4 ms·
IMO, Only browsers with dedicated security teams should receive a browser entitlement (which includes a small team for soft-fork browsers) who are committed to
by mtomweb 4y ago
IMO, Only browsers with dedicated security teams should receive a browser entitlement (which includes a small team for soft-fork browsers) who are committed to keeping their browser secure.
All browsers have vulnerabilities, and it's hard to measure. Although it's easy to spot browsers that aren't patching known vulnerabilities fast enough. Negligent browsers should be warned and then have their entitlements revoked.
As for hardware protections like APRR or Pointer Authentication Codes (PAC) Apple should be forced to provide access to the third party browsers. I would steer clear of mandating exactly how the browsers should keep their users secure because that can be a point of debate and can be done both at a software layer or a hardware layer. Firefox has also introduced Site Isolation, Chromium has proven that adequately staffed security teams are able to mitigate hardware level security issues like Spectre & Meltdown with novel, system-level mitigations and these mitigations reached users before OS and hardware updates were able to fully remove the vulnerabilities.