5 ms·
So get Firefox back to where it was, just a browser that supported extensions. Everything beyond core browsing should be an extension or plugin. I have no use
by mhurron 10y ago
So get Firefox back to where it was, just a browser that supported extensions. Everything beyond core browsing should be an extension or plugin.
I have no use for WebRTC, so I would not install the addon/plugin. You may want it, so you would. When there was a problem with Mozilla's implementation, I wouldn't have to care, and neither would anyone else who didn't use or want it. Only those that chose to have the functionality would need to be concerned, and even then it could be updated without a full browser update.
- superkuh 10y agoIf you want that you can use the Pale Moon browser. It's a very fast, non-bloated, fork of Firefox that has significantly diverged from FF. See https://www.palemoon.org/technical.shtml https://www.palemoon.org/technical.shtml for details and in particular why they don't support WebRTC.
- problems 10y agoThe catch using something like this - while great from many perspectives is that you risk vulnerabilities just due to it not being as popular and as commonly attacked. So if your threat model includes targeted attacks, where an attacker might invest some (even a small) level of effort to find a 0-day vulnerability, I don't think I'd use it.
- superkuh 10y agoAt that point you should basically only be using the hardened tor browser based off (currently) Firefox 38. https://blog.torproject.org/blog/tor-browser-65a6-hardened-released https://blog.torproject.org/blog/tor-browser-65a6-hardened-r...
- gcp 10y agoWith Pale Moon the largest risk is that as far as I know the ESR branch they forked away from no longer gets security patches from Mozilla. So you probably don't need to do effort to find a 0-day, just browse old Mozilla CVE disclosures.
- problems 10y agoI'm sure they at least attempt to patch these, but it's often all too easy to screw up a patch and leave some part of the vulnerability still exposed. Look at what happened when Google tried to patch the stagefright vulnerability.
- superkuh 10y agoAgain with the FUD? I've witnessed the last couple big 0-day discovered by the Tor people were patched in Pale Moon before Mozilla pushed out theirs for Firefox. edit: I'd reply to your response below normally but apparently I don't get to reply to any comments on HN anymore. The reply button has disappeared. When I log out of my 5 year old/458 karma account it's back. I guess my opinion isn't wanted here. You have a good point there. I bet a least a couple of those are present. But you've also completely missed my point. When looking through the FF known vuln list the vast majority are for things like WebRTC, WebGl, and other attack surfaces that Pale Moon intentionally avoids.
- deleted 10y ago[deleted]
- gcp 10y agoThe whole point of my post, which you seem to have completely and utterly missed, was that you don't need 0-days for exploiting Pale Moon. Every single Mozilla CVE published from Firefox 38 to Firefox 50 is potential issue for it. The amount of 0-days in there is exceedingly low, but amount of CVE is very high, because Mozilla publishes CVEs for security bugs they find themselves. AFAIK Google also does this, but Microsoft doesn't. This isn't FUD. You can literally go read the list: https://www.mozilla.org/en-US/security/known-vulnerabilities/firefox/ https://www.mozilla.org/en-US/security/known-vulnerabilities... I count over 174 fixed vulnerabilities and stopped at version 48. Yes, some of these might not apply to Pale Moon because they're new vulnerabilities or it has the relevant feature disabled. You think anyone did the work to go through them all? Let alone backport the ones that are relevant? Mozilla used to do this work for Pale Moon by virtue of still backporting the most important ones (i.e. not all) to ESR38. Not any more. Good luck! the vast majority are for things like WebRTC, WebGl, and other attack surfaces that Pale Moon intentionally avoids Pale Moon supports WebGL nowadays. It's needed for a few things like Google Maps to not suck. Of course, the implementation is outdated, which is perhaps what made you think it's not there...
- dromen 10y agoIf your threat model includes targeted attacks I'd have serious doubts even about using Curl.
- gcp 10y agoSee https://www.palemoon.org/technical.shtml https://www.palemoon.org/technical.shtml for details and in particular why they don't support WebRTC. The real reason is that they are based off of an old ESR and their code wouldn't be able to inter-operate with anything else. Aside from the issue that they're not getting security patches for it, either... The recommendation to use an external PDF reader is also not quite something I can stand behind. (Unless that external reader is Chrome...)
- superkuh 10y agoSounds like your a bit behind that times. Pale Moon 27 is a rebase from FF 38 which has WebRTC. I'm not sure why we should trust your claims, already shown misinformed, when the developer's page states something else. The PM community is basically in consensus in not wanting WebRTC. As for external PDF readers I'd argue that avoiding the push for integrating or redeveloping more and more external applications into a browser is very sane.
- gcp 10y agorebase from FF 38 which has WebRTC This is a bit like saying "Firefox 4 has HTML5". The WebRTC stack in Firefox evolved significantly from Firefox 38 to 50, as did the WebRTC standards themselves. That's why I pointed to interoperability issues.
- rebelwebmaster 10y agoESR38 stopped getting upstream security updates from Mozilla in April of 2016. But I'm sure the Palemoon folks have stayed on top of things since.
- ygjb 10y agoRecommending Pale Moon to folks who care about security is foolish. There is a much bigger story and a bit of internet drama around it, but essentially, when I asked the Palemoon project lead about their security program on twitter, he blocked me. The claims that they make that they "inherit" Firefox's security properties is not valid as they introduce significant code changes.