And yet according to these sources[0][1], Firefox is back this year in Pwn2own. A quote from [1]:
> "Mozilla improved their security enough for us to warrant their re-inclusion in the contest," Gorenc said.
Firefox is fine. Like in every other browser, when security problems are found, they are fixed. There's a lot of work going into making Firefox a great and secure browser, and to call for abandoning it en masse is unwarranted IMO.
Edit: Heck, isn't it your own link[2] that claims that one of the security problems with Tor is their homogeny, that they all use the same browser and version? By that logic, abandoning Firefox is a bad move for overall security.
Look at the prize money for Firefox, lowest of them all.
I think this proves my original point.
TBB is routinely attacked by nation states and other government groups. In that context, homogeneity is an important factor since they only have one target to focus on and considerable resources to use. By the way this is also another point against someone using Firefox. By choosing Firefox, you are choosing a browser that __you know__ is actively targeted by nation states and government groups, because it's used in TBB. You can safely assume said groups have multiple Firefox 0days.
My original point however is not that Firefox is insecure vs nation-grade attackers. __Every browser is__
There are plenty of criminal groups (ever increasing) and actors with limited resources that will focus on Firefox because it's easy to exploit. The fricking FBI was owning people with a Firefox 0day. The same groups would find Chrome or Edge too hard. This is of course a personal evaluation, given what I know from conversations with people in the security domain.
Let me leave you with this piece of (anecdotal) information: In my last job, we used to have new hires for exploit development pick a browser to work on for the first few months. Expectation being remote exploits, lots of them.
Firefox had no process isolation or web content sandboxing for years. It still doesn't in a lot of places even today. That meant that every little bug became a serious bug.
In contrast, RCE's for Chrome and Safari require chaining together a number of exploits - the most valuable of which is the sandbox escape.
Firefox are years behind on security - and in the meantime large number of people have abandoned it and you have an entire security community openly advocating against using or deploying it.
Yes, the security model is improving now (thanks in large part to code from Chromium) - but it's improved in the same way Adobe Flash security has improved, or Java security has improved - it will always have that huge weight of a bad reputation to carry, and it is still a far way from catching up to the norm in browsers today (check the incomplete features, bugs and open issues of e10s)
Firefox missed a huge opportunity in becoming the defacto secure and private browser - I know I don't love running Chrome/Chromium but I kinda have to
This is false and misleading. The only bits Firefox plans to nick from Chromium are things like the C++ PDF reader which is a regression compared to pdf.js running in a nominally memory-safe runtime. The browser itself doesn't use code lifted from Chromium.
> "Mozilla improved their security enough for us to warrant their re-inclusion in the contest," Gorenc said.
Firefox is fine. Like in every other browser, when security problems are found, they are fixed. There's a lot of work going into making Firefox a great and secure browser, and to call for abandoning it en masse is unwarranted IMO.
Edit: Heck, isn't it your own link[2] that claims that one of the security problems with Tor is their homogeny, that they all use the same browser and version? By that logic, abandoning Firefox is a bad move for overall security.
[0] https://blog.trendmicro.com/pwn2own-returns-for-2017-to-cele...
[1] http://www.eweek.com/security/pwn2own-2017-takes-aim-at-linu...
[2] https://medium.com/@thegrugq/tor-and-its-discontents-ef51648...