6 ms·
Rossmann also wholesale recommends LibreWolf as a replacement for Firefox with full calm assurance despite the maintainer(s) obviously being anonymous and unvet
by dingdingdang 2y ago
Rossmann also wholesale recommends LibreWolf as a replacement for Firefox with full calm assurance despite the maintainer(s) obviously being anonymous and unvetted and there being no organisation behind the fork to serve as a legal entity.
A prior time he did this was with GrapheneOS which ended in tears when he had epic fallout with the primary maintainer and withdrew all support because.. no surprise.. all the security of that fork is in the pocket of a single individual who may or may not, as according to Rossmann, be stable any given day of the week.
We all make mistakes and I hope he will retract if needed but the attention economy is clearly an -attention- economy, not a truthful-content economy..
- drpossum 2y agoI don't see how the anonymity of the maintainers of Librewolf are at all relevant to this discussion. You're just doing a gish gallop argument and undermining your credibility.
- OsrsNeedsf2P 2y ago> despite the maintainer(s) obviously being anonymous and unvetted and there being no organisation behind the fork to serve as a legal entity. Librewolf is judged by its track record of being open source, rapidly fixing security issues, and strict stance on user privacy. Why do people always attack these projects on "Hacker" News?
- nickthegreek 2y agoIt would be nice to have both though right? Ideally I want an active maintained fork by a group of security minded individuals that are known.
- ziddoap 2y ago>Why do people always attack these projects on "Hacker" News? It's not an attack. It's a pertinent statement of fact that some privacy-conscious people may want to consider when choosing their browser.
- drunner 2y agoAre the developers on Chrome or Safari not anonymous to you as well? Or basically every piece of software that you did not author yourself?
- ziddoap 2y agoThat's where the second half of the sentence comes into play: "organisation behind the fork to serve as a legal entity." There is a legal entity behind both Chrome & Safari.
- Xelbair 2y agoYeah, in both cases it is user hostile entity hellbent on tracking you, with strong legal defense. I think this actually makes things worse.
- ziddoap 2y ago>Yeah, in both cases it is user hostile entity hellbent on tracking you, with strong legal defense. This isn't related to the point. I'm not recommending any specific product. I'm just saying that the anonymity (or not) of the maintainer(s) can and should play a role in the decision of which browser you use. You may decide that you don't care about that, or that it's a risk you accept, and that's completely fine. But having the information to base the decision on is important.
- Xelbair 2y agoI'm just providing a counterpoint that non-anonymity of maintainer can also be a downside. with similar caveats.
- Nextgrid 2y agoThe threat model is completely different. A big company tracking you generally does so in a fully algorithmic manner, with little to no human eyes on the actual data, and any individual's unauthorized access to such data is generally considered a Big Deal™ in these companies and grounds for instant termination. Furthermore, these companies generally have good security controls that would be hard to subvert by a hostile attacker to release a malicious build or leak the collected data. Finally there's also safety in numbers - you are statistically unlikely to be the "most interesting" person using a major company's software product such as Chrome, so even if someone managed to gain full unfettered access to the collected tracking data and/or is able to push a malicious update, it's very unlikely you will be the target. A smaller project led by a lone developer or a small team of contributors lacks those various checks and balances, large security team, and the numbers of users, such that once breached you may very well be interesting enough for the attacker to actually take a personal look at.
- parl_match 2y agoLet me demonstrate the issue to you with a hypothetical situation: An anonymous open source developer of a popular tool is identified by a bad actor. This developer is offered a million dollars to install a backdoor that allows the bad actor access to any device used by consumers or that software product. Now, if that developer is anonymous to you, you have no legal recourse after the developer used their software product to launch a cyber attack on you. That is the issue. Also, not hypothetical, many such cases: https://arstechnica.com/security/2025/01/dozens-of-backdoored-chrome-extensions-discovered-on-2-6-million-devices/ https://arstechnica.com/security/2025/01/dozens-of-backdoore...
- autoexec 2y ago> Now, if that developer is anonymous to you, you have no legal recourse after the developer used their software product to launch a cyber attack on you. It looks like the source is hosted on codeberg, which a company in Germany. Presumably they would know which account was used to sign in and upload the malicious code, and that account would be tied to things like an email address and IP address which could be traced back to a person. It might not always be enough to find the person, but that's always true. Red Hat and The Debian Project being non-anonymous didn't mean they knew who backdoored the XZ Utils package.
- pseudalopex 2y ago> Presumably they would know which account was used to sign in and upload the malicious code, and that account would be tied to things like an email address and IP address which could be traced back to a person. Anonymous email services and VPNs exist.
- parl_match 2y ago"It looks like" "Presumably" "might not always be enough"
- dlahoda 2y agomay you share link to GrapheneOS? i was not able to find
- Nextgrid 2y agohttps://www.youtube.com/watch?v=4To-F6W1NT0 https://www.youtube.com/watch?v=4To-F6W1NT0
- larossmann 2y agoA lot of the criticism of librewolf is for being "woke" I differentiate between someone who holds political beliefs that I don't, or that are a little wild; and someone who holds the belief that I am trying to get them killed. Particularly when there is an easy way to figure out which phone is mine if one were so inclined. The former may not like me, but the latter ? if you believed someone was trying to kill you, what lengths would you go to? i think grapheneos & librewolf are two very different cases.