Hacker News new | past | comments | ask | show | jobs | submit login

I cannot fathom how a browser/WebView from 7 months ago with 244 known security issues including multiple zero-days and a PDF reader from 6 years ago with 55 known security issues is in anyone's threat model.

Do realize that combined with their Advanced Privacy app which routes users over Tor, it can very well result in HTTP only connections being MiTM'ed.

I've seen it with some of my own users recently and their RSS feeds being hijacked.

I ask /e/ team every month to do something about it and they don't, yet users keep trumpeting them and buying devices from them. It is downright negligent of them.




> I cannot fathom how a browser/WebView from 7 months ago with 244 known security issues including multiple zero-days and a PDF reader from 6 years ago with 55 known security issues is in anyone's threat model.

I use Firefox, not their chromium-based browser. I can't mention an app that I use that is using a WebView though... I remember there was one, but I could set it up to use my browser. I use their PDF reader, I'll have to check that.

> Do realize that combined with their Advanced Privacy app which routes users over Tor, it can very well result in HTTP only connections being MiTM'ed.

I don't route over Tor.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: