuse (asm.js comes to mind).
Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
#34Earlier quoted context omitted.
This keeps getting repeated and I still haven't heard a convincing argument on why that's a good thing. Chromium/Blink is opensource, has two megacorp contributors (Microsoft and Google) - it's a far cry from MS IE monopoly. Plus Apple has WebKit. Firefox just adds incompatibility to the mix of things you have to support, frankly I'd switch to Firefox if they decided to build it on top of Chromium. When they were act…
When Google wants a feature implemented in Chromium, it gets implemented, pretty much regardless of how buggy it is. When I want a feature implemented and Google wants it not implemented… tough luck.
Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
#35Earlier quoted context omitted.
This is slightly outdated now, but here's the GrapheneOS explanation for why they don't recommend Firefox, and why they bundle Chromium-based forks instead. https://grapheneos.org/usage#web-browsing It's basically universally agreed among security people that Firefox is less secure than Chrome. It's up to you to decide is it's likely Mozilla's caught up in the (year?) since this was written,. Or if they'll ever be ab…
Related: Mozilla fired parts of their security team (though likely not the people directly responsible for securing the browser) - https://news.ycombinator.com/item?id=24128865 Quote from one of the tweets confirming it: "They killed entire threat management team. Mozilla is now without detection and incident response."
Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
#36Earlier quoted context omitted.
I agree with you entirely. My third reason to stick with Firefox is to vote with my feet regarding browser engine diversity.
This keeps getting repeated and I still haven't heard a convincing argument on why that's a good thing. Chromium/Blink is opensource, has two megacorp contributors (Microsoft and Google) - it's a far cry from MS IE monopoly. Plus Apple has WebKit. Firefox just adds incompatibility to the mix of things you have to support, frankly I'd switch to Firefox if they decided to build it on top of Chromium. When they were act…
The value of IE to Microsoft was to lock people into Windows - both developers and users. They recognized that the web would become a software platform in its own right, and knew that if everyone ended up using web software then it'd be a lot easier to use non-Windows platforms.
Google gets much of its revenue from web advertising, so the value of Chromium to Google is to keep the web profitable for them. For example, Mozilla can't do to Google what Apple did to Facebook. They can do things like veto any move away from cookies as the primary tracking mechanism, at least until they have an alternative ready to go.
An open source license doesn't fully solve the problem because forking Chromium isn't enough. All the software on the web is built on top of APIs that Google gets a say in, and these are designed to be useful for ad/tracking networks.
Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
#37Earlier quoted context omitted.
Related: Mozilla fired parts of their security team (though likely not the people directly responsible for securing the browser) - https://news.ycombinator.com/item?id=24128865 Quote from one of the tweets confirming it: "They killed entire threat management team. Mozilla is now without detection and incident response."
The thing i’m still trying to understand is why Mozilla management is so hell bent on crippling their flagship product? RIP Servo, among other forward looking technologies.
Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
#38I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…
Do you really think Chrome is safer than Firefox?
Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
#39I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…
That said, I use Firefox on my desktop.
Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
#40Earlier quoted context omitted.
I agree with you entirely. My third reason to stick with Firefox is to vote with my feet regarding browser engine diversity.
This keeps getting repeated and I still haven't heard a convincing argument on why that's a good thing. Chromium/Blink is opensource, has two megacorp contributors (Microsoft and Google) - it's a far cry from MS IE monopoly. Plus Apple has WebKit. Firefox just adds incompatibility to the mix of things you have to support, frankly I'd switch to Firefox if they decided to build it on top of Chromium. When they were act…