Iridium Browser – A Chromium-based browser focused on privacy
iridiumbrowser.de
iridiumbrowser.de
(Iridium is currently branched off chromium 54, chrome is on version 55)
What data does Google own?
I mean if we're going to go to this level of paranoid; then we might as well look at attacks on Firefox (which have been suspected to be used by the NSA against Tor Browser).
It's less about being covert, and more about having multiple settings to send different types of data back.
(You can easily check this with an app like Little Snitch, look for the browser connecting to IPs 8.8.8.8 and 8.8.4.4)
I also just noticed that Little Snitch actually does NOT log the dns requests. Maybe this is caused by Chromium using ipv6 to access google-public-dns-a.google.com ?
Anyway, I then installed Vallum (1) and with this app, in the log i see many of these requests: https://i.imgur.com/lUR3Fd7.png
*edit: I'd genuinely be surprised if google made it that easy to not send anything back to them. Additionally, I'd be genuinely surprised if FF made it that simple to avoid sending things back to Mozilla.
Remove physical microphone from your computer, Chome will turn it on randomly and send recordings to Google.
1. While the Hotword module was downloaded at startup, the feature was not activated without the user explicitly enabling it via the settings menu. <https://crbug.com/500922#c6>
2. Downloading the module in Chromium was a bug, and it was fixed after being reported. <https://crbug.com/50922#30>
3. The Hotword feature was dropped from Chrome not too long after, because it was an experiment that never really panned out (and was enabled by very few people).
It's not that you're not allowed to worry about google holding your data (of course it is!), but it's pretty unsafe to be on the 'net without being properly patched.
If I had to set about this, I would have an upstream fork of Chromium that would patch the various networking functions to blacklist known google domains, and then offer a flag to ignore the blacklist in the "obvious" spots (like when you go to google.com). Probably not perfect, but a bit safer.
If you're super serious, you could just 404 all access to google.
I haven't updated Chrome in quite a while. My computer's been running just fine. I'm pretty sure I would've died if I'd tried to cross highways as you mentioned all this time. So I think something about the comparison doesn't smell right.
The relative odds aren't quite right, but consider how many people you might know who lost their PCs to virii, compared to people compromised by their Google searches.... Maybe it's a wash ;)
I think your likelyhood of getting your PC messed up is pretty dependant on habits too. You're much more likely to get hit by drive-by adware if you're (on Windows and) going to those random illegal streaming sites to watch some show than if you're reading HN.
An example: I was on a less than stellar video hosting site, and a bunch of pop-ups got me to accidentally download "FlashPlayer.dmg"
I'm pretty well versed in this stuff! And they got me to download this right as I was going to watch this video. If I didn't know better, it would have been like all those other plugin updaters (of course you need root to install flash right?)
Of course, updated Chrome didn't prevent this case for me...
Indeed...
> You're much more likely to get hit by drive-by adware if you're (on Windows
Indeed I am on Windows... without security software, etc.
> and) going to those random illegal streaming sites to watch some show
Indeed I am not...
> than if you're reading HN
Indeed I am...
> An example: I was on a less than stellar video hosting site, and a bunch of pop-ups got me to accidentally download "FlashPlayer.dmg" I'm pretty well versed in this stuff! And they got me to download this right as I was going to watch this video.
Even if you downloaded that, you have to do some extra clicks to make it run. It's not something that I can see happening by accident to the average HN reader.
> If I didn't know better, it would have been like all those other plugin updaters (of course you need root to install flash right?)
But you did know better.
> Of course, updated Chrome didn't prevent this case for me...
Well there you go, I'm out of arguments.
I think you quite beautifully narrowed down where the real problems lie and proved my point, so I'm just going to leave it at that. ;)
On the other hand, looking over CVEs for chrome[0], I'd be a bit worried. Chromes before 47 included remote code execution via the MIDI subsystem! If someone could play a MIDI, they could compromise your system!
Yikes
[0] http://www.cvedetails.com/vulnerability-list/vendor_id-1224/...
Anyway, I came here for a tangent about those "less than stellar video hosting" sites: I have an idea how to kill two birds with one stone - getting rid of them, and fixing the Internet. Can we convince MAFIAA to go after ads on the web? After all, that's what keeps illicit streaming alive.
(Torrents will obviously survive, but at least right now, most people don't know how to use them.)
I'm currently doing work in an office of ~30 people where the IT support company (supposedly accidentally) set up this lovely policy https://i.ytimg.com/vi/rC4FQwYXIok/maxresdefault.jpg which was in place for about a year before I noticed it on a colleague's computer. Pretty terrible security-wise, but no-one's been hit by a car to my knowledge.
I get that protecting against hypothetical exploits is good, but it's probably best to stop the ongoing security breaches first.
I've been shot exactly zero times, so nobody needs to worry about being shot.
On the plus side, it means you can still easily overwrite the detected encoding with the correct one.
Do these patches fill holes left in longstanding bugs, or possibly more likely, bugs introduced more recently through feature development?
Firefox also keeps eating more and more memory the more time it's open (Chrome also uses a lot memory, but at least it's stable). Firefox devs usually blame extensions for this (and I can believe them), but I really don't care who's fault it is, I just want my browser to work nicely.
Also, these are present complains. Since at work I'm back on Linux full time, I tried to stop using Safari at home and use Firefox in order to use the same browser everywhere. But Firefox just didn't cut it.
I'm now deciding between Opera and Chromium. They have their quirks, but at least they are considerably faster (on my MacBook Pro) and don't keep leaking memory like Firefox does.
Which brothers me, because the best browser on paper when it comes to multi OS support and privacy is Firefox and would be my default go to browser in this case it weren't for these big (for me personally) problems it still has after all these years of the same exact complains from a lot of users.
Also not only security updates are an issue. Some of the previous forks have been maintained by people who hardly had any idea of what they were doing. Interesting blog post about the Iron fork: http://neugierig.org/software/chromium/notes/2009/12/iron.ht...
> 10:26 < Iron> why must google be so evil :(
> 10:27 <+evmar> it's pretty rough here, what with the strangling kittens all day
Firefox is slow, klunky and the UI is deplorable. Mozilla and also hates native platforms and therefore Firefox doesn't respect my OS. For instance - since the beginning of time, every Windows program let me close the window by double-clicking in the upper left corner. People have been asking Mozilla to change this for years and got ignored. Meanwhile, the Chrome team changed it immediately upon request when one of their builds lost the ability.
IMO, Mozilla is a second-rate has-been that turns out nothing but useless crap like Rust and Servo that nobody needs or uses since there are much higher quality alternatives already in existence - http://www.mozillalabs.com/en-US/projects/
Mozilla and Tor are working to upstream many of Tor's privacy changes into the Firefox code base. Even if the features are disabled in Firefox for now, having the code already in Firefox will make Tor's work easier because they don't need to reapply bitrotted patches. They just need to toggle an about:config pref. This Tor blog post has more information about the upstreaming collaboration:
https://github.com/iridium-browser/tracker/wiki/Differences-...
Tor Browser on the other hand tries to be a very private oriented browser (blocks several features by default) and gives access to the Tor network.
animation: marquee 20s linear infinite;I feel like there's should be a word that described the things that get ruined by a small number of abusers. I'd probably already know it, if such a word were coined, but maybe not.
Doesn't seem usable.