4 ms·
Excuse my ignorance but does this makes Chrome the safest browser on Windows? Or do all Chromium-based browsers benefit from this sandboxed environment and goog
by aledthemathguy 6y ago
Excuse my ignorance but does this makes Chrome the safest browser on Windows? Or do all Chromium-based browsers benefit from this sandboxed environment and google's security measures?
Thx
- snazz 6y agoAssuming the "customizers" haven't messed up the sandbox, any Chromium-based browser is well-protected. You can visit chrome://sandbox to see which features are enabled. If you're talking about the new Edge, I think that includes the same sandboxing as regular Chrome.
- amenod 6y agoNot necessarily. Firefox has its own set of protections and even introduced a new language (Rust) to deal with common security vulnerabilities without sacrifising speed. But the takeaway from this post is more that perfect safety is difficult / impossible to achieve.
- ta1771 6y agoFirefox runs multiple sites in a single process, its sandboxing doesn't come close.
- Drdrdrq 6y agoAfaik, it uses Chromium's sandboxing? That said, safety is about much more than just sandboxing.
- cmeacham98 6y agoThis hasn't been true for years (https://wiki.mozilla.org/Electrolysis https://wiki.mozilla.org/Electrolysis)
- sciurus 6y agoActually, it is still true. Electroloysis split up Firefox into multiple processes, but not every site gets its own process. Work is underway to change this and achieve full site isolation in https://wiki.mozilla.org/Project_Fission https://wiki.mozilla.org/Project_Fission. (Disclosure: I work for Mozilla, but not on this)
- ocdtrekkie 6y agoEdge would both have all the security work of Chrome (as it's a fairly close fork) but all of the security improvements that Google refuses to add, such as blocking third party tracking scripts and cookies. The latter part is where you're most likely to find malware, so a browser that refuses to act on it is not a secure browser. Firefox, Safari, Edge, and basically everyone but Chrome have implemented significant blocking on third party scripting that Google refuses to build into their browser. Bear in mind, browser security comes from many levels. A sandbox escape first requires that someone has gotten malicious code to execute in your browser. And the first line of defense is blocking a lot of extraneous and harmful code from running in the first place.
- jedimastert 6y agoCan you talk abou wha kind of malware comes from JS scripts?
- woodrowbarlow 6y agohere is a detailed look at one particular example: https://securelist.com/chrome-0-day-exploit-cve-2019-13720-used-in-operation-wizardopium/94866/ https://securelist.com/chrome-0-day-exploit-cve-2019-13720-u...
- floatingatoll 6y agoThis post does not offer evidence that could either support or contradict your question.