17 ms·
Mozilla patches two use-after-free vulnerabilities (ab)used in the wild
- abhaynayar 5y agoI use Firefox on Ubuntu and Android. I love Firefox more than Chromium-based browsers. But security is the one thing that makes me think of switching. Two minor things that prevent me from switching to Chromium-based browsers: 1. There is no addon functionality on Android for Chromium-based browsers. For example, I can add the uBlock addon on Firefox for Android but not Chrome for Android. 2. There is no option to place the address bar at the bottom of the screen for one-handed usage, as in Firefox Android.
- stranded22 5y ago
- deleted 5y ago[deleted]
- mvkg 5y agoI have found brave to be a decent chromium-based browser for android if the only addon needed is for ad blocking. It has a bottom toolbar provides a similar experience to the firefox bottom address bar.
- tragictrash 5y agoI 2nd this
- uneekname 5y agoI agree with you entirely. My third reason to stick with Firefox is to vote with my feet regarding browser engine diversity.
- moonchrome 5y agoThis keeps getting repeated and I still haven't heard a convincing argument on why that's a good thing. Chromium/Blink is opensource, has two megacorp contributors (Microsoft and Google) - it's a far cry from MS IE monopoly. Plus Apple has WebKit. Firefox just adds incompatibility to the mix of things you have to support, frankly I'd switch to Firefox if they decided to build it on top of Chromium. When they were actively working on Servo and had devtools team I could see the potential, but after they sacked those - what's the point ? Market share is shrinking so compatibility is going to get worse, devtools are worse, performance/stability is worse in my experience.
- wizzwizz4 5y agoWhen Google wants a feature implemented in Chromium, it gets implemented, pretty much regardless of how buggy it is. When I want a feature implemented and Google wants it not implemented… tough luck.
- moonchrome 5y agoIs that different with Firefox? I haven't been paying attention in a while now but I constantly read complaints about UI changes - and Firefox has it's share of experimental features that ended up being exploited or abuse (asm.js comes to mind).
- wizzwizz4 5y agoIt's not much different with Firefox, no. I was making a point that browser monopolies are bad; the fact we only have three real browser engines (two of which are based on Konqueror) is a problem. But at least Mozilla do a basic back-of-the-envelope “is this feature a huge security vulnerability” check before shipping. (Looking at you, <portal>.)
- blihp 5y agoOnly in the sense that when Google wants a new web standard the Firefox devs need to be convinced before it happens there. That has stopped a few, but not all, user hostile things from becoming defacto standards over the years.
- tgv 5y agoDo you really think Chrome is safer than Firefox?
- abhaynayar 5y agoAnecdotally, yes. Would be great to get information on the contrary.
- aaaaaaaaata 5y agoDepends on your threat model.
- classichasclass 5y agoWhy would this make you think Firefox is less secure? They've publicly disclosed they've fixed an issue. That's what you want.
- abhaynayar 5y agoI didn't say that this specific link made me think Firefox is less secure. Advisories are great and everyone should do them. But as someone in the security community (not browsers), I've heard Chrome is a much harder target. Would love for someone actually aware of the browser security scene to let me know if otherwise.
- saagarjha 5y agoThey have a larger and better funded security team, but Chrome is also a large target and gets exploited all the time as a result.
- hannob 5y agoI'm not sure there's that much difference in browser security. There were tiny nits where Chrome was somewhat stricter that I was aware of (e.g. handling of nosniff header), but most of that has been fixed at some point. Mozilla was somewhat slower with some security improvements like site isolation, but eventually catched up. Memory safety is a general problem, but all browsers have it. "We urgently fixed this use after free bug because we've seen exploits in the wild" is something you can read about Chrome every now and then as well. It's not good, but noone has a solution for that right now. With Rust Mozilla is at least working on getting a handle on that.
