Live data from Hacker News

Ask HN: Is Firefox better than Chrome when it comes to user security?

news.ycombinator.com

91–99 of 99 posts

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#91
post #89

Earlier quoted context omitted.

Yes. Like, you are a laughably wrong. I can literally see the Brave “shield” icon staring right back at me right there in the bottom right of the screen.

I guess you must be in the EU and on iOS 17.4 or later. I forgot the Apple were forced to allow other browser engines to be installed in the EU recently. But aside from that recent exception, no one ever had anything except Safari on iOS, even if they thought otherwise.

Nope. Been adblocking on iOS in Brave since iOS.. 14? Maybe 13 or 15.

You should really do your research.

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#92

Earlier quoted context omitted.

It’s not really equal though is it? One’s the biggest advertising company the world has ever seen that hoovers up personal data like there’s no tomorrow, and the other is a one-time stupid mistake that they rolled back and apologised for.

One’s the biggest advertising company the world has ever seen that hoovers up personal data like there’s no tomorrow. The other one is almost completely funded by said advertising company and has shown multiple times that they will put their profits over the users' wishes including but not limited to adding ads directly to the browser. ¯\_(ツ)_/¯

It's not profit. Mozilla puts 100% of its income back into the organization. There is no profit at Mozilla, only reinvestment.

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#93
post #91

Earlier quoted context omitted.

I guess you must be in the EU and on iOS 17.4 or later. I forgot the Apple were forced to allow other browser engines to be installed in the EU recently. But aside from that recent exception, no one ever had anything except Safari on iOS, even if they thought otherwise.

Nope. Been adblocking on iOS in Brave since iOS.. 14? Maybe 13 or 15. You should really do your research.

You've been hiding ads, sure.

You haven't been blocking them, because iOS with Safari didn't allow that.

Hiding, and blocking, are not the same thing. The former is far less secure than the latter.

As for blocking ads on iOS with Brave, well, it really doesn't work that well[0]. Why? Because iOS doesn't let you block ads, unless you are in the EU and on 17.4 or later.

You should exit the RDF and really do at least a bare minimum of research.

[0] https://community.brave.com/t/is-brave-even-blocking-ads-on-...

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#94

Earlier quoted context omitted.

One’s the biggest advertising company the world has ever seen that hoovers up personal data like there’s no tomorrow. The other one is almost completely funded by said advertising company and has shown multiple times that they will put their profits over the users' wishes including but not limited to adding ads directly to the browser. ¯\_(ツ)_/¯

It's not profit. Mozilla puts 100% of its income back into the organization. There is no profit at Mozilla, only reinvestment.

The ones that do make these decisions profit from it. That the leadership keeps increasing their income to eat up Mozilla's profits instead of building up an endowment to eventually gain independence of Google is another issue and definitely not something to be proud of.

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#95
i am not a security expert but i got a counterpoint for the "workforce" argument for why chrome might have better security - firefox is better the same way macs or linux desktops are "more secure" than windows.

imo having a much smaller market share disincentivize exploiters for searching ways to attack browsers like firefox. this is the same argument used for the aforementioned os. it is very optimistic to assume that either sides are able to fix all vulnerabilities, as both have been shown to have 0-days recently.

on the other hand, just like in linux, you need to trust the developers publishing extensions as i don't find moderation quite as competent as google's (even though theirs is also very lacklusture overall).

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#96
post #91

Earlier quoted context omitted.

Nope. Been adblocking on iOS in Brave since iOS.. 14? Maybe 13 or 15. You should really do your research.

You've been hiding ads, sure. You haven't been blocking them, because iOS with Safari didn't allow that. Hiding, and blocking, are not the same thing. The former is far less secure than the latter. As for blocking ads on iOS with Brave, well, it really doesn't work that well[0]. Why? Because iOS doesn't let you block ads, unless you are in the EU and on 17.4 or later. You should exit the RDF and really do at least a…

I.. what?

