5 ms·
Wouldn't that value mostly be based off popularity? Chrome is vastly more popular than Firefox - therefore it's less valuable to exploit a smaller number of use
by problems 9y ago
Wouldn't that value mostly be based off popularity? Chrome is vastly more popular than Firefox - therefore it's less valuable to exploit a smaller number of users.
- tptacek 9y agoNo. Less popular browsers are also more expensive than Chrome, and the price difference isn't even close to linear. The fact is that Chrome exploits are much harder to write and command a higher price. Start here: https://medium.com/@justin.schuh/securing-browsers-through-isolation-versus-mitigation-15f0baced2c2 https://medium.com/@justin.schuh/securing-browsers-through-i...
- problems 9y agoThat link makes no mention of comparative exploit price, is that the correct one? It doesn't even contrast security features with Firefox... Fact is, exploit price is a crappy way to do such a comparison, there are too many other factors that can play into it - like what browsers companies and governments have deployed.
- tptacek 9y agoI'm getting really no indication that you understand the issues here. I am wrong about lots of things, and so is the industry consensus, but when comments show those things happening, they usually don't take the form of "maybe the exploits cost more because Chrome is more popular". When I say Chrome is more secure than Firefox, I am making a banal statement that most people in software security would roll their eyes at me collecting karma to say. As with the OCSP discussion downthread, I have the feeling that by starting a discussion of runtime security, allocator design, CFI, JIT-spraying, and sandboxing, I'm just going to give you more ammunition to make arguments about things you haven't read about. So, here's the deal: I've set you up beautifully to write the comment where you demonstrate that you've got some subject matter expertise in browser security and exploit development and further show that I'm making an ass out of myself by arrogantly assuming you don't know what you're talking about. I'll give you a hint: it's even easier to write that comment than you might think, because I do not myself work in browser security, so if you do even a little bit you should be able to nail this easily. I invite you to write that comment now. Otherwise: I'm done. Stick with Chrome.
- problems 9y agoSure, if you'd like to talk about sandboxing and exploit mitigation mechanism then sure, Chrome takes the cake. I have really no argument there. But that's not what you were talking about, you jumped to exploit pricing, seemed a weird choice to me. Forgive me for responding to what you posted I guess? Personally, I value privacy options and the ability to disable many potentially vulnerable features altogether over a slight possible mitigation for a zero day exploit.
- tptacek 9y agoYou just 10 minutes ago accused me of "talking out of my ass" (you later edited the comment) for saying that there were privacy wins to be had in Firefox, but they come at the expense of security. Now you write a comment that pretends that was your position all along, and implying that I somehow argued with that position. This is every asymmetrically-informed message board argument ever. Crazymaking.
- deleted 9y ago[deleted]