4 ms·
I'm with you on everything, but atm the most secure browser is Chrome. Of course I mean "secure" as in "difficult to exploit".
by kenoph 9y ago
I'm with you on everything, but atm the most secure browser is Chrome. Of course I mean "secure" as in "difficult to exploit".
- ocdtrekkie 9y agoAlmost every Chrome install I see on laypeople's PCs contains malicious extensions (officially hosted on the Chrome Web Store!) which have permission to see and modify all page content and collect data and/or inject ads. Google may focus on specific types of exploits, but they let everyone bad just walk right in the front door.
- Houshalter 9y agoThey cracked down on this awhile ago and removed the ability to sideload extensions. Firefox is just as vulnerable to that attack. It's just a less common browser so why bother. In any case it's not the browser makers' responsibility. If you run malicious code on your computer, it can do way worse things than put toolbars on your browser.
- ocdtrekkie 9y agoIt sounds like you do not understand. This is not a problem with sideloading. This is a problem with the Chrome Web Store itself having hundreds or thousands of malicious extensions (Google refuses to either implement an approval process for extensions or police reported malicious extensions in an expedient manner), and a browser that is easily exploitable to trick people into installing them. You can hit a single accidental click on a malicious Google ad (yes, there are many), and end up with a voice telling you to click the "Install Extension" button to regain control of your browser, which alternates between a JavaScript alert popup message and the extension installation prompt to make it hard to get out of any other way (it's doable, if you're not a layperson). Approving it installs an extension which can inject ads into web pages and collect data on everything you visit and anything you type into Chrome. Sure, it's removable, but most of the victims of this behavior don't even know what Chrome extensions are, much less how to remove them. This is absolutely something Google has failed to address, and it's really not accurate to refer to Chrome as "the most secure browser" while this is so rampant and unhandled.
- kenoph 9y agoThat's true. But if you want to look at it from the perspective of how laypeople use PCs, the discussion about security is totally different from a purely technical one. Assuming you know better than installing adware or installing random chrome extensions, Chrome is the most secure browser out there. Btw, regarding extensions, before Mozilla switched to WebExtensions, you could do nasty stuff like extension-reuse attacks.
- ocdtrekkie 9y agoI understand that people at Google tend to think in the "purely technical", but that's why I feel they're so poorly equipped to protect people. They fail to account for the real world, where people do dumb things. It's not okay to build a platform you intend non-technical users to use, and then blame the user for getting exploited when you do nothing to prevent it.