You really should read links you post.

Brave even has an option where you can choose to do:

- “aggressive” blocking (will refuse to connect to ad domains)

-“standard” blocking (will connect but block, to prevent breakage)

I will stop responding now because I’ve corrected you multiple times and you refuse to listen.

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#97

Earlier quoted context omitted.

Thing is, targeting Linux on x86 will target high value users. Either servers, developers, sysadmins and the like. Yes you will hit less people, but the value of each hit is magnitude higher. It’s the same reasons apps first target iOS rather than android: apple users have an easier wallet.

> Linux on x86 will target high value users. I'm not sure i agree with all you said. Servers: mostly are not on x86. Also they are a lot more difficult to exploit due to the security nature of linux (yes, they go down very often and nothing is unhackable) developers, sysadmins: tend to have the hardest configs and thus making it a lot more difficult to hack. So, afaik, most of the hacks on this areas are more due to…

> Servers: mostly are not on x86.

Let's agree that we disagree. I'll just say that I work for a cloud provider and non-x86 servers are anecdotal :) but their media presence is not, as it's the new hot thing and that's free advertising.

> developers, sysadmins: tend to have the hardest configs and thus making it a lot more difficult to hack.

yet those people have a cognitive bias of "i'm too smart to fall". and those people will have some practices that are so detrimental to security it's laughable. how many developers will shutdown their laptop every day after work? compare this to the common practice of "just go to sleep" which will prevent browser updates, system updates, kernel updates, you name it. take a firefox that is months old with an unpatched ubuntu and you get the idea ground for a browser escape combined with an lpe. and even without lpe you'll grab many many credentials.

imho those still are harder to trick, but not because the config is hardened, but because there is a config at all. for example a phishing that imitates a floating browser window with a fake login page would not work on me. not because i'm smart, not because my config is hardened or whatnot, but because good luck to the scam for finding the specific window decorations I have on my linux system. oh, and the fact that I use a tiling wm and thus floating windows don't exist. it's a side effect of nerds being nerds.

> So, afaik, most of the hacks on this areas are more due to human flaws than the systems per se.

This is not incompatible. "normies" will get tricked in downloading invoice.pdf.exe, but that's windows only. The payout for invoice.pdf.sh or whatever may be very high, but you need your rat or stealer or whatever to know linux.

> unless ... they are targeting the servers managed by those devs and sysadms

That was the precise reason I talked about devs and sysadmins. Infrastructure credentials, aws keys, you name it.

And as a dev/sysadmin, you don't need targeted attacks to get pwned. A malicious package on npm/gems/cargo is all it takes. It's a spray and pray strategy, but if you catch even a handful of people this way it might be the jackpot.

Re: Ask HN: Is Firefox better than Chrome when it comes to user security?

#98
post #96

Earlier quoted context omitted.

You've been hiding ads, sure. You haven't been blocking them, because iOS with Safari didn't allow that. Hiding, and blocking, are not the same thing. The former is far less secure than the latter. As for blocking ads on iOS with Brave, well, it really doesn't work that well[0]. Why? Because iOS doesn't let you block ads, unless you are in the EU and on 17.4 or later. You should exit the RDF and really do at least a…

I.. what? You really should read links you post. Brave even has an option where you can choose to do: - “aggressive” blocking (will refuse to connect to ad domains) -“standard” blocking (will connect but block, to prevent breakage) I will stop responding now because I’ve corrected you multiple times and you refuse to listen.

Jesus christ lol.

You're being fooled by marketing.

Just because Brave calls it blocking, doesn't mean it is blocking.

Again, just do some god-damn research. Really, the bare minimum. It isn't news to anyone educated on this stuff that Apple has never* allowed proper ad blocking until recently in the EU.

But, believe whatever you want. I get being too scared to leave that ever so comfy RDF you found yourself in.

Well, I tried.

Post reply on HN