Live data from Hacker News

Helium Browser

helium.computer

541–550 of 561 posts

Re: Helium Browser

#541

> Helium is based on Chromium > Best privacy by default Sorry, pass... Even with un-googled Chromium I do not think these statements are self-consistent. We need browsers that do not allow Google to control the ecosystem. We need legitimate competition. So what, our choices are Firefox (Gecko), Safari (WebKit), and Ladybird? Personally I go with Firefox on most devices and Orion (WebKit) on my iPhone and iPad. > Heli…

The thing is, Gecko is really insecure when compared to Chromium. Its sandboxing is asinine. Additionally, due to lack of WebView implementation, on mobile you have to use Chromium either way, leaving you with two completely separate attack surfaces.

Quoting GrapheneOS developers[1]:

> Avoid Gecko-based browsers like Firefox as they're currently much more vulnerable to exploitation and inherently add a huge amount of attack surface. Gecko doesn't have a WebView implementation (GeckoView is not a WebView implementation), so it has to be used alongside the Chromium-based WebView rather than instead of Chromium, which means having the remote attack surface of two separate browser engines instead of only one. Firefox / Gecko also bypass or cripple a fair bit of the upstream and GrapheneOS hardening work for apps. Worst of all, Firefox does not have internal sandboxing on Android. This is despite the fact that Chromium semantic sandbox layer on Android is implemented via the OS isolatedProcess feature, which is a very easy to use boolean property for app service processes to provide strong isolation with only the ability to communicate with the app running them via the standard service API. Even in the desktop version, Firefox's sandbox is still substantially weaker (especially on Linux) and lacks full support for isolating sites from each other rather than only containing content as a whole. The sandbox has been gradually improving on the desktop but it isn't happening for their Android browser yet.

IronFox (an FF fork) developers[2]:

> While we do as much as possible to improve the situation, it should be noted that Firefox-based web browsers, including IronFox, have security deficiencies when compared to Chromium. This is especially notable on Android.

[1] https://grapheneos.org/usage#web-browsing

[2] https://gitlab.com/ironfox-oss/IronFox/-/blob/dev/docs/Limit...

An in-depth examination of this topic and a plethora of other sources can also be found here: https://madaidans-insecurities.github.io/firefox-chromium.ht...

Re: Helium Browser

#542

Can someone explain to me why most browser forks are based on Chromium? If the goal is to make a privacy focused browser which is independent of Google, isn't it then a bit counterproductive to put all your eggs in a basket which only exists due to the goodwill of your main competitor? Why not webkit or Gecko? There might be a good argument for it, but as a person concerned with privacy and the future freedom of the…

The thing is, Gecko is really insecure when compared to Chromium. Its sandboxing is asinine. Additionally, due to lack of WebView implementation, on mobile you have to use Chromium either way, leaving you with two completely separate attack surfaces.

Quoting GrapheneOS developers[1]:

> Avoid Gecko-based browsers like Firefox as they're currently much more vulnerable to exploitation and inherently add a huge amount of attack surface. Gecko doesn't have a WebView implementation (GeckoView is not a WebView implementation), so it has to be used alongside the Chromium-based WebView rather than instead of Chromium, which means having the remote attack surface of two separate browser engines instead of only one. Firefox / Gecko also bypass or cripple a fair bit of the upstream and GrapheneOS hardening work for apps. Worst of all, Firefox does not have internal sandboxing on Android. This is despite the fact that Chromium semantic sandbox layer on Android is implemented via the OS isolatedProcess feature, which is a very easy to use boolean property for app service processes to provide strong isolation with only the ability to communicate with the app running them via the standard service API. Even in the desktop version, Firefox's sandbox is still substantially weaker (especially on Linux) and lacks full support for isolating sites from each other rather than only containing content as a whole. The sandbox has been gradually improving on the desktop but it isn't happening for their Android browser yet.

IronFox (an FF fork) developers[2]:

> While we do as much as possible to improve the situation, it should be noted that Firefox-based web browsers, including IronFox, have security deficiencies when compared to Chromium. This is especially notable on Android.

[1] https://grapheneos.org/usage#web-browsing

[2] https://gitlab.com/ironfox-oss/IronFox/-/blob/dev/docs/Limit...

An in-depth examination of this topic and a plethora of other sources can also be found here: https://madaidans-insecurities.github.io/firefox-chromium.ht...

Re: Helium Browser

#543
post #135

Earlier quoted context omitted.

Security isn't just about your data. It's about the security of an open web. Having one rendering engine that controls everything is not secure.

While I agree that monopolies suck, I _absolutely hate_ having to waste my time adjusting styles and writing workaround code just to make everything look and work consistently in a multitude of browsers. This is one of the reasons — among a hundred others — that I grew to somewhat hate front-end, doubly so with the rise of mobile devices. And the more rendering engines we have, the more developers will have to fight…

Indeed front-end development in software can be painful. Much of the cruft can be attributed to computing's byzantine history of incremental experimentation. You might take some comfort in knowing that the biological analogue is vastly more complicated: the transformation of genotype to phenotype. Trying to figure out the evolutionary pressures and various mutational accidents that drove particular biological changes feels way harder than trying to figure out WTF Project X was thinking when they decided to pivot from being a social network for dog walkers to a low-latency query planner for a database no one has heard of.