- concinds 5y agoThis is slightly outdated now, but here's the GrapheneOS explanation for why they don't recommend Firefox, and why they bundle Chromium-based forks instead. https://grapheneos.org/usage#web-browsing https://grapheneos.org/usage#web-browsing It's basically universally agreed among security people that Firefox is less secure than Chrome. It's up to you to decide is it's likely Mozilla's caught up in the (year?) since this was written,. Or if they'll ever be able to catch up, with their current funding, compensation packages, the size of their workforce (750 employees?), their hiring attractiveness to top security researchers, and their management priorities.
- upofadown 5y agoThat seems to be quite focused on the situation with Firefox on the Android/Graphene environment. >It's basically universally agreed among security people that Firefox is less secure than Chrome. A reference would be nice here...
- _rdvw 5y agoThe biggest issue is that Firefox on Android runs all websites in the same process. https://bugzilla.mozilla.org/show_bug.cgi?id=1565196 https://bugzilla.mozilla.org/show_bug.cgi?id=1565196 Another example, third party Chromium builds like Vanadium or Mulch also go further and enable CFI on Android (still default disabled upstream last I checked).
- qumpis 5y agoTo me, not having an integrated translator in android Firefox is a deal-breaker
- abhaynayar 5y agoOh yeah, this was a huge annoyance when I was in another country.
- dijonman2 5y agoMozilla laid off the bulk of their security team, there will be a natural decline in security over time.
- Georgelemental 5y agoKiwi Browser (https://kiwibrowser.com/ https://kiwibrowser.com/) is a FOSS Chromium for Android derivative that supports Chrome extensions.
- wishawa 5y agoKiwi Browser is not FOSS. They have a skeleton GitHub repo with Chromium code. Their patches aren’t published.
- Georgelemental 5y agoTheir patches do seem to be available under BSD here: https://github.com/kiwibrowser/src.next/blob/kiwi/LICENSE https://github.com/kiwibrowser/src.next/blob/kiwi/LICENSE
- Sunspark 5y agoInstall Samsung Internet Browser. It's Chromium and it will run on non-Samsung devices. You can install the AdGuard add-on in it. It will let you put the bar at the bottom too. That said, I use Firefox on my desktop.
- abhaynayar 5y agoThanks, I've just started using it and it fits all my needs.
- fulafel 5y agoIs there extension support in other Chromium based mobile browsers? If not, why not?
- peakaboo 5y agoSecurity is what you worry about as a top concern? Have you ever been personally hacked by a malicious website? I've been running Firefox since version 3, every day, searching for all kinds of stuff online daily (I work as a devops and programmer guy). Never had anything happen whatsoever. Firefox has alerted me that my email has been part of hacks of random sites however, but since I use a password manager with different passwords for each site, I don't even worry about that. Chrome doesn't even inform you about those hacks as far as I know.
- jwilk 5y agoIs there a way to disable XSLT in Firefox?
- wishawa 5y agoI’m curious why the second bug is labeled critical. WebGPU is still disabled isn’t it?
- _rdvw 5y agoMy Mull builds for Android had this update out <6 hours after. https://divestos.org/misc/ffa-dates.txt https://divestos.org/misc/ffa-dates.txt Fennec F-Droid should be updated by Wednesday or so. https://gitlab.com/fdroid/fdroiddata/-/merge_requests/10706 https://gitlab.com/fdroid/fdroiddata/-/merge_requests/10706
- melony 5y agoWhat happened to rewriting the browser engine in Rust? Isn't the language supposed to prevent this sort of bugs?
- octoberfranklin 5y agoI would like to know the same thing. And I would also like to know why you're being downvoted. Maybe somebody will reply instead of downvoting. That would be nice. The decision to kill off Servo is looking less and less smart.
- RupertHandjob 5y agoThey ditched it. Probably was too useful, so decided allocate their resources to more useless projects. Go look at the Mozilla blog. They don't give a fuck about their browser. I use Firefox, but the project is a sad train wreck.
- SilasX 5y agoAnd while we’re on the topic, even within C++, why isn’t Mozilla using better dev practices that avoid use-after-free bugs?
- throwaway29879 5y agoSo open the bugs are not viewable.
- hulitu 5y agoProactive security: patching vulnerabilities after they are (ab)used in the wild.