Live data from Hacker News

Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

mozilla.org

41–50 of 67 posts

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#41

Earlier quoted context omitted.

Related: Mozilla fired parts of their security team (though likely not the people directly responsible for securing the browser) - https://news.ycombinator.com/item?id=24128865 Quote from one of the tweets confirming it: "They killed entire threat management team. Mozilla is now without detection and incident response."

I have been dragging my feet on leaving Firefox for security reasons for so long, and just now I have come to terms with how ridiculous that is. I’ve known about the security team, and I remember hearing that even prior to that, a CTF event had banned Firefox exploits as too easy. I am doing it next time I open my work laptop. I mean what is the single most important class of features in a browser? Security. I feel d…

Turns out I was thinking of pwn2own in 2016 [0]. Can anyone update me on how Firefox does these days at CTFs?

[0] https://it.slashdot.org/story/16/02/12/034206/pwn2own-2016-w...

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#42

I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…

Kiwi Browser ( https://kiwibrowser.com/ ) is a FOSS Chromium for Android derivative that supports Chrome extensions.

Kiwi Browser is not FOSS. They have a skeleton GitHub repo with Chromium code. Their patches aren’t published.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#45

Earlier quoted context omitted.

This is slightly outdated now, but here's the GrapheneOS explanation for why they don't recommend Firefox, and why they bundle Chromium-based forks instead. https://grapheneos.org/usage#web-browsing It's basically universally agreed among security people that Firefox is less secure than Chrome. It's up to you to decide is it's likely Mozilla's caught up in the (year?) since this was written,. Or if they'll ever be ab…

That seems to be quite focused on the situation with Firefox on the Android/Graphene environment. >It's basically universally agreed among security people that Firefox is less secure than Chrome. A reference would be nice here...

The biggest issue is that Firefox on Android runs all websites in the same process.

https://bugzilla.mozilla.org/show_bug.cgi?id=1565196

Another example, third party Chromium builds like Vanadium or Mulch also go further and enable CFI on Android (still default disabled upstream last I checked).

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#47

Earlier quoted context omitted.

Related: Mozilla fired parts of their security team (though likely not the people directly responsible for securing the browser) - https://news.ycombinator.com/item?id=24128865 Quote from one of the tweets confirming it: "They killed entire threat management team. Mozilla is now without detection and incident response."

I have been dragging my feet on leaving Firefox for security reasons for so long, and just now I have come to terms with how ridiculous that is. I’ve known about the security team, and I remember hearing that even prior to that, a CTF event had banned Firefox exploits as too easy. I am doing it next time I open my work laptop. I mean what is the single most important class of features in a browser? Security. I feel d…

I would also like to point out that I would absolutely pay $5/month via something like a Patreon which funded an organized group of security minded devs to work on Firefox security issues.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#48
post #28

Earlier quoted context omitted.

What features are you referring to?

FLoC may be one that could be characterized as “evil.” I mainly think about APIs that extend beyond the browser, like USB or Bluetooth, that Firefox won’t do for security reasons.

Those are the features I was thinking of.

FLoC seems to be pretty irrelevant to anyone not directly working on ad infrastructure, so I'm fine with Mozilla ditching that.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#49
post #46

What happened to rewriting the browser engine in Rust? Isn't the language supposed to prevent this sort of bugs?

I would like to know the same thing.

And I would also like to know why you're being downvoted.

Maybe somebody will reply instead of downvoting. That would be nice.

The decision to kill off Servo is looking less and less smart.

Post reply on HN