Re: Helium Browser

#544
post #527

Earlier quoted context omitted.

Try zen browser its my favorite firefox fork with only a few extensions

I tried using Zen as I moved away from Arc, it really tries to be Arc but had a ton of issues at the time(6 months ago). Ranging from performance, different parts of UI crashing or behaving weirdly, to typos in English translations all over Settings. I settled on Brave for now because I won't give up uBlock Origin but I also didn't enjoy using Firefox long term for some reason. I honestly loved Arc, but I won't use p…

Brave is a good option too. I use brave for websites that are too junk to work in firefox. I have never used arc. I was coming from librewolf/floorp with sidebery. I really like the layout in zen, it hasnt shown the performance issues i sometimes saw in stock firefox and the vertical tab bar is good enough yo replace sidebery for me. Tge only annoyance ia how it sometomes weirdly display extensions in the truncated interface. Otger than that i am pretty happy.

Re: Helium Browser

#545

Earlier quoted context omitted.

Couldn't try to (together with Theo / t3) bully the Homebrew developers into a forced takeover of a package [1] if it were a conflict-free name. [1] https://github.com/Homebrew/homebrew-cask/pull/229061

The cask has not been majorly updated in almost 10 years years and is used to connect to a mobile app that hasn't been on the Play Store for almost 5 years, while easily underneath the minimum threshold of downloads for being removed. What's wrong with asking to expedite the removal process, considering the process is detailed in the guidelines?

> What's wrong with asking to expedite the removal process, considering the process is detailed in the guidelines?

Asking is one thing, the other thing is not accepting the decision of a maintainer on a topic that is at the maintainers discretion and instead taking it to social media [1] [2] for it to be brigaded.

Addendum: It additionally appears that this was filed before the browser was even launched, if the Wayback Machine and their social media posts are anything to go by.

[1] https://x.com/uwukko/status/1970161297783238905 [2] https://x.com/theo/status/1970266199469810127

Re: Helium Browser

#546
post #112

Earlier quoted context omitted.

Even in 2025 you still get the most compatibility with [insert-website-here] with Chromium

Sure but I only use Firefox (no other browser installed (except Edge on Windows)) and I don’t have any issues; so some none-trivial portion of the web doesn’t require Chrom(ium) specific behaviour.

The only websites I seem to have issues with are usually trash sites anyway. All my regular sites like banking, Google Docs, Office 365, finance, etc. work just fine in Firefox. I do find its performance not up to par with most sites that might have a very JavaScript heavy app for gaming and such.

Re: Helium Browser

#547

Earlier quoted context omitted.

Sure but I only use Firefox (no other browser installed (except Edge on Windows)) and I don’t have any issues; so some none-trivial portion of the web doesn’t require Chrom(ium) specific behaviour.

Google websites intentionally degrade performance if you browse from Firefox. Facebook Messenger's E2E only works on chromium browsers. There are many websites that show popups to use chromium for the best experience. I do get it, these aren't privacy-friendly websites, but for professional purposes, lot of people are forced to use chromium browsers or user-agent strings.

Messenger's E2E is working fine for me?

Re: Helium Browser

#548

Earlier quoted context omitted.

Last time I checked, Brave was actually the best-in-class for resisting fingerprinting.

Calling Brave "best-in-class for resisting fingerprinting" is quite bold. Especially when it's so easily disproven. Try some good fingerprint testing sites on Brave and see what comes up (those results alone should chock you). Then try the same sites on Firefox with privacy.resistFingerprinting=true. Unless some truly revolutionary initiatives have been taken at Brave since last I checked, you will see Firefox do A L…

> Try some good fingerprint testing sites on Brave

Um. Have you tried this? Because obviously based on my comment I've done this before (and I've of course included Firefox).

I just did this again and sites tell me Brave has a randomized fingerprint. Firefox's is "unique". A specific example: the EFF Cover Your Tracks website[1] said that both browsers convey 18.21 bits of identifying information.

Additionally, if you need to enable a certain setting for best performance, that browser is obviously worse for purpose, given that the vast majority of people don't change settings.

[1] https://coveryourtracks.eff.org/

Re: Helium Browser

#549

Earlier quoted context omitted.

Does the person's political opinion even matter if the product is good quality ? 20 years ago, nobody used to care.

The Brenden Eich Mozilla CEO gay marriage controversy was back in 2008, so 17 years ago. Not quite 20, but arguably we also did "used to care".

Does no one use search engines any longer? Or AI chatbots, the new front end to search engines? Anyway, 2014.

Re: Helium Browser

#550

Earlier quoted context omitted.

It's not just anyone, it's the folks at Igalia. I think people disregard Servo since it's no longer under Mozilla but Igalia aren't just random contributors picking up the slack, they're browser experts that also work on Chromium.

Won't servo thus become just a translation of chrome?

The Igalia folks also contribute to Gecko and WebKit, and so far, the three aren't clones of each other.
Post reply on HN