Live data from Hacker News

Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

mozilla.org

51–60 of 67 posts

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#51

Earlier quoted context omitted.

I have been dragging my feet on leaving Firefox for security reasons for so long, and just now I have come to terms with how ridiculous that is. I’ve known about the security team, and I remember hearing that even prior to that, a CTF event had banned Firefox exploits as too easy. I am doing it next time I open my work laptop. I mean what is the single most important class of features in a browser? Security. I feel d…

I would also like to point out that I would absolutely pay $5/month via something like a Patreon which funded an organized group of security minded devs to work on Firefox security issues.

It's not a money issue. It's money allocation problem. Mozilla has plenty of money they just don't care about security that much. They care more about Pocket and other useless junk that probably nobody, but they care about.

I use Firefox, but only because of "browser diversification" and privacy. Other options are worse not because Firefox is a superior product. It's sad really.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#52
post #8

Earlier quoted context omitted.

I'm not sure there's that much difference in browser security. There were tiny nits where Chrome was somewhat stricter that I was aware of (e.g. handling of nosniff header), but most of that has been fixed at some point. Mozilla was somewhat slower with some security improvements like site isolation, but eventually catched up. Memory safety is a general problem, but all browsers have it. "We urgently fixed this use a…

This is slightly outdated now, but here's the GrapheneOS explanation for why they don't recommend Firefox, and why they bundle Chromium-based forks instead. https://grapheneos.org/usage#web-browsing It's basically universally agreed among security people that Firefox is less secure than Chrome. It's up to you to decide is it's likely Mozilla's caught up in the (year?) since this was written,. Or if they'll ever be ab…

There are more factors affecting your safety as a user: how popular a target is the app? Eg a Linux desktop is thought to be less likely to get a malware infection than a Windows desktop, even though Windows has more security investment and attention and mechanisms (antivirus, quarantined files, etc) to defend against this. The same reasons might apply: Firefox too has a smaller market share and more discerning user base, so less attractive to target at least for mass malware.

We're reduced to reasoning like this because we've in browser security apathy.

If only there was a browser that wasn't implemented by juggling chainsaws like this... It's ridiculous that we have been unable to just fire all the these apps for sane reimplementation. Feeding hostile internet content to millions of lines of unsafe code day in, day out on billions of user devices would sound like a ridiculous idea if it were invented today.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#53
post #46

What happened to rewriting the browser engine in Rust? Isn't the language supposed to prevent this sort of bugs?

They ditched it. Probably was too useful, so decided allocate their resources to more useless projects. Go look at the Mozilla blog. They don't give a fuck about their browser.

I use Firefox, but the project is a sad train wreck.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#54

I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…

Is there extension support in other Chromium based mobile browsers? If not, why not?

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#55
post #52

Earlier quoted context omitted.

This is slightly outdated now, but here's the GrapheneOS explanation for why they don't recommend Firefox, and why they bundle Chromium-based forks instead. https://grapheneos.org/usage#web-browsing It's basically universally agreed among security people that Firefox is less secure than Chrome. It's up to you to decide is it's likely Mozilla's caught up in the (year?) since this was written,. Or if they'll ever be ab…

There are more factors affecting your safety as a user: how popular a target is the app? Eg a Linux desktop is thought to be less likely to get a malware infection than a Windows desktop, even though Windows has more security investment and attention and mechanisms (antivirus, quarantined files, etc) to defend against this. The same reasons might apply: Firefox too has a smaller market share and more discerning user…

> It's ridiculous that we have been unable to just fire all the these apps for sane reimplementation

It is unfortunately nigh impossible to reimplement the web with its gigantic scope.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#56
post #55
post #52

Earlier quoted context omitted.

There are more factors affecting your safety as a user: how popular a target is the app? Eg a Linux desktop is thought to be less likely to get a malware infection than a Windows desktop, even though Windows has more security investment and attention and mechanisms (antivirus, quarantined files, etc) to defend against this. The same reasons might apply: Firefox too has a smaller market share and more discerning user…

> It's ridiculous that we have been unable to just fire all the these apps for sane reimplementation It is unfortunately nigh impossible to reimplement the web with its gigantic scope.

It's easy to get daunted at least.

A realistic scenario could be something along the lines of: get content onboard by securing some buy-in from some heavyweights, for a reduced feature set. Maybe convince a incumbent browser vendor or two to also provide a safer kernel for that content profile. Then targeting that feature set with the new implementation, and supporting a compatibility mode fallback to a legacy rendering engine for other web content. (VM-based or remote cloud based sandboxed rendering for the fallback?)

But the above would of course have a much better chance of taking off if there was a promising start of an implementation first, so it's not necessarily a reason to wait for the big boys before working on it.

(I wonder if Servo could be a starting point?)

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#57

I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…

Install Samsung Internet Browser. It's Chromium and it will run on non-Samsung devices. You can install the AdGuard add-on in it. It will let you put the bar at the bottom too. That said, I use Firefox on my desktop.

Thanks, I've just started using it and it fits all my needs.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#58

Earlier quoted context omitted.

I would also like to point out that I would absolutely pay $5/month via something like a Patreon which funded an organized group of security minded devs to work on Firefox security issues.

It's not a money issue. It's money allocation problem. Mozilla has plenty of money they just don't care about security that much. They care more about Pocket and other useless junk that probably nobody, but they care about. I use Firefox, but only because of "browser diversification" and privacy. Other options are worse not because Firefox is a superior product. It's sad really.

Yeah, I have to say that this is the only tech product that I am very emotional about at this point in my life. I want Firefox to win so bad, even now, as I’m leaving it.

But I feel like I would be doing a disservice to myself, and my employers, by continuing to use a less secure browser, just because I’m religious about Mozilla.

Re: Mozilla patches two use-after-free vulnerabilities (ab)used in the wild

#60

I use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to pl…

Security is what you worry about as a top concern? Have you ever been personally hacked by a malicious website?

I've been running Firefox since version 3, every day, searching for all kinds of stuff online daily (I work as a devops and programmer guy). Never had anything happen whatsoever.

Firefox has alerted me that my email has been part of hacks of random sites however, but since I use a password manager with different passwords for each site, I don't even worry about that. Chrome doesn't even inform you about those hacks as far as I know.

Post reply on HN