Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
csagan5
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
csagan5
6y ago
/e/ uses all of Bromite's patches as well; I asked them to mention this in the About section, since it is basically a rebranded Bromite that they are shipping.
2.
▲
by
csagan5
6y ago
ungoogled-chromium[1] and Bromite[2] have had a patch to disable this for a while now [1] https://github.com/Eloston/ungoogled-chromium/blob/14fb2b0/p... [2] https://github.com/bromite&#x
3.
▲
by
csagan5
6y ago
Nobody can uncritically take his side but what you are implying here is that we should consider him "less" because of an unrelated story.
4.
▲
by
csagan5
6y ago
In Chromium it might not be blocked just because of an oversight (or because there was no consensus), see my other comment (and its parent): https://news.ycombinator.com/item?id=23253264
5.
▲
by
csagan5
6y ago
Interestingly enough they are already blocking these attacks for background requests, see https://github.com/chromium/chromium/blob/83.0.4103.53/third... Perhaps they simply forgot to cover also the WebS
6.
▲
by
csagan5
6y ago
Exactly, port scans on my public IP address are not an attack, but crossing the boundary to my localhost and private networks is malicious behavior.
7.
▲
by
csagan5
6y ago
There is an open Chromium bug for this: https://bugs.chromium.org/p/chromium/issues/detail?id=378566 I hope they consider it still valid and not close it. These are the blocked ports: https://githu
8.
▲
by
csagan5
6y ago
That's a good approach; the other alternative is to use F-Droid client, but it comes with its own bugs. https://www.bromite.org/fdroid
9.
▲
Bromite v83 Released
(bromite.org)
4 points
by
csagan5
6y ago
|
4 comments
10.
▲
by
csagan5
6y ago
> About security fixes, yes, between end of 2019 and today, new problems emerged in Chromium (not specific to Kiwi though), and there is some work to backport. Should it have been done earlier ? Certainly. I am talking about telling user
11.
▲
by
csagan5
6y ago
You have not answered to the user's concern whether his browser is up to date with all the security fixes found in Chromium after v77.
12.
▲
by
csagan5
6y ago
I did not mention Bromite at all, what are you talking about? There is no FUD here, let me write down some facts for you: * users install Kiwi which does not contain all the security fixes of upstream stable Chromium (v81); this is been goi
13.
▲
by
csagan5
6y ago
Kiwi: it is severely outdated and you installed it before it was open source.
14.
▲
by
csagan5
6y ago
And you trust instead a closed-source browser which has not been updated in months? Aside from the trust component I suggest you to use an up-to-date browser because of the security vulnerabilities which affect them.
15.
▲
by
csagan5
6y ago
Since there is no commit history I would also like to know which Chromium version this is based on, so that a diff can be made.
16.
▲
by
csagan5
6y ago
It had a GitHub repo ( https://github.com/kiwibrowser/android ) described as "source code used in Kiwi", but it was just a Chromium codebase thrown there without the actual patches. Glad to see it's open s
17.
▲
by
csagan5
7y ago
It is not and has never been, see https://github.com/kiwibrowser/android/issues/12#issuecommen...
18.
▲
by
csagan5
7y ago
It could be argued that a similar violation is present (since March 2019) in Chromium for the Widevine CDM provisioning request, see https://github.com/bromite/bromite/issues/471 Basically all users opening t
19.
▲
by
csagan5
7y ago
The poster is the author of Kiwi browser, which unfortunately is closed source [0], but I have reason to believe he is familiar - as I am for the Bromite project - with all the (sometimes shady) internals of the Chromium codebase; it is ind
20.
▲
by
csagan5
7y ago
Credits to the ungoogled-chromium project [0] for the patch [1] which is also used in Bromite since 15 February 2018 to prevent this type of leaks; see also my reply here: [2] [0]: https://github.com/Eloston/ungoogled-c
21.
▲
by
csagan5
7y ago
Edit: the article has been kindly edited, thanks to the author
22.
▲
by
csagan5
7y ago
> /e/ has modified the source code of various parts of AOSP and Chromium web browser to stop informing Google (and the NSA as a consequence of CLOUD Act) of user activity. The article is incorrect also about the browser: it is
23.
▲
by
csagan5
7y ago
Yes, there have been some issues reliability with the host; they should be solved now, see also: https://github.com/bromite/bromite/issues/378
24.
▲
by
csagan5
7y ago
> They did add a reference to the original project to the AUTHORS file, so I'd like to believe in a variation of Hanlon's razor: Never attribute to malice that which is adequately explained by laziness. This would be all fine a
25.
▲
by
csagan5
7y ago
By the way, Bromite itself is mostly a curated, maintained and adapted (for Android) list of patches from other projects, plus a good chunk of patches developed by me for Bromite itself. I keep correct attribution of all patches as much as
26.
▲
by
csagan5
7y ago
See https://github.com/bromite/bromite/blob/master/README.md
27.
▲
by
csagan5
7y ago
Yes, I am aware of the repository. > Have you already asked them to add a reference to Bromite somewhere in the about screen? I have not; I was expecting it, given the amount of modifications from Bromite patches (which is zero, as far a
28.
▲
by
csagan5
7y ago
You're welcome :)
29.
▲
by
csagan5
7y ago
Thanks, fixed that by adding a space.
30.
▲
by
csagan5
7y ago
There is also https://grapheneos.org but I haven't tried it myself yet; I have spoken with the author a few times and it looks like an interesting project.
More ›