3 ms·
I think he's actually right about the attacker being near you most of the time - compromising a data center is much harder than compromising a LAN most of the t
by problems 9y ago
I think he's actually right about the attacker being near you most of the time - compromising a data center is much harder than compromising a LAN most of the time.
However, he completely ignores the fact that some users may be sophisticated enough the handle the hard-fail scenarios mentioned. Well, I am. And so are many others. So what am I supposed to do if I want security and can handle hard-fails?
Not use Chrome seems to be the answer. Chrome fails to account for power users and developers who would rather have improved security and functionality.
- tptacek 9y agoWhat's your alternative? A customized Chromium fork? Every other browser is markedly less secure than Chrome. If exploit resilience is all you care about, you can theoretically use Edge, but now you're throwing away a lot of important TLS policy stuff that Chrome does and Microsoft is years behind on.
- problems 9y agoFirefox - they're years ahead on this sort of stuff. Their about:config gives you immense power to configure your browser to behave exactly how you want it to. Unlike any other browser around really. The flexibility this brings you in privacy gains alone is immense. Just try to do something as basic as turn off WebRTC in Chrome and you'll see what I'm talking about. Firefox is the only viable answer if you care about privacy and security and have the ability to take things into your own hands.
- tptacek 9y agoVirtually nobody who works in browser security agrees with you about that. There are privacy wins to be had with Firefox, but they come at the expense of security.
- problems 9y agoThat's a pretty big claim, one which I'm guessing you're offering absolutely no evidence to back up?
- tptacek 9y agoCompare the market prices for equivalent vulnerabilities in Chrome and Firefox.
- problems 9y agoWouldn't that value mostly be based off popularity? Chrome is vastly more popular than Firefox - therefore it's less valuable to exploit a smaller number of users.
- tptacek 9y agoNo. Less popular browsers are also more expensive than Chrome, and the price difference isn't even close to linear. The fact is that Chrome exploits are much harder to write and command a higher price. Start here: https://medium.com/@justin.schuh/securing-browsers-through-isolation-versus-mitigation-15f0baced2c2 https://medium.com/@justin.schuh/securing-browsers-through-i...
- problems 9y agoThat link makes no mention of comparative exploit price, is that the correct one? It doesn't even contrast security features with Firefox... Fact is, exploit price is a crappy way to do such a comparison, there are too many other factors that can play into it - like what browsers companies and governments have deployed.
- tptacek 9y agoI'm getting really no indication that you understand the issues here. I am wrong about lots of things, and so is the industry consensus, but when comments show those things happening, they usually don't take the form of "maybe the exploits cost more because Chrome is more popular". When I say Chrome is more secure than Firefox, I am making a banal statement that most people in software security would roll their eyes at me collecting karma to say. As with the OCSP discussion downthread, I have the feeling that by starting a discussion of runtime security, allocator design, CFI, JIT-spraying, and sandboxing, I'm just going to give you more ammunition to make arguments about things you haven't read about. So, here's the deal: I've set you up beautifully to write the comment where you demonstrate that you've got some subject matter expertise in browser security and exploit development and further show that I'm making an ass out of myself by arrogantly assuming you don't know what you're talking about. I'll give you a hint: it's even easier to write that comment than you might think, because I do not myself work in browser security, so if you do even a little bit you should be able to nail this easily. I invite you to write that comment now. Otherwise: I'm done. Stick with Chrome.