My browser recommendation, if you’re looking for something that’s open source and pretty competent, it’s a fork of Firefox with some pretty unique functionality.

    • Kissaki@programming.dev
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 hours ago

      The attack surface is the flaw. The chain of trust is the flaw/risk.

      Who’s behind the project? Who has control? How’s the release handled? What are the risks and vulnerabilities of the entirely product delivery?

      It’s much more obvious and established/vetted with Mozilla. With any other fork product, you first have to evaluate it yourself.

    • CameronDev@programming.dev
      link
      fedilink
      arrow-up
      2
      ·
      8 hours ago

      No, this is (to my knowledge anyway) a theoretical problem. But it is very much a real risk, as demonstrated by the xz backdoor.

      We should be very careful who we trust, especially for browsers, because a compromise could be catastrophic.