Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mccr8
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
mccr8
1y ago
In my personal opinion, while the flexibility of the old XUL addons was amazing, the two big issues are compatibility and performance. Compatibility: these addons could be broken very easily because they could depend on almost anything, and
32.
▲
by
mccr8
1y ago
The article says: "OpenAI's browser is built atop Chromium, Google's own open-source browser code, two of the sources said."
33.
▲
by
mccr8
2y ago
rlbox is used for more than one library: "Now, we’re bringing that technology to all supported Firefox platforms (desktop and mobile), and isolating five different modules: Graphite, Hunspell, Ogg, Expat and Woff2" https:/&#
34.
▲
by
mccr8
2y ago
Their concern is not with theoretical vulnerabilities, but actual ones that are being exploited. If an attacker never tries to find a vulnerability in some code, then it might as well not have it.
35.
▲
by
mccr8
2y ago
Firefox uses unified builds, where a bunch of .cpp files are globbed together and compiled at once. That helps a lot, but a build still takes a bit of time unless you are on an absurdly fast machine. Chrome used to also support this, called
36.
▲
by
mccr8
2y ago
That's the CTO, not the CEO.
37.
▲
by
mccr8
2y ago
According to news stories, Apple received $20 billion dollars in 2022 from Google to make Google the default search in Safari. https://www.theverge.com/2024/5/2/24147007/google-paid-apple...
38.
▲
by
mccr8
2y ago
Firefox also uses reference counting plus a trial deletion based cycle collector to manage C++ DOM objects (and cycles through JS). In fact, Graydon was responsible for the initial implementation.
39.
▲
by
mccr8
3y ago
I got 35.7 ± 2.3 on a MacBook Pro M3, Chrome 122.
40.
▲
by
mccr8
3y ago
That commit says it is for 1515930. The Chrome releases page says that CVE-2024-0519 is associated with 1517354, which is what I linked to. There may be a connection between CVE-2024-0519 and CVE-2024-0517, but none is mentioned on the Chro
41.
▲
by
mccr8
3y ago
If you are running untrusted code in Node, subtle JIT bugs are probably the least of your problems.
42.
▲
by
mccr8
3y ago
There's not a lot of context in this submission, but presumably it is being linked because the release notes for this CVE says "Google is aware of reports that an exploit for CVE-2024-0519 exists in the wild." https:/&#
43.
▲
by
mccr8
3y ago
Here's the diff: https://chromium.googlesource.com/v8/v8/+/389ea9be7d68bb189e...
44.
▲
by
mccr8
3y ago
There's no need to speculate, as the article literally says that: "Industry groups agree: Sounds Profitable, a podcast monetization trade group, lobbied Apple to make the change, and said that it would lead to more accurate audien
45.
▲
by
mccr8
3y ago
Battery status was disabled in Firefox in 2016. https://www.theguardian.com/technology/2016/nov/01/firefox-d...
46.
▲
by
mccr8
3y ago
There have long been working Spectre attacks. From skimming the paper a bit, I think the contribution of this work is that they have come up with an attack that works on Apple's processors, as well as bypasses for a number of mitigatio
47.
▲
by
mccr8
3y ago
The paper does imply that, but I would disagree that it is more hardened. I would guess that this strict process per tab model is Safari's attempt to get some degree of isolation despite not having true site isolation. > Given that
48.
▲
by
mccr8
3y ago
Chromium and Firefox have implemented site isolation on their desktop browsers, so pages that are not same site should never be loaded in the same process. On mobile browsers, Chromium's site isolation is limited, and Firefox has not f
49.
▲
by
mccr8
3y ago
FWIW, I filed a bug a few days ago for the issue I was seeing. A profile showed that Firefox was spending all of its time evaluating a regex. Which is weird because Chrome uses the same regex engine. https://bugzilla.mozilla.org&
50.
▲
by
mccr8
3y ago
The linked graph is for Firefox Nightly (currently 117) running on Windows.
51.
▲
by
mccr8
4y ago
Are the versions of WebKit that ship on those consoles patched regularly and kept up to date? Probably not, so I don't think it is too relevant to how secure Safari is. There have been plenty of zero days for Chrome, but that doesn
52.
▲
by
mccr8
4y ago
Comparing CVE counts is a bit nonsensical. For instance, Chrome and Firefox don't individually assign CVEs for internally reported vulnerabilities. For instance, in these patch notes Chrome lists "Various fixes from internal audit
53.
▲
by
mccr8
5y ago
It was broken for a couple of hours, and late at night in the Americas. You might have been asleep for the entire duration of the outage.
54.
▲
by
mccr8
5y ago
The ocean's real big.
55.
▲
by
mccr8
5y ago
The quote the article is based around is discussing a new web API in the context of deciding what Mozilla thinks about it. If Mozilla isn't going to have any opinions on new web APIs, then what is even the point of Firefox? (Disclaimer
56.
▲
by
mccr8
5y ago
This is probably referring to some work to use Stencil for self-hosted code. That reduced process overhead by 6%, which is quite a bit: https://bugzilla.mozilla.org/show_bug.cgi?id=1688794 There might have been some other S
57.
▲
by
mccr8
5y ago
I think the overhead is something more like 15MB per process, on Windows. It is higher on other OSes, due in part to the way they load executables. In practice, the total overhead is less bad than you might expect, because people usually do
58.
▲
by
mccr8
5y ago
Being rude isn't going to discourage malicious actors, who are motivated by fame or wealth. If you ran a bank and had a bunch of rude bank tellers, you are only going to dissuade customers, not bank robbers.
59.
▲
by
mccr8
6y ago
Iterator invalidation was the cause of a Firefox zero day in 2016. https://bugzilla.mozilla.org/show_bug.cgi?id=1321066
60.
▲
by
mccr8
6y ago
If you go to about:memory and click on "Measure" you can get some information about what is in memory. In addition to web pages, Firefox uses child processes for things like the new tab page, extensions, talking to the GPU, and so
More ›