#html5

canoodle@nerdpol.ch

GNU Linux -> Alternative Privacy enhanced Browsers :) (for Desktop and Mobile) - WARNING SDKs with surveillance build in! - check VPN app

who/what to trust in 2022?

it’s hard…

“A February 2020 research report published by the School of Computer Science and Statistics at Trinity College Dublin tested six browsers and deemed Brave to be the most private of them, in terms of phoning home: “In the first (most private) group lies Brave, in the second Chrome, Firefox and Safari, and in the third (least private) group lie Edge and Yandex.”[108] (src)

“From a privacy perspective Microsoft Edge and Yandex are qualitatively different from the other browsers studied.”

Both send persistent identifiers that can be used to link requests (and associated IP address/location) to backend servers.”

Edge also sends the hardware UUID of the device to Microsoft and Yandex similarly transmits a hashed hardware identifier to back end servers.”

“As far as we can tell this behaviour cannot be disabled by users.”

“In addition to the search autocomplete functionality that shares details of web pages visited, both transmit web page information to servers that appear unrelated to search autocomplete.”

(src: arstechnica.com)

alternative Browsers for Mobile OS: Android

https://privacytests.org/android.html

https://privacytests.org/ios.html

alternative Browsers for Desktop OS:

update 2022-04

https://librewolf.net/

https://librewolf.net/

https://librewolf.net/docs/faq/

just for completion:

https://www.torproject.org/download/

https://www.torproject.org/download/

https://brave.com/

(currently best Browser in terms of privacy according to https://privacytests.org <- check em out they got a ton of alternative browsers also mobile)

(based on Google’s https://www.chromium.org/)

how to install for various GNU Linux distributions: https://brave.com/linux/

update 2020-10

(untested)

https://www.falkon.org/

“Vivaldi is a freeware, cross-platform web browser developed by Vivaldi Technologies, a company founded by Opera Software co-founder and former CEO Jon Stephenson von Tetzchner and Tatsuki Tomita” <- if that is a good thing… probably not.

Given the Kremlin’s naming convention “Wagner” (the Russian mercenary group killing around the globe like Ukraine but also Africa).

Antonio Vivaldi would be (almost obviously) just another classic music composer in their naming scheme (correct if wrong!?).

“The browser was officially launched on April 12, 2016.[8][9] The browser is aimed at staunch technologists, heavy Internet users, and previous Opera web browser users disgruntled by Opera’s transition from the Presto layout engine to the Blink layout engine, which removed many popular features.[8][10] Vivaldi aims to revive the old, popular features of Opera 12.[11] The browser has gained popularity since the launch of its first technical preview.[12][13] The browser has 1 million users as of January 2017.[14]

the bigger problem with Opera might be this: the Russian Yandex SDK:

  • “A development kit for applications offered for free by Yandex, the Russian tech giant, collects information, which is then stored on Russian servers.”
  • “The proximity between the company and the Kremlin raises questions about the end use of this data.”
  • “Your personal data probably ends up on Russian servers.”
  • “On Tuesday, March 29, the British daily Financial Times revealed that tens of thousands of applications have been developed using software that retrieves users’ information.”
  • “The computer tool is provided by Yandex, a Russian search engine, Google’s main competitor in this country.”
  • “The recovered data is then stored in servers in Russia and Finland.”
  • “In the clutches of the Kremlin AppMetrica’s “open access” makes it one of the most used tools on the market: 36% of applications on Google Play go through this SDK and 11% on the App Store according to Appfigures.”
  • “Among the services offered are video games, messaging apps and virtual private networks (VPNs), designed to browse the web without being tracked.”
  • 7x VPN apps are offered specifically for the Ukrainian public, according to financial times.”
  • “In total, it would be applications installed hundreds of millions of times that would be affected.”
  • auto translated from (src: numerama.com)

(… Google & Apple would NEVER do such things…. NEVER (right? X-D))

# -> what are those files doing INSIDE tor-browser bundle folder #wtf?
./tor-browser_en-US/Browser/.config/vivaldi
./tor-browser_en-US/Browser/.cache/vivaldi
./tor-browser_en-US/Browser/.local/share/.vivaldi_reporting_data

/home/user/.cache/vivaldi
/home/user/.config/vivaldi
/home/user/.local/share/.vivaldi_reporting_data

{"description":"This file contains data used for counting users.
If you are worried about privacy implications,
please see https://help.vivaldi.com/article/how-we-count-our-users/",
"installation_time":"XXXXXXXXXXXXXXXXXX","next_daily_ping":"XXXXXXXXXXXXXXXXX",
"next_monthly_ping":"XXXXXXXXXXXXXXXXXX","next_semestrial_ping":"XXXXXXXXXXXXXXXXX",
"next_trimestrial_ping":"XXXXXXXXXXXXXXXXX",
"next_weekly_ping":"XXXXXXXXXXXXXXXXX",
"next_yearly_ping":"XXXXXXXXXXXXXXXXX",
"pings_since_last_month":0,"unique_user_id":"XXXXXXXXXXXXXXXXX"}

Arora

it’s always a good idea to try out alternatives. 🙂 Welcome to Arora: (under Debian-Gnome3)

arora alternative webKit based browser (similar to firefox)_1

is a lightweight, cross-platform, free and open-source web browser

Arora is available for Linux, OS X, Windows, FreeBSD, OS/2, Haiku,[6] and any other operating system supported by the Qt toolkit. Arora’s name is a palindrome.

