4 ms·
Why is Tor Browser still using FF instead of Chrome or something? A sandbox is necessary, and I'm 100% sure there are a ton of 0-days in all browsers.
by f00_ 10y ago
Why is Tor Browser still using FF instead of Chrome or something?
A sandbox is necessary, and I'm 100% sure there are a ton of 0-days in all browsers.
- kolme 10y agoChrome is not even open source. They can't use it. If you're referring to Chromium, well, what makes you think it's more secure than Firefox? Also, don't you think that the developers of the Tor browser are pretty security-aware? That they might make very well informed decisions?
- munin 10y agochromium still has a sandbox
- fapjacks 10y agoAnd mystery binary blobs have made an appearance[0] [0] https://www.reddit.com/r/linux/comments/3a0rz0/chromium_unconditionally_downloads_binary_blob/ https://www.reddit.com/r/linux/comments/3a0rz0/chromium_unco...
- lima 10y agoDistros can choose to disable that feature. Also note that the blob runs _inside_ the sandbox.
- f00_ 10y ago"developers of the Tor browser" probably not, lots of incompetent people in infosec. Tor itself has decent devs, but even they have seen leadership troubles recently, pressure from feds etc. Check the mailing-list. Reminder, this isn't a vulnerability in Tor, but an IP leak in Firefox, or at least the way it's configured in TBB. Maybe a sandbox is irrelevant to an IP leak though, idk.
- lima 10y agoChromium is a magnitude more secure than Firefox. If you find a 0day in the Firefox renderer, bam, code execution with full user permissions. A 0day in Chromium renderer code is pretty much worthless. Firefox has zero additional layers of security. Chromium has a battle-tested sandbox which kills 99% of all exploits in the absence of an additional kernel exploit. Also note how none of the recent Flash 0days was exploitable on Chrome.
- deleted 10y ago[deleted]
- retox 10y agoI for one would never trust a Google tor client.
- ikeboy 10y agohttps://www.torproject.org/docs/faq#TBBOtherBrowser https://www.torproject.org/docs/faq#TBBOtherBrowser >Our efforts to work with the Chrome team to add missing APIs were unsuccessful, unfortunately. Currently, it is impossible to use other browsers and get the same level of protections as when using the Tor Browser. https://blog.torproject.org/blog/google-chrome-incognito-mode-tor-and-fingerprinting https://blog.torproject.org/blog/google-chrome-incognito-mod...
- AckSyn 10y agoI'm not sure why anyone uses a big-name browser on tor anymore. It's trivial to lock something like wget or lynx/links into using the tor connection and getting the same kind of results.
- awqrre 10y agoYes, zero day exploits are present in all software, that is a known fact (Chrome is not an exception)... in fact, 0-days is just what is publicized... there is the exploits that are kept private which might one day become "0-day".
- white-flame 10y agoOr more importantly, why isn't there a browser written in a language impervious to low level buffer overruns, ROP, and pointer problems? Certainly there are other higher level data exposure problems that could manifest, but I'm so utterly sick of C-level security exploits that I'm ready to throw everything out with the bathwater.
- nemothekid 10y agoThat's one of the hopes of Servo: https://github.com/servo/servo https://github.com/servo/servo