4 ms·
Which browser has a better security track record?
by lima 1mo ago
Which browser has a better security track record?
- Cider9986 1mo agoVanadium makes improvements on Chromium. https://grapheneos.org/features#vanadium https://grapheneos.org/features#vanadium
- esseph 1mo agoRight, but it's value-add on a derivative, not its own standalone engine.
- StilesCrisis 1mo agoMost of those are just changing flags, not really unique development. Like "disable JIT" is a Chromium flag. "Zero-init everything" is a Clang flag.
- LiamPowell 29d agoIt's not even a build flag, it's a setting that you can just go and enable in Chrome's own settings menu (chrome://settings/content/v8).
- p-e-w 1mo agoFirefox with uBlock Origin. It’s astonishing how many exploits uBO stops before they ever reach your browser engine. It’s the antivirus of the 2020s.
- Alifatisk 1mo agoI suggest Zen browser (fork of FF), it feels closer to chrome.
- ZiiS 1mo agoIn a good way?
- Alifatisk 28d agoYes, in my opinion. I know a couple of people who actually jumped from Chrome to Zen because of it. In their mind, Firefox is something from the past and rough around the edges. Zen gave new attraction to FF. I am all for any opportunity to disrupt the Chrome monopoly we currently have.
- Barbing 1mo agoI hear about Zen. Random q: It can’t trick Canva into letting you use the color picker, or otherwise enable it, can it - if someone happens to know? (What a dumb feature to be locked to the Googlesphere.)
- Alifatisk 28d agoI don’t know honestly.
- aleksandrm 1mo agoWhat does it mean "closer to chrome"?
- Alifatisk 28d agoI should have been more specific. I meant the aesthetics. Zen mimics Arc Browser with vertical tabs and a hidden sidebar to maximize screen space.
- Cider9986 1mo agoBrave would be a much better option if you want security and good adblocking.
- armadyl 1mo ago[flagged]
- yjftsjthsd-h 1mo agoI'm willing to believe that stock chrome has a better record than stock Firefox, but > and on top of it you’re recommending an extension as a security measure ... Yes? Why can a browser extension not be a security measure/improvement?
- armadyl 29d agoBecause extensions especially MV2 ones only increase attack surface.
- yjftsjthsd-h 29d agoNo, they don't only increase attack surface. In particular, uBo reduces attack surface a lot more than it increases it.
- armadyl 29d agoThe only scenario in which one could possibly argue this is if the option is using MV3 uBlock Origin Lite in basic mode, where the browser handles the content blocking just reading rules from uBoL. uBO MV2 and MV3 in any of the higher two modes objectively add more attack surface when the alternative is basic uBoL + DNS level filtering which is the most secure combination second to just DNS-only filtering. And ultimately ad blocking is only badness enumeration which is a poor security measure to rely on, especially when the main application (Firefox) lacks proper security measures versus Chromium. It’s like the NVIDIA owners coming up with 3,000 different cable solutions to the burning connectors when its a problem with the card itself.
- drnick1 1mo agoThe idea here is that uBlock filters the domains that may serve the malware in the first place. It basically works the same as a DNS filter.
- lima 29d agouBlock Origin won't help with this kind of targeted exploit, and Firefox has a much worse security track record.
- Batman8675309 29d agouBO stops exploits? Source?
- p-e-w 29d agoIt blocks many shady domains, which stops many exploits before they ever reach your browser.
- bawolff 28d agomalvertising is really a method of delivering exploits, but there is no reason to think its relavent to this situation. For non technical users, scam adverts are probably the biggest threat. So i agree ubo is an important security technology, but its probably irrelavent to the topic at hand.
- bawolff 1mo agoDespite what people are saying here, chrome has a really excellent track record. Nobody is perfect. Switching just because chrome got exploited one time will likely result in you switching to something worse. If you're paranoid, disable JIT.
- dwattttt 1mo agoOr disable JS altogether, and enjoy many sites working much quicker. Many others fail & need to be selectively allowed, but it's been worth it.
- doublerabbit 29d agoIf by quicker you mean blank content, I'll agree, it is worth it.
- jacquesm 29d agoIt's not about switching because chrome got exploited one time, it's about switching not to reward unethical behavior.
- bawolff 28d agowell one someone posts on an article about an exploit in chrome saying that the exploit is a reason to switch, i think its fair to say its not about "not reward[ing] unethical behaviour"