[Q] Problems with Firefox security? - Firefox OS General

Hi folks,
I listen to security related podcasts, and there seems to be a consensus that Firefox is a fairly exploitable browser.
The FBI used a Javascript exploit recently to attack the Tor browser which is based on Firefox.
Firefox ships with Java and Javascript enabled, both of which are common attack vectors.
For this reason I am very skeptical about a Firefox-based phone. I am curious, what measures if any has Mozilla taken to make Firefox more secure on phones?
Cheers.

no offence, but name one popular browser that a lot of people use that can't be exploited in some way or ship with JavaScript enabled?
ps. java itself needs to be installed on its own, and a lot of websites have posted on how unsecure it is.

Related

Skyfire FULL WEB BROWSING ON WM5/6 PHONES AWSOME!!!!!!!!!!

LADIES AND GENTLEMEN, BOYS AND GIRLS, THE MOMENT YOU'VE ALL BEEN WAITING FOR. THE WAIT IS ALMOST OVER, HISTORY IS ABOUT TO BE MADE, I'M TALKING ABOUT FULLY EMBEDDED ADOBE FLASH 9, AJAX, FULLY EMBEDDED QUICKTIME 7, FULL DESKTOP CLASS JAVA RUNTIME, FULLY EMBEDDED WINDOWS MEDIA AUDIO AND VIDEO, AND I BELIEVE SILVERLIGHT AS WELL.
WATCH ANY VIDEO ON SITES LIKE YOUTUBE, DAILYMOTION, AND BREAK
LISTEN TO ANY MUSIC ON SITES LIKE LAST.FM, RHAPSODY, YAHOO! MUSIC, AND NAPSTER
STAY CONNECTED WITH FRIENDS ON SOCIAL NETWORKING SITES LIKE FACEBOOK AND MYSPACE
BROWSE WHATEVER YOU WANT WEATHER, NEWS, SPORTS, AND MAPS
SIGN UP FOR THE PRIVATE BETA AT http://skyfire.com/
whats up with the caps?
post some pics of your experience with this browser.
he's excited? I don't think anyone has gotten into the private beta yet...
read privacy policy, they track everything, incl. personal information.
There was a compiled at PPCGeeks regarding SkyFire. It looks fantastic (it always does). The private beta is due soon for release for the first-come, first-signed few...
I signed up about 5 days ago but I would imagine that it may take some time before public beta and I hope it does; if they are doing their homework and researching the triumphs & failures of Piscel, Opera, MiniMo, etc then I would expect to wait for a truely functioning & worthwhile WM browser. Hopefully SkyFire reps have been sitting in these forums and watching.
We have all suffered so many near hits and misses with a browser that would give us WM users the Safari-like browsing ability...
I signed up for the public beta a few days back as well when I saw the post over at PPCGEEKS. Personally I want to see if it will play the romp.com shockwave files I've had for years, they seem to still render in desktop browsers, but haven't found a way to render them on the PPC.
theFear13ss said:
I signed up for the public beta a few days back as well when I saw the post over at PPCGEEKS. Personally I want to see if it will play the romp.com shockwave files I've had for years, they seem to still render in desktop browsers, but haven't found a way to render them on the PPC.
Click to expand...
Click to collapse
Aw man I forgot about those. We used to play with them back in the day.
Also, regarding "they track everything, incl. personal information", I believe that is the case with any browser that uses any server side caching or compression. If I'm not mistaken, the same could be said for Opera Mini. Everything goes through their server first. Someone said this browser is like manipulating a full browser window open on their server.
neodorian said:
Aw man I forgot about those. We used to play with them back in the day.
Also, regarding "they track everything, incl. personal information", I believe that is the case with any browser that uses any server side caching or compression. If I'm not mistaken, the same could be said for Opera Mini. Everything goes through their server first. Someone said this browser is like manipulating a full browser window open on their server.
Click to expand...
Click to collapse
Opera Mini's privacy policy is:
Opera does not store any users' private information. Opera generates statistics of the usage of Opera Mini, but these are aggregated numbers and no information can be linked to a single user.
All information gathered by Opera Mini is subject to Norwegian laws regarding personal data. More information about the Norwegian Personal Data Act and Regulations can be found here.
I'm surprised spam like this is allowed here.

