• grue@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    ·
    1 day ago

    And yet the GrapheneOS people recommend their own “Vanadium” hardened version of Chromium instead, for reasons I don’t understand.

    • Metz@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      edit-2
      1 day ago

      It is explained here https://grapheneos.org/usage#web-browsing

      They don’t explicitly mention Firefox but:

      "Chromium-based browsers like Vanadium provide the strongest sandbox implementation, leagues ahead of the alternatives. "

      and

      "Chromium has decent exploit mitigations, unlike the available alternatives. "

      Since I myself lack the knowledge and skills to judge this, I have to trust the word of the developers.

      Edit, correction. They do mention Firefox

      “Avoid Gecko-based browsers like Firefox as they’re currently much more vulnerable to exploitation and inherently add a huge amount of attack surface.”

      • grue@lemmy.world
        link
        fedilink
        English
        arrow-up
        13
        ·
        1 day ago

        Merely asserting something and explaining it to my satisfaction (as a developer myself) are two different things. I don’t want to have to read through both codebases myself, but I would have liked the Graphene OS devs to cite some examples to prove their point.

        • REDACTED@infosec.pub
          link
          fedilink
          English
          arrow-up
          7
          ·
          15 hours ago

          Seriously. I’ve never heard of firefox being more vulnerable than chrome. It could be, but realistically not many groups are looking for exploits in a browser with 3% market share

          • Arghblarg@lemmy.ca
            link
            fedilink
            English
            arrow-up
            2
            ·
            6 hours ago

            Really? Didn’t seem to to me; I just installed latest GrapheneOS on my pixel 9 this weekend, and Vanadium definitely let Google Adsense crap all over many sites I visited.

            Is there a way to enable effective ad blocking that I missed?