this post was submitted on 27 Dec 2025
9 points (84.6% liked)

Browsers

2167 readers
1 users here now

About Community

This is the community to discuss about browsers.

Browsers List

Open Source browsers

Closed Source browsers

List will be updated

founded 5 years ago
MODERATORS
 

Hello. I am a Firefox user, and everyone I know tells me that using Firefox on Android is not secure. What are they basing this claim on? I have tried using Chrome, but I always go back to Firefox because it is the only open-source browser that allows me to pin favourites to the home page and because the display of websites adapts very well to the chosen size. Which FOSS browser derived from Chromium allows you to choose your favourite websites on the home page?

you are viewing a single comment's thread
view the rest of the comments
[โ€“] boredsquirrel@slrpnk.net 7 points 1 month ago* (last edited 1 month ago) (1 children)

Content Isolation

Firefox lacks support for a fork server that can deduplicate memory when using different sandboxing mechanisms, not controlled by firefox.

On Android, the Zygote is the process spawning subprocesses, and it is used for app sandboxing and browser sandboxing. It deals with deduplicating memory so apps can share the same resources even though they are isolated.

On Linux with Flatpak you have a similar scenario, while the Flatpak sandbox is way less low level compared to the Android sandbox (Android uses SELinux and unix users, Flatpak uses user namespaces).

Firefox now started to work on it. If you use Ironfox, there is a setting where you can enable content isolation and zygote usage, and so far it "just works" for me! So it seems they are working on a fork server.

There was an announcement, and there are bugzilla issues on this matter.

So yes, currently on Android a Chromium based Browser (that actually uses the whole capabilities of Chromium on Android, which some browsers that just use the Webview may not) is still more secure, as it neatly integrates with the zygote and UUID sandbox native to Android.

But Firefox is closing in. I daily drive Ironfox and recommend donating to the project.

Content Filtering

Keep in mind that Firefox has UBlock Origin and thus access to very powerful content filtering.

While blocklist-based filtering is natively integrated in Brave, Cromite and Vanadium too, this is generally a bad approach as it follows "badness enumeration". It lists all the bad things and the moment a new thing appears, you are ๐Ÿฆ†ed.

But it does not require any user tweaking and can thus be implemented easily without the need to actually offer user control (apart from an on/off switch maybe).

UBlockOrigin allows to use the "expert mode" where you can disable everything by default. Then you allow content per domain, for this site only or globally. It lacks the "content type header" filtering of NoScript (like Images, CSS, Javascript), but both together are very slow, and uMatrix (which combined them) is dead with no actively maintained forks (sadly).

It looks like this:

This allows to easily prevent malicious code from running at all. If you dont make mistakes, this could eliminate the need for any sandbox (but as you have to allow all sorts of shit or the horrendous modern web doesnt work, you need one anyways).

[โ€“] Maragato@lemmy.world 2 points 1 month ago (1 children)

Thank you for such a detailed reply. Is Ironfox similar to Fennec in terms of security and privacy?

[โ€“] boredsquirrel@slrpnk.net 3 points 1 month ago* (last edited 1 month ago)

Fennec is slightly behind Firefox versions, Ironfox is also downstream so a bit behind but not as much.

Ironfox has a ton of security and privacy hardening, as well as interface changes so users can do a lot of things themselves. Fennec just has a few incomplete telemitry changes.

I do not recommend Fennec at all, unless people are too "technologically challenged" to tweak a few things, as some hardening like blocking JIT breaks a few websites