Google Chrome

So, I've just installed the new Chrome browser from Google and first impressions are that it's a good match for the Shift. Seems pretty fast and the tools bar etc doesn't occupy a lot of screen real estate.
I'm starting this thread as I'm interested to hear other peoples experiences with this browser on the Shift.
Regards,
Dave
It seems pretty snappy, but I'd forgotten how many ads there are are the sites I regularly visit, and it makes me realise how well the AdBlock Firefox extension works.
I just did the first tests too...
I like to flick with the stylus over the screen for scrolling up and down...doesn't work on chrome
also i used the plugins firebug and smart bookmarks bar on FF, which aren't yet supported on chrome.
Should you/we be sending these requests back to google so they can include functionality? Cheers
Hi,
my impression is that it is much faster than IE and FF, but missing add-ons so far. For example, Google's own toolbar. I use it for synchronizing bookmarks.
S.
As far as I know ....
As far as I know it's jet too early to install Google Chrome in a pc......
http://www.webnews.it/news/leggi/9046/chrome-ed-e-subito-vulnerabilita/
http://www.securityfocus.com/bid/30983
...vulnerabilities in Chrome...
We all take risks every time we visit a new site, or click on a link in an email. The simple fact of the matter is that the only truly safe way to browse the internet is on someone elses machine, and not to use any kind of internet banking or any other site where personal details can be obtained and compromised!
There are vulnerabilities in *every* mainstream browser, most of which are yet to be found, but that doesn't mean that they shouldn't or can't be used.
Each to their own of course!
Regards,
Dave
Yess...
We take risks everyday but, why to use well known bugged browsers?
Regards
Simply because if someone doesn't, future bugs will never get found and fixed. This particular bug has already been fixed in the current version of WebKit and therefore I'd expect to see a new release from Google based on the latest (or later) version of WebKit within a fairly short order.
Yes, this version of Chrome has a number of vulnerabilities, but then again so will IE, Firefox, Opera, Safari - so take your pick!
Thus far though, surfing the web using Chrome on the Shift is proving to be a far more pleasant experience (for me at least) than IE or Firefox.
Regards,
Dave
I absolutely agree....
...but in the meanwhile I prefer to use broswers whose bugs are often fixed allthough it's clear that there are unknown or not jet discovered vulnerabilities.
But it's still just my opinion.
Best solution would be to keep an eye on what happens on some sites like securityfocus.org.
Best regards

(REQ) Webtop Hacks, Multi-user, Pkg installer

So I have some thoughts on what would make improvments to the devices over all user experiance.
The finger reader is cool, If we could use it to identify two or three people /and/or Have a multi-user support then in the Laptop regard it would be better. Even if it was just Owner/Guest support. I realize that any access other then Owner would open security risk but on the laptop mode this could be a neat thing.
Also Since it is running a lame version of Ubuntu it should support multi user. The Webtop OS, can/should/may support it where I realize that Android isn't really ment for this, it would be a neat option on both OS's.
We really need package manager support in the Webtop. I can't view my bank account correctly due to lack of Java support in firefox and When I attempt to DL and install it, it can't because there is not a package manager. I haven't hacked much at it but it is not there by default.
Of course once the Double rainbow, as some call it, is out then this will be a non-point hence more of a gripe, but if your going to make Ubuntu into a web base OS, why not use Chrome OS, at least it has a App store and a great web browser. (not that firefox isn't but I've been doing chrome since beta).
joeavery2 said:
Of course once the Double rainbow, as some call it, is out then this will be a non-point hence more of a gripe, but if your going to make Ubuntu into a web base OS, why not use Chrome OS, at least it has a App store and a great web browser. (not that firefox isn't but I've been doing chrome since beta).
Click to expand...
Click to collapse
*sigh* I really wish people would get their heads straight, because I keep seeing this over and over.
Look.
Nobody has access to the source for Chrome OS except for Google. Chrome OS hasn't been released out of beta yet. This isn't a Google Experience device, so there's no chance in hell that it would have Chrome OS.
Similarly, before you ask for Chrome, nobody (except Google, probably) has access to Chrome for ARM, since source isn't available for that either.

Ads with sound... Has the always been?

