Dangerous bug in Chrome’s ‘New Tab’ page bypassed security features
portswigger.net
portswigger.net
On a smaller scale, tech people do the same thing by using more complex terms for simple things to appear to have some kind of special knowledge. It's all about who is on the inside and who is on the outside. Highly annoying.
Such DSLs can serve to increase the speed of communication but more often than not they are simply used for obfuscation purposes.
(I think I missed the self referencing joke).
The military take the abbr.hl. to the next level. But atleast the abbreviations are properly documented there. I guess the root is keeping telegraphy short?
On my last job it was so bad that it took like a year before you could follow conversations properly. Also old deprecated abbreviations were used for extra flavor. E.g. calling projects or departments by their former former name.
On top of the usual acronym madness, nearly everything is always referenced by code name, versioned according to arcane and strange conventions, and the mapping to released product names and real version numbers is not always documented or obvious.
Just kidding, trick question, the answer is NEVER.
(No, an extension which overrides all the bloated pile of crap after it's already been processed and rendered does not count.)
Preferences » Home » New Tab page [Firefox startpage v]
or, about:preferences#home
https://chromeenterprise.google/policies/#NewTabPageLocation
afaik, extensions that set chrome_url_overrides.newtab in their manifests file prevent the native NTP from loading at all.
i would never use a browser w/o a blank new tab page; it's universally supported isn't it?
What? The answer is ALWAYS. Set your start page to be `about:blank` and you see a blank page. I've had this as my starting page in every single browser since the 90s.
For all the hate they get, FF is easily the best and most respectful browser around
Without containers, I’d probably bite the bullet and start using some chrome fork that doesn’t show me useless ads.
So Chrome and FF are in the same boat: "UX" "designer" taking non-sensical decisions for the whimsical greater good.
I presume grandparent has either hit a bug, has some unusual/untested about:config combination, or, most likely, an addon that broken.
Here is the relevant about:config settings I have these changed for the URL bar:
browser.urlbar.suggest.searches false
browser.urlbar.searchSuggestionsChoice false
browser.urlbar.showSearchSuggestionsFirst false
Also for your urlbar you want to change it so it always shows the scheme and every part of the URL. browser.urlbar.trimURLs false
Stop Firefox trying to help with incomplete urls and loading the wrong site: browser.fixup.alternate.enabled false
Setting the above about:config entries should stop URLS you type being sent to a search engine and also stop some other surprises in the URL bar.* Tips and News from Mozilla and Firefox * Recommendations while surfing * Recommend addons while surfing
I'm not entirely sure what you saw that made you angry, but I'm pretty sure you can switch them off rather than abandon the entire browser.
That goes for a lot of Firefox hate, I find: quite often people are ranting online about some new or removed feature, which they can dis- or enable easily in the settings. Or -a tad harder- in about:config. Or even a tad harder, with an addon.
That makes me think those ranters don't really want their problem solved, but just want to vent some anger about X changing something that they are emotionally not ready to see changed.
Obviously the actual page rendering and JavaScript executing would be Safari. But 99% of the time when I hear people advocating for browser X over browser Y it is not because X has better rendering or a better JS engine. It is because of higher level things, like containers (Firefox over Chrome) or better profile handling (Chrome over Firefox) or better spell checking (everything over Firefox).
Does having to build on top of Safari on iOS also constrain those higher level things?
Yes!
> containers (Firefox over Chrome)
No, they can't install add-ons (https://support.mozilla.org/en-US/kb/add-ons-firefox-ios). Even if they could built this into the browser, they can't (see how the profiles are handled).
> better profile handling (Chrome over Firefox)
No, Chrome does not support this feature on iOS (https://support.google.com/chrome/answer/2364824?hl=en&co=GE...). iOS' WebKit limits this to only one permanent profile and one ephemeral profile. You can technically have multiple profiles in the iPad - that is, if you're a school, and that's really more of a OS-wide user account thing. (G did a hack over this by rewriting that profile when switching profiles - but it's not truly a multitask thing, and violates Apple Developer Guidelines).
