— How quickly will serious vulnerabilities be patched?
Given the project is so small, I wouldn't trust their future response to be rapid even if they have been in the past. Right now most security fixes come in the form of merging upstream security fixes from Mozilla. As their code base becomes increasingly divergent to the Firefox head, merging in upstream security fixes will become increasingly difficult and increasingly cumbersome.
— How much do you really trust these developers?
I don't think many people realise just how important your browser is when it comes to trust. When you access online banking, your browser is in ultimate control of the entire trust chain. Your browser validates the security certificates. Your browser decides what to do with the passwords you enter. Your browser decides what to show you in the address bar.
— What's wrong with Firefox 67+ anyway?
The one thing everyone seems to cite when they say they use Pale Moon or Waterfox is that they still support the older extension system. The reality is all important extensions were unaffected. And while some genuinely useful extensions were lost in the transition (e.g. DownThemAll) most should be standalone applications anyway.
Also, my problems with the browser product itself are simple: the UI is awful and cannot be meaningfully fixed, and multi-process programs cause my computer to hang (so I set up a script to auto kill them). Pale Moon respects me as a User, not as an ad profile for Google.
I would never trust the judgement of the most important piece of software on my computer to a small group of tinkerers maintaining a fork of someone else's massively complicated and deeply outdated source code. I don't care who they are—if they don't have a big enough reputation on the line, there's no reason to trust them.
I'm sure your cousin is super trustworthy, but that doesn't mean anyone should put him in charge of the armoured vehicles division of a bank.
Besides, it's a lot easier for a microscopically small and individualistic outfit like Pale Moon to never disappoint you compared to a large, managed entity like Mozilla which has disclosure policies and hundreds of employees each with their own priorities and agenda.
But for a limited use program like a browser, yeah, I want the people who won't disappoint me.
Mozilla is morally wise a totally unacceptable developer. They have been on the good side in the past, but what is left is almost as disgusting as Google itself... the Google - which Mozilla tries so hard to become itself.
For the technical reasons read
https://www.howtogeek.com/335712/update-why-you-shouldnt-use...
For the interpersonal reasons please see the lead developer acting like a spoiled child here.
https://github.com/jasperla/openbsd-wip/issues/86
Friends don't let friends use a crappy, out of date, insecure, janky browser.
>For the technical reasons read
https://forum.palemoon.org/viewtopic.php?p=135424#p135424
>For the interpersonal reasons please see the lead developer acting like a spoiled child here.
(btw mattatobin is not a lead developer, get your fact straight please)
https://forum.palemoon.org/viewtopic.php?p=134236#p134236
>Friends don't let friends use a crappy, out of date, insecure, janky browser.
The unofficial patches are presumably by definition not copyright the project considering they are written by a third party.
This is kind of how multiple source based packages work. Nothing is being distributed by the repo save instructions the end user does the fetching and building.
Normally people do a small amount of research before attacking volunteers who are providing free labor to make their package more broadly available.
An example dialog could have been opened like so.
"We at the Pale Moon project prefer that distributions package as close as possible to the default experience to ensure that all users have the same experience and aid in troubleshooting. Can we talk about the patches that are being distributed with Pale Moon to see if they are really needed for our product to work on your OS?"
If no agreement can ultimately be reached respectfully ask for it not to be distributed but use the know how generated to add a forum post "Building on OpenBSD" not burning any bridges AND actually profiting from the experience.
Instead Pale Moon devs appear to have learned nothing from the interaction.
I've noticed that you didn't bother to address the technical reasons whatsoever. Your browser is probably the best vector into your system and malware no longer just screws up your system. It's now common for malware to encrypt your files and hold them for ransom.
In effect an out of date firefox means that malware authors can use up to date firefox's security fixes to target users using old software that perforce is vulnerable to the same attacks. This needn't be specifically targeted at JUST palemoon users. All users of out of date firefox represent a possible victim pool with attractively low security.
It's right there, bellow the "crappy, out of date, insecure, janky browser" unfounded claims, open the two links I've provided and you'll see that ALL the technical reasons are covered extensively.
In fact, i also would use Vivaldi every day over Firefox. Mozilla has turned into a greedy sell-out developer with zero respect for power- or geek users!
Example Pentadactyl -> Tridactyl, noscript, ublock origin, stylus.
I'm not clear where you are coming from with the "greedy" accusation nor where you get off calling them sell outs. Based on what?
Your refrains betray "reduced to 180 characters" level of understanding of the matter and I strongly suggest you gain a more complete understanding of technical and business matters before attacking people who are producing so much value for the open source community.
https://github.com/gorhill/uBlock/releases/tag/firefox-legac...
and here's the uBlock Origin Updater https://addons.palemoon.org/addon/ublock0-updater/