GrapheneOS recomienda no usar Firefox por ser POCO SEGURO

galaxxy
Tu forero favorito
#1
Yo en verdad ya no lo usaba porque da problemas en muchas webs, porque la única razón que da la gente para usarlo es que no es Chromium y que tiene mucha falta de algunas features que son imprescindibles (como los perfiles). Es eso, un navegador que vive de la lástima, que da pena y que los cuatro gatos que lo usan lo hacen por motivos no tecnológicos. Les interesa más su estúpido activismo antes siquiera que ser financieramente sostenibles (han tenido dos despidos masivos en 2024).

Después de leer esto, si usara Firefox por lástima o por un tema de querer ser anti-Google yo me lo pensaba, que ya no se trata de darle la chapa a tu primo con que usas un navegador "diferente", sino de tu propia seguridad.

Esto es de la propia página de GrapheneOS, un sistema móvil para los Pixel con especial interés en la seguridad y la privacidad.

Avoid Gecko-based browsers like Firefox as they're currently much more vulnerable to exploitation and inherently add a huge amount of attack surface. Gecko doesn't have a WebView implementation (GeckoView is not a WebView implementation), so it has to be used alongside the Chromium-based WebView rather than instead of Chromium, which means having the remote attack surface of two separate browser engines instead of only one. Firefox / Gecko also bypass or cripple a fair bit of the upstream and GrapheneOS hardening work for apps. Worst of all, Firefox does not have internal sandboxing on Android. This is despite the fact that Chromium semantic sandbox layer on Android is implemented via the OS isolatedProcess feature, which is a very easy to use boolean property for app service processes to provide strong isolation with only the ability to communicate with the app running them via the standard service API. Even in the desktop version, Firefox's sandbox is still substantially weaker (especially on Linux) and lacks full support for isolating sites from each other rather than only containing content as a whole. The sandbox has been gradually improving on the desktop but it isn't happening for their Android browser yet.
Y seguimos con otros comentarios de la propia cuenta de X de GrapheneOS.

Firefox sandbox is much weaker than Chromium on desktop Linux. The main difference is that Firefox doesn't have completed site isolation so it only defends the overall OS from compromise rather than properly defending sites and browser data from sites. They're working on it...
Seguimos con el desastre que fué moverse a Rust.

The main improvement Firefox was working on which Chromium wasn't was porting code to Rust, but Mozilla laid off most of the people doing it. Rust and Servo aren't Mozilla projects anymore. Firefox's efforts on this largely stalled and now they have a lot of redundant code.

Rust doesn't have all the basic exploit mitigations implemented so using only a bit of it creates some more weaknesses for the C++ code. Firefox doesn't deploy basic mitigations like type-based CFI anyway. Since it doesn't even use Clang CFI yet, it really says a lot about it.
Otros comentarios sobre seguridad y el desmantelamiento de Mozilla.

Similarly far less JIT hardening in Firefox. One of the major differences is that Chromium has a massive level of fuzzing, auditing, etc. compared to Firefox. Google also monitors for in the wild exploits so they get often caught to both fix the bugs and learn from the exploits.

They probably don't catch the majority of exploits used in the wild but they catch enough to regularly learn from how attackers are actually exploiting the browser and then implement defenses against the real world attacks. Mozilla gave up on doing those kinds of things.

Bear in mind Mozilla laid off tons of their security people and most people working on Rust. They got rid of a ton of not just browser security people but infrastructure security. They're more focused on trying to use stuff like AI or privacy-respecting advertising in Firefox.
Y para terminar de añadir otro problema, se suma la delicada situación financiera, que además casi todos sus ingresos dependen de Google.

If Google gets forced to stop paying money to Mozilla to be the default search engine, that could be the beginning of the end of things for Mozilla. Bear in mind nearly all their funding comes from Google and that's currently in jeopardy. Bing might pay but likely not as much.

Google is likely going to be forced to stop paying them. They're likely going to have to settle for a much lower, much less competitive bid from Microsoft. Maybe Microsoft feels like being generous to them, but they have Edge and Firefox doesn't have much usage share anymore.

Microsoft could just let Firefox die and get a lot of the market share for Edge. Windows desktop is where most of the Firefox users are and a lot would probably just go to Brave, Edge, etc. Microsoft may benefit more not giving them a new massive source of funding.

Edge has a ton of monetization in it for Microsoft, not just them being the default search engine. It also regularly asks to reset back to Bing, etc. after major updates to optimize your experience or however they spin. They get people to switch to Edge in the same way.
FerNür106
ForoCoches: Miembro
#2
Pero que dice este??
Sabio idiota
1 INT 10 SUE
#3
Ah vale.
Sidewinder
ForoCoches: Usuario
#4
Mozaic killer que prefieres mandar dinero a negros en vez de mejorar su producto.
MrEmu
ForoCoches: Usuario
#5
Que browser recomiendas?
Enredador
*AutoBan Spam/Flood/Troll*
#6
No me jodas, tete, que Firefox es el navegador de mi infancia.
-Stormrider-
ForoCoches: Miembro
#7
Donde se ponga el Netscape Navigator...
jossemartin
ForoCoches: Miembro
#8
Uso brave y Firefox en Mac y Android y sin problema en ninguno
Morya
ForoCoches: Miembro
#9
Ah, lo dice el del sistema del pixel que es de Google. Y seguro que Chrome es el mejor jajaja
Portapapeles
Copio, luego pego
#10
Este post está patrocinado por OperaGX. Es el primer navegador para GAMERS. Opera GX incluye una función llamada GX Control que te permite controlar el uso de tu CPU, RAM o red.
thys0n
ForoCoches: Miembro
#11
Yo uso edge y no me pide que cambie a bing ni nada. Creo que esa actitud tan agresiva es en Estados Unidos, aquí en la UE no se comportan igual. Es verdad que la configuración inicial (quitar todo el bloat) es un poco engorrosa, pero bueno. Es el que menor consumo de RAM me da.
ladrillos S.A
ForoCoches: Miembro
#12
Y qué usamos?
Jimi_Hendrix
Seniso
#13
Pues nada, tendré que dejar de usarlo porque lo dice ese, a cuál nos vamos?
aavvaallooss
ForoCoches: Miembro
#14
Seguiré en Firefox hasta que implosione
alfacentauro
Rollercoaster
#15
El problema es que al final todo queda supeditado a Google: ya sea porque usan un motor común (Chromium) o porque dependen de las perras de Google (Firefox, Safari).

Yo de momento me he cambiado a WebKit (Orion).
LZHMR
Audiofilo / Diogenes
#16
Yo sólo uso Librewolf y Mullvad Browser, ambos basados en Firefox.
galaxxy
Tu forero favorito
#17
Cita de Morya
Ah, lo dice el del sistema del pixel que es de Google. Y seguro que Chrome es el mejor jajaja


Creo que no tienes mucha idea de lo que es GrapheneOS.
Molly Rankin
Cuenta verificada ✔️
#18
Que dices hippie colgao
devmsv
ForoCoches: Usuario
#19
El problema es que en vanadium no puedes porner uBlock y navegar sin bloqueador de anuncios es casi impossible.

Y no, el DNS adbloquer no bloquea casi nada.
FreeYourMind
ForoCoches: Usuario
#20
soy uno de los cuatro gatos, pero prefiero eso que ser otra oveja mas usando chrome
FerminBanderin
#21
un OS para frikis que funciona especialmente en pixel (google), quiere que uses el navegador de google (pixel) o al menos no usar firefox que les come la tostada
← A General