> better spell checking (everything over Firefox)
No, and for more sensible reasons. Users do expect consistent spell checking because they use the keyboard to do that. Regardless, if you want to implement spell checking in-browser, that's impossible. If you want to do it outside of Safari, go ahead - it's just not integrated to those Apple things (more of a dedicated Grammarly interface rather than desktop spell checking).
Was switched off.
All the others (according to the linked information) are irrelevant for intrusive pop-up ads. By all means, please explain to me which of those settings do something different from what they are supposed to do, or tell me about an about:config settings that tells Firefox to never show me pop-up ads.
What made me angry: https://i.imgur.com/s9hC23U.png which blocks the interaction with any part of Firefox until I click "Not Now"
With a bit of effort, you can get a similar level of privacy to Firefox in Chrom[e/ium].
What specific effort?
A real shame.
What I don't like is Mozilla using it as a dairy cow, and starving it on top of that.
> What I don't like is Mozilla using it as a dairy cow, and starving it on top of that.
I don't get the analogy. What exactly is Mozilla doing that you don't like?Mozilla have many interesting projects and several of them may be good, but none of them have had such impact or has such potential for the future as Firefox.
Edit: and I'm willing to pay $10 - $50 a month to someone who will create and maintain a patched version of the latest Firefox that fixes the worst problems like not being able to hide the standard tabs (in addition to any sponsored search deals they may get).
I suspect I'm not alone: for many(most?) of us our browser is one of our most important tools, the other being and IDE, an editor or some graphics tool.
Edit 2: Paid Chromium based doesn't count for me. A major point is to counter the Chrome monoculture.
But if you are willing to fork Firefox, that's a very good reason. I just don't think any fork will be as long as the majority of users are on a chromium based browser, those are toxic to the ecosystem.
Who said I do, I often have multiple months between every time I use a Chrome or Chrome based browser.
Edit, I use a multipronged approach:
- I use only Firefox - except once in a blue moon to verify if something is an actual Firefox bug or a general bug.
- and develop in Firefox. Bonus: Without testing in any other browsers most weeks I can count on one finger the times I have introduced cross browser defects
- I raise awareness that Mozilla is extracting money from Firefox, not funding it.
- I raise awareness about how Google is pushing to kill competition in the browser markets (besides here on HN and contacting authorities myself I have also urged a grumpy colleague today to contact relevant competition authorities)
- I rise awareness about the likely outcome of a Chrome monoculture: mostly that ad blocking will disappear, the web as a platform will stagnate and we will have to live with more nasty restrictions.
For me it would be Edge that gets the most laughs but I find is a better performing browser, at least in terms of UI than FF or Chrome. Side-bar tasks, grouping, integrated screen-shot, etc.
Damn that is an offensively small amount - less than the cost of a Google engineer for a days work.
And after all that, all it can do is run a search query. It can't leak all your Gmail emails or exploit the local machine.
Doesn't that contradict the following?
> “However, because the IPC channel was exposed to JS directly in New Tab page, the XSS in Chrome’s NTP can be treated as the equivalent of renderer process RCE.”
And the New Tab Page doesn't even have permissions to do much via that IPC channel, because its origin isn't equal to anything interesting.
Google, shame on you.
Well... I don't know. Does anyone have to be a domain expert to say that security reporting that affects tens or hundreds of million of people should be compensated better than 1k USD?
I dislike a bit the "justified" argument, as very often it dismisses important weak signal warnings. Our work in Security is often about being sensitive and not dismissal. But here you go:
I'm infosec since 1987 (34 years) and never left it, so I'll let you decide ;-) even if i'm a dinosaur in Internet times ;-)
Q: What do you think would be a fair amount ?
IMHO, the fair amount is definitely in the tens of thousands.
But we could attempt a quantified approach, always debatable (Risk = Likelihood * Consequence), eg. Likelihood based on fishing campaign success per country or global, and then mean / average cost of theft when leveraging the full exploit chain (IPC included), i.e. cookies -> auth -> leveraged identity theft impact. And then give percentage of cost as an bounty-based "insurance" mechanism. Not easy but attempt could be done. Surely that would result in way higher compensation.