TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Firefox vs. Chrome security

82 pointsby nsudioover 7 years ago
I&#x27;m seeing a lot of hype surrounding Mozilla&#x27;s recent release of Firefox Quantum - which promises massive improvements, mainly speed.<p>Looking past the speed aspect, where does FF stand against Chrome? Does Rust offer much better security? AFAIK Chrome is gold standard in sandboxing...does this still hold true?

12 comments

nwah1over 7 years ago
One of the exciting new features is the beginnings of a formally verified cryptography stack.<p><a href="https:&#x2F;&#x2F;blog.mozilla.org&#x2F;security&#x2F;2017&#x2F;09&#x2F;13&#x2F;verified-cryptography-firefox-57&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.mozilla.org&#x2F;security&#x2F;2017&#x2F;09&#x2F;13&#x2F;verified-crypto...</a>
mintplantover 7 years ago
&gt; AFAIK Chrome is gold standard in sandboxing...does this still hold true?<p>Firefox offers similar sandboxing; see <a href="https:&#x2F;&#x2F;wiki.mozilla.org&#x2F;Security&#x2F;Sandbox" rel="nofollow">https:&#x2F;&#x2F;wiki.mozilla.org&#x2F;Security&#x2F;Sandbox</a><p>Firefox&#x27;s JavaScript engine also implements more in-depth protections than V8, such as W^X in the JIT and compartments+wrappers to provide revokable access control and separation between code from different origins. There&#x27;s a lot more to security than ensuring code execution can&#x27;t break out of the browser.
prohorover 7 years ago
The release is also improving sandboxing for Linux:<p><a href="https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;firefox-57-brings-better-sandboxing-on-linux&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;firefox-57-br...</a><p>Sandboxing for Windows was introduced in version 54.
AdmiralAsshatover 7 years ago
Firefox has been a low-priority target for a couple years due to its waning user-base. In fact, Firefox wasn&#x27;t even at Pwn2Own 2016 because hackers didn&#x27;t think it was worth their time[0].<p>Hopefully with Quantum and a resurge in popularity, it&#x27;ll become a target of white-hat hackers again.<p>[0] <a href="http:&#x2F;&#x2F;www.eweek.com&#x2F;security&#x2F;pwn2own-hacking-contest-returns-as-joint-hpe-trend-micro-effort" rel="nofollow">http:&#x2F;&#x2F;www.eweek.com&#x2F;security&#x2F;pwn2own-hacking-contest-return...</a>
评论 #15705639 未加载
评论 #15705069 未加载
评论 #15706567 未加载
评论 #15705442 未加载
beaconfieldover 7 years ago
From Peter Bright at Ars: &quot;And security remains a pressing concern, prompting the use of new techniques to protect against exploitation. Some of the rebuilt portions are even using Mozilla&#x27;s new Rust programming language, which is designed to offer improved security compared to C++.<p>While today&#x27;s release represents a major step forward in the browser&#x27;s performance and reliability, work on Quantum continues. One major weakness of Firefox, relative to Chrome and Edge, is its use of sandboxing and process isolation to limit the impact that security flaws can have. Next year Mozilla will be working to improve these areas. Early next year should also see the rollout of a new GPU-accelerated rendering engine.&quot;
评论 #15705595 未加载
评论 #15705468 未加载
hdhzyover 7 years ago
One interesting extension for desktop Firefox is Containers [0]. This is like per site incognito mode so tracking cookies do not escape between containers. While it&#x27;s not a strict security thing for me it&#x27;s one of more interesting aspects of Firefox as a browser.<p>[0]: <a href="https:&#x2F;&#x2F;addons.mozilla.org&#x2F;en-US&#x2F;firefox&#x2F;addon&#x2F;multi-account-containers&#x2F;" rel="nofollow">https:&#x2F;&#x2F;addons.mozilla.org&#x2F;en-US&#x2F;firefox&#x2F;addon&#x2F;multi-account...</a>
_hyn3over 7 years ago
Google has (always) gathered information about Chrome -- and Chromium -- users <i>by default</i>, including every keystroke typed into the &quot;omnibox&quot;. Not easy to disable, either.<p>This seems to be a recent Firefox policy change: all editions of Firefox is now collecting data, such as telemetry, information gathering, usage data. (URL&#x27;s? Form data?) This is all <i>opt-out</i> instead of opt-in now, and you&#x27;re asked only after installation. You have to pro-actively disable it.<p>(Formerly, telemetry gathering was only gathered by default on nightlies and dev tracks; this telemetry <i>does</i> cover usage.. i.e., this seems to include what URL&#x27;s you&#x27;re browsing; this could be a security risk for apps like Dropbox and OneDrive.)<p>To be fair, it&#x27;s easier to opt-out in Firefox than it is in Chrome, and Firefox is also more up-front about it after initial setup&#x2F;installation; still, given that Firefox held itself out as the privacy-oriented browser, this is a significant change.<p>(Which leads to a new question.. what&#x27;s the new best privacy browser? probably Brave? or, perhaps, Opera?)<p>EDIT: citation, thanks to cJ0th:<p><a href="https:&#x2F;&#x2F;www.mozilla.org&#x2F;en-US&#x2F;privacy&#x2F;firefox&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.mozilla.org&#x2F;en-US&#x2F;privacy&#x2F;firefox&#x2F;</a>
评论 #15705714 未加载
评论 #15708402 未加载
评论 #15705640 未加载
评论 #15705784 未加载
3dsover 7 years ago
My understanding is, that Firefox Quantum is not faster due to any additional rust parts, but because the team focused on performance optimization across the entire codebase.<p>The only big rust component was introduced a couple of releases ago: Stylo.<p>Once Webrender is in Firefox, a serious chunk of Firefox will be written in Rust.
评论 #15705253 未加载
评论 #15705213 未加载
评论 #15705199 未加载
评论 #15705236 未加载
robbykingover 7 years ago
I actually noticed some weird and potentially concerning behavior with Firefox Quantum this morning.<p>I had a fair number of tabs open (~28 or so), and I restarted the browser so a change I made would take effect. I have FF set to show my windows and tabs from my previous session on start up, but it instead launched with a single tab showing my home page. Okay, no big deal, I&#x27;ll just restore my previous session from the History menu. When I clicked on the history menu, though, I didn&#x27;t see my most recent history, but instead a list of URLs from my bank.<p>I assume this is due to a syncing issue with my Firefox account (I changed my banking password just to be safe), but it&#x27;s still concerning.
评论 #15706772 未加载
beaconfieldover 7 years ago
From what I understand about Rust, it does offer some native security improvements.
评论 #15704892 未加载
notacisspover 7 years ago
Look for the recent whitepapers by Cure53 and X41 both titled Browser Security Whitepaper.<p>tl;dr Chrome + Edge are more secure. Do not use Internet Exploder
mtgxover 7 years ago
Until proven otherwise, I think Chrome remains the most secure browser.<p>From what I&#x27;ve seen, FF57 only uses one content process by default (at least when you upgrade it from FF56), although you can enable up to 7 in settings ( I wish they gave higher numbers, too, like 50, or have a custom field).<p>Also, Rust is still a small portion of the browser. I&#x27;m not sure how big of a portion is of the rendering parts, which are usually the ones causing security issues.<p>We&#x27;ll see how it fares at the next Pwn2Own and perhaps in new papers comparing browsers&#x27; security over the coming year.<p>That said, I am excited that Tor will soon use FF59, which should include all of these improvements (but hopefully customized to have improved hardening by default compared to regular Firefox, on all operating systems).
评论 #15705418 未加载