Fifth Browser
github.com
github.com
(Though it does include a gratuitous and poorly-executed 3.3MB animated GIF of 43 words: “Who should control your web? / Not the advertisers / Not even the site designer / You // Browsers should / stay out of your way / avoid change for change's sake / not copy Chrome just because // Avoid monitoring / Web for sites, not apps / Stay lean // Fifth / Join us”.)
Last release almost six years ago.
Last commits pulled in on November 8, 2020.[0]
> CAs are ignored, the only thing that matters is that the cert does not change. With today's rogue CAs and governments, this policy is better suited for detecting man-in-the-middle attacks than a browser blindly trusting a CA.
I'm not sure this is a good idea. SSH best practice is that you acquire the server's key fingerprints via a previous secure channel. E.g., Hetzner will email them to you when they set up your server.
-Attest a CA for initial connection
-Alert on change, include CA details, with option to (not) override cache
Will this browser make it into EPEL?
Even for a TOFU implementation of SSL, this repository is amazingly bad.
[1] Yes, those site names are hardcoded. By server name. So anyone could MITM google here. Or cdnjs.cloudfare.com.
email != secure channel
I wouldn't want to bet my web experience on a browser maintained by a small team of volunteers diverging from a known engine. Seems like it would be easy to end up in a state where modern features are unavailable or security vulnerabilities are unpatched, because some dude on the Internet prioritized his own life over being the maintenance guy for your browser.
Until then these browsers will be just nice toys for random browsing, but dangerous for more sensitive things like banking or buying things online.
Wouldn't it be the other way around? I personally am more afraid of some random site exploiting an vulnerability on me than my banking site exploiting a vulnerability on me.
OTOH a number of sensitive things, such as TLS certificate handling, or custom extensions, is external to WebKit, and may be exploitable.
The chances an exploit would be developed especially for a narrow-niche browser like Fifth are pretty slim, though. Some security through utter obscurity.
And on official site there is "Propaganda" page with comparison to other browsers.[1]
[0] https://www.phoronix.com/scan.php?page=news_item&px=MTg0MDk
I tend to build a lot of programs from source code and those that use autotools are always the most frictionless, especially since i like to put things in their own directories (so that i can easily remove them) instead of installing them globally.
From a developer's perspective, i tried to use autotools at some point and i really wish there was a real replacement that provides all the features autotools have (including not requiring to have that replacement installed, like cmake, meson, etc do) while being a bit more user friendly.