Scheduled Maintenance: We are aware of an issue with Google, AOL, and Yahoo services as email providers which are blocking new registrations. We are trying to fix the issue and we have several internal and external support tickets in process to resolve the issue. Please see: viewtopic.php?t=158230

 

 

 

[solved]Gnome Epiphany secure enought for daily use

Graphical Environments, Managers, Multimedia & Desktop questions.
Post Reply
Message
Author
Heliosstyx
Posts: 29
Joined: 2019-10-26 09:52

[solved]Gnome Epiphany secure enought for daily use

#1 Post by Heliosstyx »

Is Gnome Epiphany secure enough for daily use under Debian 10 Gnome 3.30? What is your recommendation?

Thank you. :wink:
Last edited by Heliosstyx on 2020-02-19 12:33, edited 1 time in total.

User avatar
Head_on_a_Stick
Posts: 14114
Joined: 2014-06-01 17:46
Location: London, England
Has thanked: 81 times
Been thanked: 133 times

Re: Gnome Epiphany secure enought for daily use

#2 Post by Head_on_a_Stick »

deadbang

Heliosstyx
Posts: 29
Joined: 2019-10-26 09:52

Re: Gnome Epiphany secure enought for daily use

#3 Post by Heliosstyx »

Thank you for your answer. I thought that epiphany is based on Webkit GTK 2 and so it will be security monitored by Debian, is'nt it? Your reference to the Debian 10 release information is very helpfully. :mrgreen:

User avatar
Head_on_a_Stick
Posts: 14114
Joined: 2014-06-01 17:46
Location: London, England
Has thanked: 81 times
Been thanked: 133 times

Re: Gnome Epiphany secure enought for daily use

#4 Post by Head_on_a_Stick »

Heliosstyx wrote:I thought that epiphany is based on Webkit GTK 2 and so it will be security monitored by Debian, is'nt it?
Yes, you're right. That's the second time I've made that mistake...
deadbang

Heliosstyx
Posts: 29
Joined: 2019-10-26 09:52

Re: Gnome Epiphany secure enought for daily use

#5 Post by Heliosstyx »

So everbody can use Epiphany under Debian 10 without any risks? Thank you.

shep
Posts: 423
Joined: 2011-03-15 15:22

Re: Gnome Epiphany secure enought for daily use

#6 Post by shep »

So everbody can use Epiphany under Debian 10 without any risks? Thank you.
I watched a talk on risk and it broke it down into 3 aspects.
1) Attack surface, ie the part of the software that is exposed.
2) Code quality
3) How motivated the bad guys are to try to find a vulnerability.

From the standpoint of Chromium and Firefox, Chromium has better privilege separation and code quality according to Theo De Raadt.
Both are widely used and a ripe target for attackers.

Webkitgtk browsers previously had poor code quality which is now being addressed. Given its lower popularity, it is a less lucrative target


When assessing a browsers, risk is relative. A browser may have a vulnerability but there are no active exploits in the wild.

There are also mitigations you can do over and above. Disable browser access to cameras, microphones etc. Set the browser to clean all cookies/history when closing. Make sure the browser can only upload/download from one folder and not your entire system. Sandbox the browser, Debian does this automatically with Chromium and webkitgtk/bubblewrap.

Higher Risk is a vulnerability that is actively being exploited.
Last edited by shep on 2020-02-19 12:16, edited 1 time in total.

Heliosstyx
Posts: 29
Joined: 2019-10-26 09:52

Re: Gnome Epiphany secure enought for daily use

#7 Post by Heliosstyx »

Thank you @shep for your clear answer. Debian is sandboxing automatically Chromium and WebGtk: does this mean that Epiphany will also be sandboxed automatically by Debian, because it is using WebGtk 2?

:mrgreen:

shep
Posts: 423
Joined: 2011-03-15 15:22

Re: Gnome Epiphany secure enought for daily use

#8 Post by shep »

Front ends for webkitgtk will be sandboxed. That includes Epiphany, Midori, Qutebrowser and Vimb.

trinidad
Posts: 299
Joined: 2016-08-04 14:58
Been thanked: 16 times

Re: [solved]Gnome Epiphany secure enought for daily use

#9 Post by trinidad »

https://www.cvedetails.com/vulnerabilit ... phany.html

I would say it is secure enough if your praxis is sensible and you are on Buster.

TC
You can't believe your eyes if your imagination is out of focus.

Post Reply