Live data from Hacker News

Ask HN: Is Firefox better than Chrome when it comes to user security?

news.ycombinator.com

61–70 of 99 posts

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#61

Earlier quoted context omitted.

This is exactly it. I used Linux on PowerPC for the same reason: Literally nobody was targeting it, especially compared to Windows on x86. Even now, why would anyone waste their time targeting desktop Linux on x86. Basically unheard of, because it's pointless (Except in targeted attacks.)

Thing is, targeting Linux on x86 will target high value users. Either servers, developers, sysadmins and the like. Yes you will hit less people, but the value of each hit is magnitude higher. It’s the same reasons apps first target iOS rather than android: apple users have an easier wallet.

> Linux on x86 will target high value users.

I'm not sure i agree with all you said.

Servers: mostly are not on x86. Also they are a lot more difficult to exploit due to the security nature of linux (yes, they go down very often and nothing is unhackable)

developers, sysadmins: tend to have the hardest configs and thus making it a lot more difficult to hack.

So, afaik, most of the hacks on this areas are more due to human flaws than the systems per se.

Now, i do agree that for a group of hackers with profound knowledge and that is trying to hit really big, servers are more attractive. devs and sysadms alone/personally not that much! ... unless ... they are targeting the servers managed by those devs and sysadms and in this case, targeting the devs and sysadms personally make more sense - which tend to be one of the best/easiest ways to hack the servers - again, exploiting human flaw instead of system flaw)

naturally, this is my personal view! I may be wrong here!

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#62
post #23

Earlier quoted context omitted.

> i actually have more faith in servo: https://servo.org Together with RedoxOS, COSMIC EPIC, and coreutils in Rust -- the future holds such great potential :)

RedoxOS, yes... I like that!!! :) But i still prefer Genode/Sculpt + seL4 ( https://genode.org ) they are doing amazing work there!!! If only they had a nice GUI (say... LXQt, for example)

Significantly more than just a nice GUI would be needed for general use, but it's certainly a fascinating proof of concept.

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#63
Looking at the pwn2own recent competition results, both Chrome and Firefox have been exploited. Overall it looks like they are more or less on the same level security-wise.

Firefox security has improved significantly in the last decade, it was pretty terrible back then. "Electrolysis" and "Quantum" certainly helped.

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#64
post #58

Let's not talk about privacy (because there is no point in talking about it: Firefox is eons more private than Chrome - or any of it's based browsers - can ever be) About security: Chrome has a biggest workforce, yes. but let's think about this a bit... First, let's not forget that chrome is also a bigger target. let's imagine this: Consider that 90% of the users worldwide use chromium-based browsers, and you are an…

> Firefox is eons more private than Chrome cough* safe browsing cough*. /s Enabled by default.

My understanding of safe browsing is that a local database is maintained and lookups happen against that. Eg: no information about the sites you're visiting is leaked.

Is this not the case / am I misunderstanding something?

Ref: https://feeding.cloud.geek.nz/posts/how-safe-browsing-works-...

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#65

Earlier quoted context omitted.

not sure why you say it's a "controversial comment"... What you say is well documented and you made a reasonable comment! The bigger the software, the more likely it is to be exploited...

> Many security layers are counterproductive Where is this part documented? I've read that security is best done as a layered approach

> Where is this part documented?

i don't have any example over this part. Maybe the OP has...

Still, a layered approach is great "on paper" (and probably the best actual solution we have atm), but it is only great in practice if it's well coded and the op is right that in lots of cases there are numerous flaws.

yes, you have failsafes on the layer bellow, but then again... it's just another "challenge" to find the flaw...

If we have a simple and effective code (à lá unix: do one thing, do it well), that has the possibility of becoming more effective that "flawed layers".

yeah... we can have multiple - simple - layers... but again... that will also raise the possibility of unforeseen flaws...

all in all: it's always a double-edged sword...

you're right and the op is right XP

(unless the layered approach is actually really really well coded!!! That's the ideal... but not many can do it!!! - i surely can't ahahah)

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#66

Let's not talk about privacy (because there is no point in talking about it: Firefox is eons more private than Chrome - or any of it's based browsers - can ever be) About security: Chrome has a biggest workforce, yes. but let's think about this a bit... First, let's not forget that chrome is also a bigger target. let's imagine this: Consider that 90% of the users worldwide use chromium-based browsers, and you are an…

This is exactly it. I used Linux on PowerPC for the same reason: Literally nobody was targeting it, especially compared to Windows on x86. Even now, why would anyone waste their time targeting desktop Linux on x86. Basically unheard of, because it's pointless (Except in targeted attacks.)

Most servers use Linux so that’s probably a more valuable target than Windows.

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#67
post #38

Let's not talk about privacy (because there is no point in talking about it: Firefox is eons more private than Chrome - or any of it's based browsers - can ever be) About security: Chrome has a biggest workforce, yes. but let's think about this a bit... First, let's not forget that chrome is also a bigger target. let's imagine this: Consider that 90% of the users worldwide use chromium-based browsers, and you are an…

> Let's not talk about privacy (because there is no point in talking about it: Firefox is eons more private than Chrome - or any of it's based browsers - can ever be) Firefox with its default settings is both less private and less secure than Brave. On iOS, Firefox has refused for years to implement an adblocker. It’s best to say nothing if you don’t know what you’re talking about.

Brave with its default settings is both less private and less secure than LibreWolf.

> On iOS, Firefox has refused for years to implement an adblocker.

Blame Apple.

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#68

Earlier quoted context omitted.

Thing is, targeting Linux on x86 will target high value users. Either servers, developers, sysadmins and the like. Yes you will hit less people, but the value of each hit is magnitude higher. It’s the same reasons apps first target iOS rather than android: apple users have an easier wallet.

> Linux on x86 will target high value users. I'm not sure i agree with all you said. Servers: mostly are not on x86. Also they are a lot more difficult to exploit due to the security nature of linux (yes, they go down very often and nothing is unhackable) developers, sysadmins: tend to have the hardest configs and thus making it a lot more difficult to hack. So, afaik, most of the hacks on this areas are more due to…

What architecture do you think servers use? Some graphs I found with a quick google ( https://www.itcandor.com/server-q219/ ) suggest >85% market share of x86, what else would they use? ARM is still not very widely used in servers, I think.

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#70
post #5
post #2

Firefox is much more private, but Chrome is more secure, although I don’t know to what extent and whether there is a difference in practice. The main consideration is chance of zero days. Anyone knows?

Another non-technical consideration is market-share. Firefox's share is low so exploiting a zero day on Chrome is much more profitable than on Firefox.

True, but I suppose this is at least partially compensated by the cost of such a 0-day. For sure, a 0-day on Chrome is a lot more expensive than one on Firefox
Post reply on HN