Chrome is so RAM heavy, its horrendous. So, I’m glad you’re going to switch and try better options.
I just downloaded and installed Helium. First impressions: It’s really nice and I am liking the look and feel of it! I can’t wait for it to be finished and be out of beta.
Beta is why I don’t suggest making it your primary browser. I also wish it had auto delete history, cookies, and site data (with exceptions if you want) but it doesn’t.
But otherwise it’s super clean and just works. No frills browser.
Kinda strange to have a “private” “secure” browser available only as AppImage on Linux? Would be cool to try this, but I’m not running a browser as an AppImage.
Why not? AppImages are especially made that way that you can sandbox all of them (e. g. FireJail), although this is not necessary for average people / threat models, so it‘s in my opinion a good decision since sandboxing costs performance.
If that works for you great.
Personally, most of the sensitive data on my computer goes through my browser. I’m not using a browser that relies on outdated, unmaintained libraries (fuse2), requires manual setup of sandboxing, and doesn’t update automatically. This is so far below the security of so many other options available. Just…no.
Unaccurate: fuse2 being maintained depends on the GNU/Linux distro. I personally use and love Void GNU/Linux (because it is [censored] systemd-free) which continues support for fuse2, so in that aspect it can be private and/or secure on GNU/Linux which was the only point from you I was challenging.
Again:
helium.computer, official homepage of the helium browser:
Helium updates itself automatically on macOS, with auto-updating options available on Linux and Windows.
Also you can use a script for auto-updating which again means that it can be private and/or secure on GNU/Linux in that aspect which was the only point from you I was challenging.
I cannot get past a lot of major concerns here. Regardless of it being a fresh face, it’s an Ungoogled Chromium fork that will never support Widevine and will eventually break once MV2 is no longer hanging on by life support, and they will not have a solution to that.
But the real issue is the chain of custody. We are trusting a browser, one of our most precious assets, maintained by two developers fresh out of high school, Russian based hiding behind a Wyoming LLC. That implies a level of obfuscation that makes me uncomfortable, especially combined with the concerning rhetoric, and some of the, how can I put this….. some very interesting takes from one of the developers on social media. This is a hard pass.
Developers don’t deserve privacy? Oh, or should he tell more about himself, living in Russia, so the authorities can find him and send him straight to prison for “LGBT propaganda”?
Why are you saying that and not providing any sources? Or was that meant as “trust me, bro”?
I appreciate your reply!
I’m thinking something similar with beta apps and beta web browsers in particular: They may not be a good choice because the beta app developers want user data/user telemetry so user privacy may be a 2nd priority…? ![]()
Was looking into this browser, what exactly is the big issue with supporting Manifest v2? Is it just that some extensions can end up being sketchy? Firefox supports it too right?
I don’t think that’s what he meant…
I personally wouldn’t recommend a browser maintained by two young dudes with not that much experience. I don’t care that much about them being Russian, but I understand that to some that may be a concern.
Well, he criticized Brave for making a paid browser. Seems a bit hypocritical to me since Helium relies on some of the Brave browser patches to function/improve privacy protections.
He also posts some questionable stuff from time to time, but this is completely subjective though and I understand that not everyone sees it the same way.
For better, or for worse, Helium Browser kind of reminds me of Thoruim Browser and all of the various baggage that went along with it.
MV2 on Chromium has hit its end of life. It’s like sticking with Windows 10, the system isn’t going to get updated anymore, and anyone who still has it enabled on Chromium is essentially just running obsolete software that gets more outdated by the day.
As for Mozilla, they can afford to keep maintaining it because they actually have the money, the infrastructure, and the manpower to do so, not to mention that Gecko is a completely different engine anyway.
I know someone from the brave team had mentioned before that they have some of the extensions hosted on another server for whenever they’re deleted, and maintaining it for right now is pretty much a full time job and they’ve been encouraging people to move away from it.
Specifically Brave currently still supports the MV2 versions of UblockOrigin along with NoScript, AdGuard, and uMatrix but no others.
- see: https://github.com/brave/brave-browser/issues/46915
- and brave://settings/extensions/v2 (in Brave browser settings) for reference.
I see, I did not realize brave only maintains specific v2 extensions. Are the security issues with MV2 in the long run negligible if the user does not actually install any extenstions or can they pose a risk even without extension installs? The only extension I really care about is uBlock Origin personally so I don’t know what else people need MV2 for
Leaving that in is just going to expand the attack surface as time goes on. There’s even a lot of speculation right now about Firefox’s next move is, given that they’re supposedly integrating Brave’s built in system for future testing. Brave’s adblocker bypasses the MV2 nightmare without causing headaches, which I’m pretty sure Waterfox has already figured out and implemented it as well.
It’s tough to predict the future, and over speculating is mostly a waste of time. But, my gut tells me a lot of these smaller forks will eventually have to take the L, swallow their pride, bend the knee, and kiss the ring, because Brave’s engine is incredibly effective as a plug and play solution to a massive industry problem of MV2 adblocking dying.
That’s what he meant.
And what kind of experience are they supposed to have? Like, having 100 years of experience shoving “brave” bloatware into a browser? They are the cobalt developers, and right now they’re doing a pretty good job with an entire browser.
And how did you even connect one with the other? Does the license require payment for use or does it forbid using their code?
That’s what he meant.
That’s not what I meant.
Is there evidence that enabling the workarounds to keep MV2 extensions alive in Chromium actually present a security risk or is that speculation?
I wouldn’t recommend people willy-nilly installing MV2 extensions left and right, but enabling the shortcut “hack” to keep uBO available seems pretty low risk.
Is it something “Grandma Smith” should do? No, stick with uBOL, but it seems slightly fear mongering with no evidence to imply that keeping it enabled also opens one up to significant security risks. Especially when the people enabling the existing “hacks” to keep uBO active are likely more advanced users anyway that might be less likely to fall for the security pitfalls a casual user might go into.
