Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Here's to hoping they maintain this for a while. There are a lot of "hardened Firefox" forks around, none of them that I would trust to follow upstream for a long enough time to switch.

I already trust Mullvad enough to use as VPN, and am likely willing to extend that trust to a fork of Firefox they manage, but truthfully, I always concerned when achieving goals means new ventures and projects as it may mean resources are moving to other areas and may impact their code product. I like my core providers to do one thing and do it well.

Edit: I hope they bring this to Android also!



> Edit: I hope they bring this to Android also!

"Avoid Gecko-based browsers like Firefox as they're currently much more vulnerable to exploitation and inherently add a huge amount of attack surface. Gecko doesn't have a WebView implementation (GeckoView is not a WebView implementation), so it has to be used alongside the Chromium-based WebView rather than instead of Chromium, which means having the remote attack surface of two separate browser engines instead of only one. Firefox / Gecko also bypass or cripple a fair bit of the upstream and GrapheneOS hardening work for apps. Worst of all, Firefox does not have internal sandboxing on Android. This is despite the fact that Chromium semantic sandbox layer on Android is implemented via the OS isolatedProcess feature, which is a very easy to use boolean property for app service processes to provide strong isolation with only the ability to communicate with the app running them via the standard service API. Even in the desktop version, Firefox's sandbox is still substantially weaker (especially on Linux) and lacks full support for isolating sites from each other rather than only containing content as a whole. The sandbox has been gradually improving on the desktop but it isn't happening for their Android browser yet."

Source: https://grapheneos.org/usage#web-browsing


Your quoted part seems to refer to people using the OS browser component in some contexts (eg app embedded web content) and the actual browser app in others. It's good to be aware of but claiming the resulting attack surface is the union is only technically correct. The resulting risk is not increased correspondingly as you are not accessing most content through 2 browsers.


This is good reminder, thank you. I am an advocate and user of GrapheneOS, but often find myself using Firefox because of Sync, and because of the bottom toolbar -- which is ridiculous to think about.

I understand the want to stay close to upstream and requests for such "usability" tweaks this should go to Chromium.

Alas the rigidity of the GrapheneOS project is a double edged sword.


> There are a lot of "hardened Firefox" forks around

Sticking with LibreWolf for now, which has updates disabled in the policies section, but I frequently ping their Gitlab for new releases. It's annoying having to do that, but if it means I get security patches in time, I do it.


re Android & fork maintenance I track this here for Firefox: https://divestos.org/misc/ffa-dates.txt

and for Chromium: https://divestos.org/misc/ch-dates.txt


Firefox runs like cold molassas on Android, unfortunately.

Bromite seems like its sticking around, fortunately.


> Bromite seems like its sticking around, fortunately.

Only barely, unfortunately.

I've since moved to Vanadium for anything untrusted and/or critical. It's still missing some features I'll enjoy seeing added, but it's improved considerably lately.


Bromite has not been updated since December 12th 2022 per my history here: https://divestos.org/misc/ch-dates.txt


Oh actually I was mistaken, looks like dev builds are still up here: https://github.com/uazo/bromite-buildtools/releases/

I do not like Brave's business model (replacing web ads with their own, even setting the crypto thing aside), but I will check out your link if Bromite fizzles out.




Oh dear, you are right. Last commit was in January.

Thorium was comatose for awhile but come back, so I am keeping my fingers crossed.


If you really want Chromium based consider switching to Brave and following my steps here: https://divestos.org/pages/browsers#tuningBrave




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: