Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your statement may be valid, but the two links you provided don't seem to have much to say on that topic. The first refers to a bug currently fixed in current GA Firefox, the second is a rant about Tor bundle. If reblogging snark is the standard of proof here, anyone could justify any "modern browser" as "worst".

My counterargument is that Firefox has always and continues to support tools such as NoScript and uBlock that prevent whole classes of attack. And Chrome, for example, is pwned like clockwork at every contest for exploitation. Behavior and not platform is the biggest determinant of security online.



If you're talking about Pwn2own, they've dropped Firefox from the competition __because it was too easy to exploit__ [1].

I quote:

"For the last decade, the Pwn2own hacking competition has pitted the world's best hackers against web browsers to try and find zero-day vulnerabilities in a live event. The contest, which is sponsored by HPE and TrendMicro this year, is offering over half a million dollars in prize money, but for the first time, not a penny of that will directed to Mozilla Firefox. While Microsoft Edge, Google Chrome and Apple Safari are targets, Firefox isn't because it's apparently too easy and not keeping up with modern security: "'We wanted to focus on the browsers that have made serious security improvements in the last year,' Brian Gorenc, manager of Vulnerability Research at HPE said."

How is that for a slap in the face?

Selectively reading what you like and ignoring the rest [an entire section in the second link is devoted to Firefox issues that have nothing to do with TBB, including the conclusion] won't change the basic facts. Another point those not in the security domain miss, is that there are plenty of exploitable bugs that are deliberately kept private. Those who have visibility in these circles (such as thegrugq) are obviously in a much better position to appraise how secure a software system really is. Trying to determine how secure Firefox is just from CVEs and bugs that are made public will only lead you to a piece of the entire puzzle. In Firefox case, even that alone should be enough to trigger RED ALERT in somebody's mind.

The best we can all hope for is for people to stop using Firefox and flock to alternatives that raise the bar significantly.

[1] https://it.slashdot.org/story/16/02/12/034206/pwn2own-2016-w...


And yet according to these sources[0][1], Firefox is back this year in Pwn2own. A quote from [1]:

> "Mozilla improved their security enough for us to warrant their re-inclusion in the contest," Gorenc said.

Firefox is fine. Like in every other browser, when security problems are found, they are fixed. There's a lot of work going into making Firefox a great and secure browser, and to call for abandoning it en masse is unwarranted IMO.

Edit: Heck, isn't it your own link[2] that claims that one of the security problems with Tor is their homogeny, that they all use the same browser and version? By that logic, abandoning Firefox is a bad move for overall security.

[0] https://blog.trendmicro.com/pwn2own-returns-for-2017-to-cele...

[1] http://www.eweek.com/security/pwn2own-2017-takes-aim-at-linu...

[2] https://medium.com/@thegrugq/tor-and-its-discontents-ef51648...


Look at the prize money for Firefox, lowest of them all. I think this proves my original point.

TBB is routinely attacked by nation states and other government groups. In that context, homogeneity is an important factor since they only have one target to focus on and considerable resources to use. By the way this is also another point against someone using Firefox. By choosing Firefox, you are choosing a browser that __you know__ is actively targeted by nation states and government groups, because it's used in TBB. You can safely assume said groups have multiple Firefox 0days.

My original point however is not that Firefox is insecure vs nation-grade attackers. __Every browser is__

There are plenty of criminal groups (ever increasing) and actors with limited resources that will focus on Firefox because it's easy to exploit. The fricking FBI was owning people with a Firefox 0day. The same groups would find Chrome or Edge too hard. This is of course a personal evaluation, given what I know from conversations with people in the security domain.

Let me leave you with this piece of (anecdotal) information: In my last job, we used to have new hires for exploit development pick a browser to work on for the first few months. Expectation being remote exploits, lots of them.

Most of them picked Firefox.


Firefox had no process isolation or web content sandboxing for years. It still doesn't in a lot of places even today. That meant that every little bug became a serious bug.

In contrast, RCE's for Chrome and Safari require chaining together a number of exploits - the most valuable of which is the sandbox escape.

Firefox are years behind on security - and in the meantime large number of people have abandoned it and you have an entire security community openly advocating against using or deploying it.

Yes, the security model is improving now (thanks in large part to code from Chromium) - but it's improved in the same way Adobe Flash security has improved, or Java security has improved - it will always have that huge weight of a bad reputation to carry, and it is still a far way from catching up to the norm in browsers today (check the incomplete features, bugs and open issues of e10s)

Firefox missed a huge opportunity in becoming the defacto secure and private browser - I know I don't love running Chrome/Chromium but I kinda have to


>thanks in large part to code from Chromium

This is false and misleading. The only bits Firefox plans to nick from Chromium are things like the C++ PDF reader which is a regression compared to pdf.js running in a nominally memory-safe runtime. The browser itself doesn't use code lifted from Chromium.



Something ruffled your feathers. Why do you want Firefox to be abandoned rather than improve it's security? For my and most other's mundane browsing needs Firefox _is_ secure enough. Mozilla is the only browser vendor actually innovating with Rust, Servo/Quantum and WebRender as examples, the first two give me hope that Mozilla really can tighten the ship and make a more secure browser than Chromium would be.


Nothing ruffled my feathers, I'm simply laying out facts. Feel free to ignore them.

There is no improvement for Firefox, it will never amount to anything given how rotten the codebase is. Unless they plan to scrap it and rewrite everything from scratch, with an actual focus on security from the beginning, which of course they don't. Slowly rewriting small parts of Firefox in Rust will do nothing for security, it's just more smoke and mirrors from Mozilla.

On the other hand, we have Google who were really the pioneers when it comes to securing the browser since they spent millions of dollars doing just that. Mozilla didn't even bother. Even their current attempts are laughable really in terms of scope and actual impact, it's just shitty PR aimed at people without security experience.

That's not to say that Chrome is a secure browser, but it has raised the bar significantly and it deserves wider adoption. Finally, we also have Microsoft who have probably spent even more than Google on improving security on Windows and are doing a lot of innovative security-related work with Edge [1].

[1] http://arstechnica.com/information-technology/2016/09/window...


It's not "small parts." Quantum has big ambitions. For example, Stylo, a sub-project of quantum, replaces the CSS layout code with Rust. That's a large, key component.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: