1063
submitted 10 months ago by corbin@infosec.pub to c/technology@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[-] DontTreadOnBigfoot@lemmy.world 306 points 10 months ago* (last edited 10 months ago)

Holy shit.

I thought this was just going to be a matter of poor security implementation or crappy feature sets.

Turns out they converted the company into a loan shark operation owned by Chinese ad companies

when the Opera browser continued losing users (due to competition from Google and Apple), the company shifted gears to building mobile apps that provided predatory short-term loans. The interest rates on those loans ranged from 365-876% per year, and loan terms from 7-29 days.

[-] dual_sport_dork@lemmy.world 160 points 10 months ago

This behavior is just beyond batshit. Before anyone decides tl;dr, the article is well worth a read.

I had a hunch that Opera was circling the drain when I started seeing them sponsor Youtubers. A general rule of thumb is that no company that has anything worth a shit devolves to sponsoring Youtube videos. I had no idea about the predatory loans thing, or the crypto scam chasing thing, or the ripping off ChatGPT thing...

Back here in reality, there is no reason anyone should be using any other browser than Firefox. There is one organization left in this arena still devoted to protecting privacy, maintaining open standards, and a fair and open web for all. And it ain't Google, it ain't Microsoft, and it ain't Opera.

[-] fartsparkles@sh.itjust.works 77 points 10 months ago

And it’s always been Firefox since day one. Out of the ashes of Netscape Navigator rose Firefox and Mozilla have been one of the only bastions of the free and open web ever since. I honestly don’t understand why anyone would use another browser.

[-] dual_sport_dork@lemmy.world 17 points 10 months ago

Fear of change and effective marketing. Those are the only reasons.

[-] TheBananaKing@lemmy.world 2 points 10 months ago

Actually it's an effective cloud-based password manager that doesn't rely on local storage or weird plugins or backups.

That's what keeps me using chrome. I could lose everything in a house fire, pick up any device, log in and have access to all my stuff without any further action on my part, right out of the box.

That's the only feature I care about, and chrome is the only browser I've seen that provides it.

Get me that in firefox, and I'll switch today.

[-] Maven@lemmy.sdf.org 68 points 10 months ago* (last edited 10 months ago)

What are you talking about? Firefox has had literally Sync since before Chrome existed.

Firefox Sync initial release: December 21, 2007

Google Chrome intial release: September 2, 2008 (Beta), (1.0) December 11, 2008

A full year, my guy.

[-] Deebster@programming.dev 40 points 10 months ago* (last edited 10 months ago)

I'm confused since Firefox Sync has been letting you sync/backup your passwords, bookmarks and history for a decade or two at this point, and you can even self-host the sync server.

I don't know the complete FF password manager details (Bitwarden user here) but where does Firefox fall short for you?

[-] mystik@lemmy.world 27 points 10 months ago

You can lose your Google account in the blink of an eye with no recourse, no access to support or anything.

With local and my own backups, I can choose to put them at any location, cloud or local.

[-] Swaziboy@lemmy.world 23 points 10 months ago

I have all that functionality today with FF... Not sure when you last checked, but if you create a Mozilla account and log in to FF you can sync all the same stuff as Chrome does.

[-] TheBananaKing@lemmy.world 2 points 10 months ago

Checked it out: apparently I had a mozilla account at one point in time. Hit 'forgot password':

Note: When you reset your password, you reset your account. You may lose some of your personal information (including history, bookmarks, and passwords). That’s because we encrypt your data with your password to protect your privacy.

Forgot your password: fuck you.

This is the exact fucking opposite of the behaviour I'd ever want from a password manager.

[-] feannag@lemmy.ml 29 points 10 months ago

I think that's what most people want in a password manager. The only way to have a truly secure pw manager is to encrypt it and failsafe to delete. That way if your identity gets stolen or email compromised, it limits the damage.

[-] ilmagico@lemmy.world 7 points 10 months ago

Said another way: if a company offering a password manager can recover all your passwords with you just clicking "forgot password", that means they can read your passwords in plain text (and so can hackers if the company gets hacked).

[-] Passerby6497@lemmy.world 4 points 10 months ago

Forgot your password: fuck you.

This is the exact fucking opposite of the behaviour I’d ever want from a password manager.

Wait wait wait wait, you're telling me you want the people who hold your password to be able to view them without your explicit permission (entering a secret that unlocks your vault)? Because that's what you're asking for - if they can reset your password and provide you your plaintext passwords, that means they can 1) read your passwords if they chose to and 2) you can be phished and have your account stolen and passwords provided to some rando.

The convenience offered by that "feature" is outweighed by the potential consequences of it existing. Passwords should absolutely be a Trust No One (TNO) solution.

[-] TheBananaKing@lemmy.world 1 points 10 months ago

Pretty much every service on the internet does password-reset via a token sent to your mailbox, so if someone gets control of your mail, you're pretty much pwned anyway. It would be slower and more inconvenient for an attacker to reset everything individually, but I'm sure they can automate that.

This is just security theatre. Burning all my data makes my life a lot harder, but an attacker would barely notice.

If I can reset each individual credential via mail token, on the assumption that only the genuine owner has access to the mailbox, then I lose nothing by resetting access to the whole set of credentials via mail token, on that same assumption.

[-] Passerby6497@lemmy.world 2 points 10 months ago* (last edited 10 months ago)

It's only security theater because you have this kind of mentality:

It would be slower and more inconvenient for an attacker to reset everything individually, but I'm sure they can automate that.

then I lose nothing by resetting access to the whole set of credentials via mail token, on that same assumption.

You're right that an attacker could reset everything if they had access to your primary email account, but 1) you should already have 2fa on that account to protect yourself, 2) losing access to your email would be a signal that something is wrong and gives you a chance to react before they have everything, and 3) there's a world of difference between having credentials immediately vs having to jump through hoops to reset stuff. Also:

Burning all my data makes my life a lot harder, but an attacker would barely notice.

Burning all your data means your attacker can't suddenly transfer the contents of your checking account away or buy all kinds of shit from trusted vendors just because they broke into one account. Security is about layered defense, not just giving the attacker keys to the kingdom because you couldn't remember one password.

[-] mypasswordistaco@iusearchlinux.fyi 7 points 10 months ago

Looks like you best get to switching.

[-] dasJot@feddit.de 7 points 10 months ago

That’s great until Google finds that one picture of your child at the pool and immediately deletes your CSAM-harboring filthy account.

[-] TORFdot0@lemmy.world 8 points 10 months ago

Sadly chromium is often the only supported browser for a lot of web apps. Sometimes not even chromium but just chrome in particular. Chrome has basically inherited all the downsides of internet explorer of yesteryear except it doesn’t run like shit yet.

[-] lobster@sh.itjust.works 15 points 10 months ago

I wonder if it’s really a lack of support and not just a user agent string check for lazy development.

[-] A_Random_Idiot@lemmy.world 5 points 10 months ago* (last edited 10 months ago)

and google sabotaging shit so it only works on their platform.

Like they did with youtube and Edge (before they finally gave in to googles terrorism and switched edge to chrome base)

like they are doing with youtube and adblockers.

[-] Wermhatswormhat@lemmy.world 3 points 10 months ago

I’ll say this. I use chrome and I KNOW I need to switch to Mozilla. It’s just such a pain to switch that I inevitably go back. Maybe this is the wake up call I need.

[-] hoshikarakitaridia@sh.itjust.works 20 points 10 months ago

I do not agree with your generalisation of YouTube sponsorships, but with the rest I absolutely agree with.

Honestly, I read something about Opera being vaguely connected to shady Chinese companies right before I started recommending ppl to switch away from Opera or Opera GX. Glad I stuck to that, looks like my intuition did not fail me.

[-] dual_sport_dork@lemmy.world 8 points 10 months ago

You, uh, really feel that the likes of Raid: Shadow Legends, Nord VPN, Honey by PayPal, Raycons, and HelloFresh are really making a positive contribution to the world that we can't do without?

[-] Syrc@lemmy.world 2 points 10 months ago

I mean, what’s the problem with NordVPN? Pretty much every youtuber I respect who does sponsorship promotes it, and I’ve never heard anything bad about it. Generalizing like that is always bad (or well, mostly always, or ironically I would be generalizing).

[-] obbelusk@lemmy.world 1 points 10 months ago

I think there might be a few exceptions, but generally it's just loot boxes and predatory games.

[-] Engywuck@lemm.ee 5 points 10 months ago* (last edited 10 months ago)

there is no reason anyone should be using any other browser than Firefox.

Yeah. And everybody should use the same brand of shoes, drive the same model of car, buy at the same store, eat the same food...

God forbids people having different tastes, opinions and needs.

There is one organization left in this arena still devoted to protecting privacy, maintaining open standards, and a fair and open web for all. And it ain’t Google, it ain’t Microsoft, and it ain’t Opera.

Yeah, and it's not Mozilla either.

[-] fernandofig@reddthat.com 6 points 10 months ago* (last edited 10 months ago)

Yeah, and it's not Mozilla either.

Which one do you think it is, then? Genuinely curious here. I don't disagree with on most of what you said - I find the simping for Mozilla (and sneering towards chromium) here in Lemmy rather annoying. Mozilla and its browser both have shortcomings as well, and choosing a web browser these days is, as most things in life, choosing the lesser of evils vs. one's own needs.

[-] Engywuck@lemm.ee 3 points 10 months ago* (last edited 10 months ago)

Which one do you think it is, then? Genuinely curious here.

I simply don't assume that an org/com actually exist which is concerned users' privacy. Mozilla just follows the money, as any other corp.

Protecting my privacy is a task I prefer to delegate to mybrain(.org).

[-] fernandofig@reddthat.com 2 points 10 months ago

Good. We think alike 👍

[-] Zerlyna@lemmy.world 37 points 10 months ago
[-] takeda@lemmy.world 24 points 10 months ago

Yeah, I was a huge fan but the moment they changed the engine it was just Chrome in different skin. And later the news that they were bought by a Chinese firm doing shady stuff just confirmed that it was the right decision.

I am sad that they did not open source the engine. Somebody leaked it, but no one serious would touch it for legal reasons.

this post was submitted on 24 Jan 2024
1063 points (100.0% liked)

Technology

59598 readers
2588 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS