8 ms·
All the major browsers perform well enough for the great majority of users. For me the differentiator is privacy with regard to the browser vendor and websites
by hackuser 10y ago
All the major browsers perform well enough for the great majority of users. For me the differentiator is privacy with regard to the browser vendor and websites I visit, and for that I trust only Mozilla because of their mission and track record (and I use some add-ons).
I've read that Chrome is more secure, in terms of integrity when attacked, which of course can help privacy (i.e., confidentiality). I've read that it's due to Chrome's security model, but I'd be interested if someone would be willing to describe it in more detail.
- martey 10y ago"For me the differentiator is privacy with regard to the browser vendor and websites I visit, and for that I trust only Mozilla because of their mission and track record (and I use some add-ons)." Are you concerned about Firefox's previous integrations with Pocket [1] and Firefox Hello [2]? [1]: https://groups.google.com/forum/#!msg/mozilla.governance/2PYq2w8tejs/i_IindFDxxgJ https://groups.google.com/forum/#!msg/mozilla.governance/2PY... [2]: https://news.ycombinator.com/item?id=9668526 https://news.ycombinator.com/item?id=9668526
- hackuser 10y agoI don't remember the details of those issues, other than concluding that the risks were way overblown and they were easy to disable.
- mastazi 10y ago> For me the differentiator is privacy [...] for that I trust only Mozilla [...] (and I use some add-ons). What FF add-ons and/or configuration do you recommend? I use Privacy Badger, AdBlock Plus and HTTPS Everywhere. In Firefox Options, I clear cookies at the end of every session. If I had Private Mode always active, then I could use Firefox's own Tracking Protection, but I thought Privacy Badger is enough and is made by the EFF which I trust.
- incompatible 10y agoSelf-destructing cookies is nice.
- hackuser 10y agoI'm assuming you are an advanced user who can understand and manage these add-ons, and also diagnose the occasional website malfunctions that they cause. Here are some of the most useful I know about: --- * uMatrix: Use this for five minutes and I think you'll be sold on it. Essentially an application-level firewall for your web browser, which replaces several other add-ons. Controls cookies, JavaScript, plugins, frames, provides connection-level privacy blacklists, and all at a granular level, using firewall-style rules for local (to the website) & remote pairs: e.g., * * * DENY # Deny all default cnn.com googleapis.com javascript ALLOW But the most impressive part is the GUI, the "matrix", which allows you to visualize as well as create/remove rules very efficiently, with a click (though you can still write them manually if you like). Like a well-made car, it's so well-designed and executed that it's a pleasure to drive. Real firewalls should use this GUI. --- * NoScript: Does far more than block JavaScript, and provides a bunch of security that uMatrix does not: https://news.ycombinator.com/item?id=12624596 https://news.ycombinator.com/item?id=12624596 --- * Decentraleyes: A local cache of common CDNs and other resources. It protects privacy by minimizing connections to CDNs, should reduce bandwidth, and can help performance in some cases. From their documentation: - Supported Networks: Google Hosted Libraries, Microsoft Ajax CDN, CDNJS (Cloudflare), jQuery CDN (MaxCDN), jsDelivr (MaxCDN), Yandex CDN, Baidu CDN, Sina Public Resources, and UpYun Libraries. - Bundled Resources: AngularJS, Backbone.js, Dojo, Ember.js, Ext Core, jQuery, jQuery UI, Modernizr, MooTools, Prototype, Scriptaculous, SWFObject, Underscore.js, and Web Font Loader. --- * HTTPS Everywhere: For the reference of others reading this comment, it's an EFF project that uses a whitelist of websites which accept https connections and forces the browser to connect to them over the secure protocol. --- * CsFire: CSRF detection and protection. Also technically interesting. https://distrinet.cs.kuleuven.be/software/CsFire/ https://distrinet.cs.kuleuven.be/software/CsFire/
- JoshMnem 10y agoTry Self-destructing Cookies, BetterPrivacy, Decentraleyes, Google Search Link Fix, Random Agent Spoofer, and RefControl. Chrome gives far less control over privacy. (Consider the business motivations of Mozilla vs. Google.) You can also add a file called user.js to your Firefox profile folder with these settings to make it better: https://gist.github.com/j127/8627698e47612eaf9d2bf4c633bbbb46 https://gist.github.com/j127/8627698e47612eaf9d2bf4c633bbbb4... Anything in about:config can be overridden in user.js. You can use multiple Firefox profiles to launch separate browser profiles, each with different extensions. (I have an alias for that: `alias ff="firefox -P"`) Ctrl-shift-p is a fast way to enter private browsing mode, which, by default, will keep your privacy extensions enabled. (You can ctrl-shift-n in Chromium/Chrome if you need to turn off all extensions for a quick look at something.) Firefox for Android is also the only mobile browser that allows add-ons, so you can get your privacy tools and customizations there too. Also check out the Firefox developer console. Go into settings and check the boxes until it's how you want it.
- dingo_bat 10y ago>All the major browsers perform well enough for the great majority of users. I guess I'm in the minority then. Firefox is markedly slow in rendering and navigating large pages. Even searching inside the page is slow. Chrome doesn't even notice a difference. Edge is similarly indifferent to the page size, but it's buggy as hell in general. It's infuriating that after all these years Firefox is still so much behind on basic performance.
- ploxiln 10y agoWhat's infuriating to me (except that I've mellowed about it over the years) is that web pages use as much cpu and memory as they can get away with, up to the edge of un-usability. Pre-mature optimization being evil and all that. FWIW here's a huge page with colored text and links (real html stuff), and it's quite snappy in firefox: https://git.kernel.org/cgit/linux/kernel/git/stable/linux-stable.git/diff/?id=v4.7.8&id2=v4.7&context=3&ignorews=0&dt=0 https://git.kernel.org/cgit/linux/kernel/git/stable/linux-st...
- confounded 10y agoAfter moving from Firefox to Chromium about five years ago, I've gradually moved back. Initially for Self Destructing Cookies and NoScript, but the Reader View really is fantastic. I've found a locked down version of FF for reading, and Chromium for webapps works very well.
- ryuuchin 10y ago> I've read that Chrome is more secure, in terms of integrity when attacked, which of course can help privacy (i.e., confidentiality). I've read that it's due to Chrome's security model, but I'd be interested if someone would be willing to describe it in more detail. The developer documentation[1] does a pretty good job at describing the security model and the defense in depth that it provides. Edge adopts a similar sandbox model although Chrome's is probably better. Their sandbox model allows them to leverage nearly all of the OS mitigations and security features that Windows[2] (and other's) have to offer. One example of a major difference that can be enabled because of Chrome's model is the usage of Win32k.sys lockdown which is the only way which you can reduce the kernel attack surface on Windows. This is enabled for all renderer processes and may be enabled on plugin processes as well (not sure if that got enabled globally yet outside of field tests). Win32k lockdown blocks access to the entire GDI subsystem among some other things. As far as I know Chrome and possibly chromium based browsers are the only ones who currently use the win32k lockdown mitigation. [1] https://www.chromium.org/developers/design-documents/sandbox https://www.chromium.org/developers/design-documents/sandbox [2] https://www.chromium.org/developers/design-documents/sandbox#TOC-Sandbox-restrictions https://www.chromium.org/developers/design-documents/sandbox...