• grue@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    18 days ago

    And yet the GrapheneOS people recommend their own “Vanadium” hardened version of Chromium instead, for reasons I don’t understand.

    • Metz@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      18 days ago

      It is explained here https://grapheneos.org/usage#web-browsing

      They don’t explicitly mention Firefox but:

      "Chromium-based browsers like Vanadium provide the strongest sandbox implementation, leagues ahead of the alternatives. "

      and

      "Chromium has decent exploit mitigations, unlike the available alternatives. "

      Since I myself lack the knowledge and skills to judge this, I have to trust the word of the developers.

      Edit, correction. They do mention Firefox

      “Avoid Gecko-based browsers like Firefox as they’re currently much more vulnerable to exploitation and inherently add a huge amount of attack surface.”

      • grue@lemmy.world
        link
        fedilink
        English
        arrow-up
        11
        ·
        18 days ago

        Merely asserting something and explaining it to my satisfaction (as a developer myself) are two different things. I don’t want to have to read through both codebases myself, but I would have liked the Graphene OS devs to cite some examples to prove their point.

        • REDACTED@infosec.pub
          link
          fedilink
          English
          arrow-up
          6
          ·
          18 days ago

          Seriously. I’ve never heard of firefox being more vulnerable than chrome. It could be, but realistically not many groups are looking for exploits in a browser with 3% market share

          • Arghblarg@lemmy.ca
            link
            fedilink
            English
            arrow-up
            2
            ·
            17 days ago

            Really? Didn’t seem to to me; I just installed latest GrapheneOS on my pixel 9 this weekend, and Vanadium definitely let Google Adsense crap all over many sites I visited.

            Is there a way to enable effective ad blocking that I missed?

            • cole@lemdro.id
              link
              fedilink
              English
              arrow-up
              1
              ·
              17 days ago

              I’m not sure I think it’s enabled by default. look in the settings to be sure. works pretty well on my grapheneos pixel 8

              • jet@hackertalks.com
                link
                fedilink
                English
                arrow-up
                2
                ·
                15 days ago

                Can you show us where the adblocking is? I just went through all my vanadium settings and found nothing.