5 ms·
You don’t consider Mozilla trustworthy so you’ll use their browser but not if it’s packaged by them? > At least when it's packaged by the distribution someone
by daenney 4y ago
You don’t consider Mozilla trustworthy so you’ll use their browser but not if it’s packaged by them?
> At least when it's packaged by the distribution someone has reviewed the changes and can flag up and disable any nonsense that mozilla is adding.
For something the size of Fx, that’s probably not happening as much as you think, unless it’s something publicly announced in changelogs. Your distribution maintainers aren’t reviewing every line of code changes between Fx releases, ESR or not.
- shrimp_emoji 4y ago>You don’t consider Mozilla trustworthy so you’ll use their browser but not if it’s packaged by them? Yea, I think this is silly. Apps have the power to update themselves out-of-band from the package manager, so, even if you only install it via the package manager, it can do whatever it wants while short-circuiting the maintainers' oversight.
- plonk 4y ago> Apps have the power to update themselves out-of-band from the package manager Isn't that disabled in Ubuntu's Firefox APT package?
- adhesive_wombat 4y agoWell, not directly: they'd need root to overwrite /usr/bin/firefox, which it wouldn't normally (hopefully) run as. They could have latent malicious code which gets packaged and that could download a payload and execute that (or already contains the attack). But a program without such a pre-existing ability won't be able to update itself to a version that does.
- IceWreck 4y agoThe do change the defaults and enable/disable features during compile time. This is very different than going through every line of code and patching something they dont like. I'm not OP, but I too consider Firefox published by my distribution (Fedora) to be more trustworthy than Mozilla's official distribution channel.
- bubblethink 4y agoI think there is some merit to it, at least as far as dubious features with auto opt-in go. It's not so much that the distro will save you from a hostile firefox or chromium. Rather, it'll give you the modicum of dignity by preventing you from being enrolled in these. In the best case, it prevents upstream from further rolling out such features due to the pushback. In the worst case, you get a small heads up about what's coming down the pipe inevitably anyway and you can plan accordingly.
- okasaki 4y ago> You don’t consider Mozilla trustworthy so you’ll use their browser but not if it’s packaged by them? I have to use a web browser. > For something the size of Fx, that’s probably not happening as much as you think, unless it’s something publicly announced in changelogs. Your distribution maintainers aren’t reviewing every line of code changes between Fx releases, ESR or not. Reading and respoding to the changelogs is substantially better than no review.
- throwaway82652 4y ago>I have to use a web browser. No you don't, I suggest getting a different career outside the IT department, if it really bothers you that much. No reason to take the path of most resistance with something that makes you unhappy. >Reading and respoding to the changelogs is substantially better than no review. No, not really. The reason this stuff with snap is happening to begin with is because distro maintainers don't have the resources to maintain a ton of patches on top of a giant browser that releases every month, even if they knew there was something objectionable in the changelog there may not be anything they can do about it in a reasonable amount of time.
- anothernewdude 4y agoNot when Mozilla will just disable things like ublock origin and umatrix, without telling the user. browsing the web is *dangerous* without them.
- vetinari 4y ago> You don’t consider Mozilla trustworthy so you’ll use their browser but not if it’s packaged by them? Exactly. The distribution maintainers are reviewers, who can remove the unwanted parts: https://pagure.io/fesco/issue/1518 https://pagure.io/fesco/issue/1518 > Your distribution maintainers aren’t reviewing every line of code changes between Fx releases, ESR or not. Actually, Redhat and SuSE guys are active in the development, especially the linux-specific functionality. However, when they package it, they don't have to follow Mozilla's agenda.
- flomo 4y agoJust posting in agreement. I'd like my Firefox direct from Mozilla, without being molested by some rando 'maintainer' who could do things like null-out SSL code or include their personal "standard violating" config (and has). As ultra-paranoid as some people on HN are, they suddenly weirdly trusting of mostly unaccountable volunteers. Backdooring some distro firefox would be a lot easier than backdooring your CPU.