I am finding the sounds emanating from XDA's ad streams to be QUITE a turn-off to the site. On my desktop, that is.
Is there any way to get some control over that, as a user? I mean, outside of my planned behavior of not having it open in my browser on my desktop.
I am finding the experience of the XDA site severely diminished when I, a nerdy guy, is listening to some female talk about things I don't use; that my wife despises and I would never purchase.
Seems the research on that has failed miserably.
if you are using chrome or mozilla download the adblock extension. with chrome you can even get flashblock to block ads with flash.
i m currently using chrome, and once when i when to xda webpage, using another browser(i wasnt for sure on my laptop), i thought i was on a wrong website from the lot of ads..
install chrome, and adblock extension..

Stock Rom: Unreadable status bar with Firefox

When running Firefox on the stock rom, the status bar turns white while the text remains white so that the time, date, signal, and other status bar items are unreadable. I tried changing the system themes and the Firefox themes without any change. Is there any other possible solution to force the status bar to any color other than white with Firefox? I guess I could use an unofficial build, but I wanted to try out the play store version for a while.
dweekie said:
When running Firefox on the stock rom, the status bar turns white while the text remains white so that the time, date, signal, and other status bar items are unreadable. I tried changing the system themes and the Firefox themes without any change. Is there any other possible solution to force the status bar to any color other than white with Firefox? I guess I could use an unofficial build, but I wanted to try out the play store version for a while.
Click to expand...
Click to collapse
This is a known Firefox bug, and they are working on it. If you must use Firefox, install the beta version, which will give the fix a little quicker.
Firefox is my favorite browser on desktops. But, It's still a little too buggy for me on Android.
tsongming said:
This is a known Firefox bug, and they are working on it. If you must use Firefox, install the beta version, which will give the fix a little quicker.
Firefox is my favorite browser on desktops. But, It's still a little too buggy for me on Android.
Click to expand...
Click to collapse
Thanks, I guess I'll have to be patient since the beta and nightlies exhibit the same result.
I thought Firefox Focus was great and wanted to try Firefox Quantum across the platforms after years of using mainly Chrome. Chrome for Android still freezes and crashes on pages with heavy ads (including ESPN), and it has been that case for years. I'm still not sure why....
dweekie said:
Thanks, I guess I'll have to be patient since the beta and nightlies exhibit the same result.
I thought Firefox Focus was great and wanted to try Firefox Quantum across the platforms after years of using mainly Chrome. Chrome for Android still freezes and crashes on pages with heavy ads (including ESPN), and it has been that case for years. I'm still not sure why....
Click to expand...
Click to collapse
Did you update to 5.8.21s ?
If so force close the browser and clear the cache in the browser app settings
Also try the stock browser, it's pretty decent.
dweekie said:
Thanks, I guess I'll have to be patient since the beta and nightlies exhibit the same result.
I thought Firefox Focus was great and wanted to try Firefox Quantum across the platforms after years of using mainly Chrome. Chrome for Android still freezes and crashes on pages with heavy ads (including ESPN), and it has been that case for years. I'm still not sure why....
Click to expand...
Click to collapse
I tried ESPN and it works just fine. I've got a Pro3 Elite (x722) with a SD820 on 20s (a cleaned vendor ROM from Banggood). Then again, I've uninstalled all LeEco apps, save for Phone and Contacts, and I'm running Adguard for adblocking. You really need VPN adblocking, my friend. It will revolutionize the way you browse on mobile. And I'm not talking about uBlock Origin on Firefox for Android, which isn't always reliable (sometimes it simply doesn't load).
Either that, or try a browser that supports adblockers natively, like Samsung Internet. Firefox Quantum on desktop is great--I'm using it right now, but FF for Android sucks. You can try Waterfox, a popular fork of Firefox. It has an Android app too.
tsongming said:
Did you update to 5.8.21s ?
If so force close the browser and clear the cache in the browser app settings
Also try the stock browser, it's pretty decent.
Click to expand...
Click to collapse
sk8223 said:
I tried ESPN and it works just fine. I've got a Pro3 Elite (x722) with a SD820 on 20s (a cleaned vendor ROM from Banggood). Then again, I've uninstalled all LeEco apps, save for Phone and Contacts, and I'm running Adguard for adblocking. You really need VPN adblocking, my friend. It will revolutionize the way you browse on mobile. And I'm not talking about uBlock Origin on Firefox for Android, which isn't always reliable (sometimes it simply doesn't load).
Either that, or try a browser that supports adblockers natively, like Samsung Internet. Firefox Quantum on desktop is great--I'm using it right now, but FF for Android sucks. You can try Waterfox, a popular fork of Firefox. It has an Android app too.
Click to expand...
Click to collapse
I'm on 21s. The Chrome freezing bug has been recurring for years as far as I can remember, through my Nexus 4, 5, 6, and 6P. I think adblocking helped, but it still freezes regularly on some sites.
I installed AdGuard Premium and am still testing it (page loading delays and errors, battery, whitelisting, etc). I may just break down and root this phone to compare to Adaway for fun. I've been hesitant to try custom roms as I prefer maximum battery life over other benefits.
LeEco was a slight deviation and a breath of fresh air for battery life. It's just annoying to have merely a few months of software support from the company.
Thanks for all the suggestions!
dweekie said:
I'm on 21s. The Chrome freezing bug has been recurring for years as far as I can remember, through my Nexus 4, 5, 6, and 6P. I think adblocking helped, but it still freezes regularly on some sites.
I installed AdGuard Premium and am still testing it (page loading delays and errors, battery, whitelisting, etc). I may just break down and root this phone to compare to Adaway for fun. I've been hesitant to try custom roms as I prefer maximum battery life over other benefits.
LeEco was a slight deviation and a breath of fresh air for battery life. It's just annoying to have merely a few months of software support from the company.
Thanks for all the suggestions!
Click to expand...
Click to collapse
Adaway is pretty fantastic. In fact, I haven't seen ads since installing it. You do a have a few options for ad blocking without rooting: Brokada is excellent, and blocks Ads in apps as well. But, you will see the occasional ad.
Another non root option is Ad Clear, which places a firewall on IPV6. I haven't used AdGuard premium, is there no where in the settings for filter addons/updates or firewall blocking?
If you decide root the phone, be very careful if you haven't gone through extended steps of unlocking the bootloader. As you know, you could brick your device.
If you decide to go for it. I recommend AICP, or Omnirom both will give you continued long battery life, and allows you to use the Pixel Modded camera with zero issues.
If you need help with unlocking your bootloader, rom installation and rooting, let me know and I can send you detailed instructions. Just so you know once you unlock the bootloader and install Twrp, the rest is easy and you can always return to stock if wanted.
dweekie said:
I'm on 21s. The Chrome freezing bug has been recurring for years as far as I can remember, through my Nexus 4, 5, 6, and 6P. I think adblocking helped, but it still freezes regularly on some sites.
I installed AdGuard Premium and am still testing it (page loading delays and errors, battery, whitelisting, etc). I may just break down and root this phone to compare to Adaway for fun. I've been hesitant to try custom roms as I prefer maximum battery life over other benefits.
LeEco was a slight deviation and a breath of fresh air for battery life. It's just annoying to have merely a few months of software support from the company.
Thanks for all the suggestions!
Click to expand...
Click to collapse
Chrome freezing in general, or just on ESPN? If it still happens with adblocking, then the issue lies with ESPN. They're not doing a proper job of optimizing their mobile page for Android. As for Chrome freezing in general, I've never seen that happen... well, except when trying to type a reply on reddit in desktop mode. Then again, I don't visit any heavy websites. Just a lot of text-based ones.
I used to use Adaway a lot, but the lack of good lists for it makes it kind of... useless. Like it doesn't block ads in the mobile version of Google.com. Or mobile version Twitter ads or sponsored tweets. It's nowhere near as useful as, say uBlock for your PC or Firefox Android (whenever it works). It's up to you to create a list of your own with all those blocked elements. Neither do AdGuard, DNS66, or Blockada, for that matter. Mobile adblocking is still in its infancy, unfortunately.
sk8223 said:
Chrome freezing in general, or just on ESPN? If it still happens with adblocking, then the issue lies with ESPN. They're not doing a proper job of optimizing their mobile page for Android. As for Chrome freezing in general, I've never seen that happen... well, except when trying to type a reply on reddit in desktop mode. Then again, I don't visit any heavy websites. Just a lot of text-based ones.
I used to use Adaway a lot, but the lack of good lists for it makes it kind of... useless. Like it doesn't block ads in the mobile version of Google.com. Or mobile version Twitter ads or sponsored tweets. It's nowhere near as useful as, say uBlock for your PC or Firefox Android (whenever it works). It's up to you to create a list of your own with all those blocked elements. Neither do AdGuard, DNS66, or Blockada, for that matter. Mobile adblocking is still in its infancy, unfortunately.
Click to expand...
Click to collapse
AdClear is the strongest ad blocker app that I have used. But, it seems to sometimes cause applications to hang.
The newest version of Adaway is very good. But, for it to work extremely well, I update the host files daily and use my own filter links.
I tried DNS666 and didn't see any blocking at all. There is a Adblock module that can be installed through Magisk called: Unified Hosts. Install that in conjunction with Adaway and you will not see ads.
Yeah, the issue is that Adaway, DNS66 and Blockada depend on hosts files and I haven't found any thorough ones yet. The repositories uBlock Origin uses aren't hosts files AFAIK and you'd have to convert them to hosts files for use with those apps. Adguard will accept uBlock filters though.
sk8223 said:
Yeah, the issue is that Adaway, DNS66 and Blockada depend on hosts files and I haven't found any thorough ones yet. The repositories uBlock Origin uses aren't hosts files AFAIK and you'd have to convert them to hosts files for use with those apps. Adguard will accept uBlock filters though.
Click to expand...
Click to collapse
AdAway now has the ability to use links.
Here is an excellent source for links updated daily: https://github.com/StevenBlack/hosts
Go down the page to : Sources of hosts data unified in this variant
Use can either use the link and add Adaways user links, or you can generate you own host files by using tool here: https://hostsaway.appspot.com/
Note:
This page is in Japanese, it will convert to English if you set Chrome to always translate Japanese to English.
Instructions here: https://support.google.com/chrome/answer/173424?co=GENIE.Platform=Desktop&hl=en
sk8223 said:
Chrome freezing in general, or just on ESPN? If it still happens with adblocking, then the issue lies with ESPN. They're not doing a proper job of optimizing their mobile page for Android. As for Chrome freezing in general, I've never seen that happen... well, except when trying to type a reply on reddit in desktop mode. Then again, I don't visit any heavy websites. Just a lot of text-based ones.
I used to use Adaway a lot, but the lack of good lists for it makes it kind of... useless. Like it doesn't block ads in the mobile version of Google.com. Or mobile version Twitter ads or sponsored tweets. It's nowhere near as useful as, say uBlock for your PC or Firefox Android (whenever it works). It's up to you to create a list of your own with all those blocked elements. Neither do AdGuard, DNS66, or Blockada, for that matter. Mobile adblocking is still in its infancy, unfortunately.
Click to expand...
Click to collapse
It's a lot of random sites as well as ESPN; Business Insider is another one that will hang on me randomly. Adguard defaults don't prevent it. I've kind of just accepted Chrome freezing as normal expected behavior over the years.
Thanks for all the input everyone. I haven't really explored VPN adblocking prior to this thread, but I'll definitely play around with it further. I am rather curious what to expect from Chrome's built-in minimal adblocker in the future. I'm actually okay with some ads to support websites, but the bad ones truly ruin it for everyone.
dweekie said:
It's a lot of random sites as well as ESPN; Business Insider is another one that will hang on me randomly. Adguard defaults don't prevent it. I've kind of just accepted Chrome freezing as normal expected behavior over the years.
Thanks for all the input everyone. I haven't really explored VPN adblocking prior to this thread, but I'll definitely play around with it further. I am rather curious what to expect from Chrome's built-in minimal adblocker in the future. I'm actually okay with some ads to support websites, but the bad ones truly ruin it for everyone.
Click to expand...
Click to collapse
It could be a number of things. Again, uninstall LeEco bloatware via adb. Try other browsers like Samsung Internet, which is purportedly much faster than Chrome. And use it with an adblocking add-on like Adhell. I doubt Chrome's adblocker will be very effective, considering that Google makes the bulk of its money from ad revenue and those Analytics scripts aren't exactly lightweight.
Record your screen and visit those sites in Chrome. I'm curious about how bad it gets.
I'm with you about supporting websites through ads, but too many websites run ridiculous ads that drive up your CPU use. And what about all those stupid websites that use cryptomining ads? No thanks. As long as the ad industry stays shady, and websites aren't transparent about the ads they run, I'm going to keep using an adblocker.

Categories

Resources