Is Pale Moon Safe?

Users and developers helping users with generic and technical Pale Moon issues on all operating systems.

Moderator: trava90

Forum rules
This board is for technical/general usage questions and troubleshooting for the Pale Moon browser only.
Technical issues and questions not related to the Pale Moon browser should be posted in other boards!
Please keep off-topic and general discussion out of this board, thank you!
vannilla
Moon Magic practitioner
Moon Magic practitioner
Posts: 2190
Joined: 2018-05-05, 13:29

Re: Is Pale Moon Safe?

Unread post by vannilla » 2021-04-02, 21:09

Keirnoth wrote:
2021-04-02, 20:29
If you want an example of why you should use Pale Moon as your daily driver - I vaguely remember that that there was a huge security exploit that affected FF, Chrome, and what was then Internet Explorer, but PM was already hardened against it because of their proactive dev cycle. I'm trying to remember what the exploit is but I believe it was in the news either last year or the year before then and I remember going directly to the PM frontpage to see an announcement about it and the devs proudly stating that they already took care of it a long time ago.
If it's the one I'm thinking about, it was about malicious actors exploiting high-precision clocks to get access to another (and unrelated to the browser) exploit.
At the time when this usage of the clocks was discovered, Pale Moon (because if I remember correctly, UXP was still to be released, but don't quote me on that) had its high-precision clocks made less fine-grained, so that they could still provide the requested details compared to normal clocks, but they were not so precise as to allow for the exploit to take place (as timing-based attacks rely on nanoseconds and it can take very little to stop them.)
But that was the most famous: there were a few others in which other browsers ended up removing features or hard-code some value (instead of allowing a configuration flag), while Pale Moon (or UXP in general) just carried on unaffected as it was already protected, either from defenses being added already, or because the exploit simply relied on behaviours that the application doesn't have.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35597
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Is Pale Moon Safe?

Unread post by Moonchild » 2021-04-02, 21:12

Keirnoth wrote:
2021-04-02, 20:29
Pale Moon looks like older FF, but the Pale Moon devs follow and implement security fixes from the ESR.
Incorrect. What happens is that every release cycle of Firefox i contact Mozilla Security and request access to every security bug addressed in the latest versions of Firefox (both release and ESR) and evaluate what is applicable, and either port or write patches to address security issues (many are definse-in-0depth by now and not exploitable).
You still after 10 years seem to assume we are following Firefox/Firefox ESR in our code development. We are not.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

Locked