3 ms·
Can you cite one real-world example of someone who's been infected using Firefox in newer times? The link you're referencing talks about NT kernel syscalls - i
by p1peridine 5y ago
Can you cite one real-world example of someone who's been infected using Firefox in newer times?
The link you're referencing talks about NT kernel syscalls - if the computer is already infected it doesn't matter what browser is being used.
If one is a high-value target for a nation state or something of that caliber I would agree with you - but that doesn't apply to regular users. Atleast to my knowledge.
Another counter-argument here is that people looking for vulnerabilities would much rather spend their time looking for chrome exploits than firefox exploits (because of market share), no?
- concinds 5y ago> Can you cite one real-world example of someone who's been infected using Firefox in newer times? Coinbase was, and that wasn't long ago. If I were a sysadmin I'd blacklist Firefox from all my machines, no matter how I feel about the open web, about Mozilla or their mission statement, it's not a reasonable risk to take. > Another counter-argument here is that people looking for vulnerabilities would much rather spend their time looking for chrome exploits than firefox exploits (because of market share), no? People look for both. Firefox is a much higher value target to governments than Chrome, because that's what Tor Browser is. Tor is Firefox ESR, which only has big security fixes backported; other security flaws remain in Firefox ESR for much longer. But beyond that, the security fundamentals were never a part of the original Firefox project like they were for Chrome, and it still isn't. 13 years later, Chrome's still making faster progress with exploit mitigation than Firefox, and Firefox is the one that needed catching up. There's a reason why GrapheneOS, which people here trust, don't use Firefox. Check their website for a great readup[0]. On Zerodium, Chrome RCE+LPE goes for $500k, Firefox and Safari. People will argue that's marketshare, but get any exploit mitigation researcher in here and they'll tell you Firefox (and Safari) are fundamentally less secure than Chrome. Price isn't just determined by demand (by governments), it's supply too. I understand the "cyberpunk" love for Firefox, they're the good guys fighting big G. But that doesn't change what their codebase is. [0]: https://grapheneos.org/usage#web-browsing https://grapheneos.org/usage#web-browsing
- johncolanduoni 5y agoOnce an exploit allows running arbitrary code in a sandboxed browser process, NT kernel syscalls become relevant even if your computer isn’t otherwise infected. See project zero for a rundown of NT kernel vulnerabilities actually exploited from sandboxed processes (Firefox uses the same sandbox as Chrome on Windows): https://googleprojectzero.blogspot.com/2021/01/in-wild-series-windows-exploits.html https://googleprojectzero.blogspot.com/2021/01/in-wild-serie... .