• Siliconic
    link
    English
    11
    edit-2
    11 months ago

    About time. I’m tempted to switch back to Mull from Bromite, but I’m worried about the security of Firefox compared to Chromium (that’s why I switched in the first place), I’ve heard that particularly Mobile Firefox has awful sandboxing and bad security, I’m pretty sure it was the GrapheneOS team saying this? I’m no security expert though…

    • @randint@lemm.ee
      link
      fedilink
      English
      8
      edit-2
      11 months ago

      Yes it was the GrapheneOS team who said that. See the paragraph just above Camera. I literally just skimmed their guides and saw this yesterday while considering getting a Pixel.

      • z3rOR0ne
        link
        fedilink
        English
        4
        edit-2
        11 months ago

        I use Mull and Vanadium on Graphene OS, and the experience on Vanadium is just okay by comparison. It is true that not having extensions does decrease the attack surface, and Vanadium does have a built in ad blocker, but it simply isn’t as all encompassing as ublock’s list.

        I use Mull mainly but don’t log into anything with it, and have noscript extension on by default.

        I also turn off JS by default in Vanadium. Both browsers have ways of making exceptions for certain sites in this case, but NoScript has more granular control.

        I remember reading on reddit a convo that basically the GrapheneOS team was much more concerned with security than privacy. This isn’t to say they don’t care about privacy at all, just that they will always prioritize security first.

        This makes sense considering their decision to only officially support the Pixel line of devices. You still are supporting Google by giving them your money (and a bit of your data in the process of purchase). Additionally, the decision to default to using the Google Play Store and sandbox the apps, rather than use the Aurora Store, also points to these underlying values.

        • @randint@lemm.ee
          link
          fedilink
          English
          311 months ago

          Yeah, I can tell this just from skimming their FAQ and Usage Guides. When they talk about the applications they offer, they always sell it as the most secure thing ever. I still personally care more about privacy than security though.

        • @JuvenoiaAgent@lemmy.ca
          link
          fedilink
          English
          2
          edit-2
          11 months ago

          Posted this above, but it might interest you as an alternative to Vanadium:

          Bromite hasn’t been updated in a while, so you should at least switch to Cromite if you’re not switching to Mull. It’s a fork by a previous Bromite contributor and includes some improvements, like a bottom toolbar and adblock plus (so normal block lists, not Bromite’s less customizable ad blocker.

          • z3rOR0ne
            link
            fedilink
            English
            -111 months ago

            Is Vanadium just Bromite under the hood? I thought they were separate projects…

            • @JuvenoiaAgent@lemmy.ca
              link
              fedilink
              English
              211 months ago

              They’re different, but according to its readme, Cromite includes “security enhancement patches from GrapheneOS project”, so I assume it contains Vanadium’s changes as well as other improvements.

              • z3rOR0ne
                link
                fedilink
                English
                -111 months ago

                Thanks for the clarification! I’ll investigate.

    • @JuvenoiaAgent@lemmy.ca
      link
      fedilink
      English
      511 months ago

      Bromite hasn’t been updated in a while, so you should at least switch to Cromite if you’re not switching to Mull. It’s a fork by a previous Bromite contributor and includes some improvements, like a bottom toolbar and adblock plus (so normal block lists, not Bromite’s less customizable ad blocker.

      • Siliconic
        link
        English
        111 months ago

        Thanks, I hadn’t noticed it wasn’t updating