If Chromium is the most secure browser engine, how come the most secure browsers don't use it?

Thinking mostly of Tor browser and Mullvad Browser.

They are not.

Privacy, anonymity, and security are three different things.

6 Likes

So what is the “most secure” browser?

Vanadium

5 Likes

depends on what you mean by secure and the OS you are using.

Based on our security bros on PG. :melting_face::+1:

GrapheneOS → Vanadium
Other Androids → Probably Brave
IOS → Safari
Fedora and Secureblue → Trivalent
Other Linux distros - > Probably Brave Origin
Whonix and Tails → Tor Browser
QubesOS → Depends
Windows idk
MacOS → I guess Safari but idk

I guess? But for me personally, security isn’t the most important thing for a browser as long as the browser has good enough security and keeps up with updates, you will be fine.

4 Likes

Because of all the bad press Chrome has received lately, I would have presumed Firefox derivatives like floorp, librewolf etc. to be safer choices for linux distros than Chrome based ones like Brave (even if it’s the Origin variant). Is that presumption invalid?

It’s nice to see some browsers mentioned here that I hadn’t even heard of. I’ll see what they’re all about.

1 Like

As a casual LibreWolf enjoyer, I approve. :grinning_face_with_smiling_eyes: LibreWolf has been my go to set and forget browser for Linux for the last few years.

2 Likes

Because when Tor Browser was first created Chromium wasn’t even a thing.

I’d imagine if they released it today, it would be a Chromium-based browser.

Mullvad Browser is basically just Tor Browser without the Tor so it’s “easy” releasing it automatically using GitHub Actions.

2 Likes

Going for security Edge might be the best. As it has the same benefit as Safari on iOS, Vanadium on GrapheneOS and Trivalent on SecureBlue: OS integration

It works with Microsoft Defender and has other security features Microsoft Edge and Microsoft Defender Application Guard | Microsoft Learn

But if I used Windows I’d go for Brave

Otherwise I agree

Question, wouldn’t be Brave better on iOS too as both use the same rendering engine there thus the same OS security integration?

3 Likes

Why wouldn’t these be Chrome for MacOS, Whonix, and Tails, Trivalent on Qubes and Edge on Windows?

Idk if trivalent works on Whonix and Tails but I remember hearing it works on fedora which you can use on Qubes afaik.

I’m also trying to separate engine security from the browser’s hardening and default privacy settings here. The distinction between Chromium’s upstream security model and the more opinionated configurations used by Tor and Mullvad makes the comparison less straightforward, so I’m following the concrete examples in this thread.

If you use browser in disposable qube in QubesOS then any browser is secure…

Becasue Whonix and Tails is purpose built distros and is designed to add features and security to Tor. Brave would just add fingerprint and attack surface, and you will stand out from the crowd. you will defeating the whole purpose of using Tor/Whonix and Tails.

If you want to use “Whonix” with Brave for whatever reason use Kicksecure they even have a installer for it.

For MacOS, you may be right, I have no idea. I have never really looked into MacOS, I’m just guessing they would have some OS hardening that only works on Safari, like Edge does on Windows. Idk.

Even if you installed Trivalent, you would be better off using Brave because they are based on Debian and use AppArmor. What makes Trivalent better than Brave on Fedora “for security” is mainly the SELinux policy they added to Trivalent. And would probably only work on Fedora based distros with SELinux.

I guess for Fedora templates, but it would depend on the template and what you’re trying to achieve, and Trivalent wouldn’t matter that much for Qubes security, to be honest.

To the rest of your system but you get defense in depth from a secure browser.

1 Like

If by safe you mean secure, then I’d say your presumption is invalid. Chromium is still far ahead of other browser engines interms of security. IMO, considering how much everyone relies on browsers, and the amount of vulnerabilities constantly being discovered, I think security is more important than privacy in this domain.

I used librewolf and hardened Firefox for years, loved both. Then I learned about the their weaknesses compared to chromium and made the switch to brave origin. Besides some UI/UX differences the experience is the same. In terms of privacy it’s no different. Mv2 is gone for good reason, and honestly it’s not needed. uBlite works just as good and is a hell of a lot more secure. And if we talk about fingerprinting, well if you’re not on Tor or stock Google chrome then your fingerprint is unique no matter what and no amount of “tracking protection” is going to aid you in actually preventing data brockers from building and maintaining a profile on you.

Block the ads, scams and malware. That’s what matters to me.

Edit: I mentioned stock Google chrome next to Tor because its my assumption that millions upon millions of people are using stock chrome, that assumption would lead me to think all those millions of people have a similar fingerprint after accounting for the device specific/timezone metrics. But I’ve never run a fingerprint test on that browser to verify.

2 Likes

The only real thing people are missing from uBlock Origin that I can tell is custom filters, or rather as powerful of custom filters because you can still use them it just has to be in a more specific way.

If you’re using Brave though there is no reason to be adding uBlock Origin Lite though. It’s more attack surface and Brave’s should be even safer since it’s memory safe. Brave also has custom filters the same as uBlock Origin.

Honestly I’ve been meaning to switch over from Librewolf, but I’ve been waiting on them adding scrollable tabs back to the horizontal tabstrip. I do honestly love Librewolf, it’s a great project and any1here is a pretty cool person, but it’s (at least in terms of security) unfortunately Firefox.

2 Likes

Well that’s nonsense. Definitely having better tracking protection is going to aid in preventing data brokers from effectively tracking you. It won’t be 100% but it will help!

To be honest, for some days I’ve tested fingerprinting because I’ve tested Donut Browser when it started (and was free and you could change any parameters of fingerprint).

IMHO, browser ID and system ID is only part of fingerprint.
Whatever you use unike browser or common browser and you stand out is a matter for a people who opose governments.
For corporations and advertisers, it just few additional data which could profile you better (they won’t advertise you Outlook 365 if you have linux id) but for tracking you, fingerprint must be consistent and repeatedly used every time.

Somewhat related to the security question, I have to be honest, nowadays I’m having a hard time to fit Mullvad browser to my workflow.