The browser’s features include tabbed browsing, bookmarks, browsing history, smart location bar, OpenSearch, session management, privacy mode, a download manager, WebInspector, and AdBlock.[7]

For several months, Meyer discontinued development of Arora due to uncertainty about the strictures of non-compete clauses by his employer; finally in July 2011, he announced that he would no longer contribute to the project.[8] Another software developer, Bastien Pederencino forked Arora’s source code, and published a variant called zBrowser – renamed Zeromus Browser in February 2013. In May 2013, Pederencino published another variant called BlueLightCat. In February 2014, some new patches were released on Arora’s github project page, with some Linux distributions incorporating the changes in their individual versions of Arora packages in their repositories.[9]

Source: https://en.wikipedia.org/wiki/Arora_(web_browser)

install

under Debian it’s easy as the usual:

<span style="color: #00ffff;">apt-get update</span>; # update apt package definitions
<span style="color: #00ffff;">apt-get install arora</span>; # install arora browser

Nice features:

  • fast, sleak, efficient, webkit without Google influenced Firefox (they get millions for making Google the default search engine…)
  • JavaScript and Images can be easily disabled
  • AdBlock INCLUDED 🙂
  • Nice Page-loading %percentage% view
  • Excellent https://startpage.com/ / https://ixquick.com/ integration 🙂
  • You can use all the Firefox-Hotkeys like Alt+D to select the Adress-Bar

I really love that loading %percentage display, that also shows you how big and bulky a website is: (maybe disable grafics or js) arora alternative webKit based browser (similar to firefox)_5 size of website

Nicely: Easy to disable image loading (speed up things) and javascript (security problem)

arora alternative webKit based browser (similar to firefox)_3

It has Adblock INCLUDED! 🙂 No extension needed! GOOD JOB!

arora alternative webKit based browser (similar to firefox)_2

Midori

Check out the FAQ.

Midori is a cross-platform GTK browser based on Webkit. It tracks the latest Webkit very closely, so you always have a fresh version. Midori is very lightweight and fast, but still has a lot of features. Midori is amazingly quick and can be useful for sites like Facebook which tend to slow down Firefox. Users concerned about privacy will be interested to know that Midori features Duck Duck Go as the default search engine, offers built-in ad blocking and good cookie control. An old version (0.4.3) is currently included with Ubuntu 13.10, so it is recommended that you install from the Midori PPA.

SETUP:

tested on debian:

<span style="color: #00ffff;">apt-get update; apt-get install midori</span>; # let's test this ;)

QupZilla

QupZilla is a fast Qt and Webkit based browser that is available for multiple operating systems. It features a reasonably simple interface that will seem familiar to new users. The browser is packed with options, but really offers nothing new or unique when compared to Firefox or Chromium. The QupZilla team has put together a really solid browser, but without offering something unique, I find myself asking “what’s the point?” [Install Now](apt://qupzilla)

IceCat

icecat_browser_logo_gnuzilla_fsf

GNU IceCat, formerly known as GNU IceWeasel,[3] is a free software rebranding of the Mozilla Firefox web browser distributed by the GNU Project. It is compatible with Linux, Windows, Android and macOS.[4]

IceCat is released as a part of GNUzilla, GNU’s rebranding of a code base that used to be the Mozilla Application Suite. As an internet suite, GNUzilla also includes a mail & newsgroup program and an HTML composer.

Mozilla produces free and open-source software, but the binaries include trademarked artwork. The GNU Project attempts to keep IceCat in synchronization with upstream development of Firefox (long-term support versions) while removing all trademarked artwork and non-free add-ons. It also maintains a large list of free software plugins. In addition, it features a few security features not found in the mainline Firefox browser.

https://en.wikipedia.org/wiki/GNU_IceCat

QupZilla 1.6.6 on Debian-Gnome3

qupzilla_screenshot_browser

qupzilla_screenshot_about

install

debian linux

<span style="color: #00ffff;">apt-get update</span>; # you know what this does
<span style="color: #00ffff;">apt-get install qupzilla</span>; # install qupzilla

Screenshots

Import Bookmarks.html

it’s nice that Arora and QupZilla (the naming is terrible 2 remember :-D) allow importing Firefox/Iceweasel exported bookmarks.html.

qupzilla_screenshot_toolbar_bookmarks

QupZilla even gets all the website Icons for you….

qupzilla_screenshot_preferences_bookmark_importer qupzilla_screenshot_preferences_bookmark_importer2

qupzilla_screenshot_preferences_extensions qupzilla_screenshot_preferences_javascript_options qupzilla_screenshot_preferences_privacy qupzilla_screenshot_preferences_appearance qupzilla_screenshot_preferences_downloads qupzilla_screenshot_preferences_browsing qupzilla_screenshot_preferences_browsing2 qupzilla_screenshot_preferences_tabs qupzilla_screenshot_preferences_appearance qupzilla_screenshot_preferences_bookmark_importer qupzilla_screenshot_preferences_adblock_settings

Web (Epiphany)

Web (formerly Epiphany) is the official web browser of the GNOME desktop. It is a very easy to use Webkit based browser with a simplistic user interface. In fact, Web is like the granddaddy of simple web browsers, delivering a simple user interface years before Chrome came on the scene. The browser is very speedy and polished, offering more features with each release. Web makes a great simple alternative to Firefox and Chrome. [Install Now](apt://epiphany-browser)

Bash / Command Line Browsers 🙂

Elinks

Elinks is a text based browser similar to the classic Lynx browser. It launches inside a Terminal window and presents you with only the text of websites, no images, javascript, or Flash. This can be rather useful for website developers to test their sites, or for reading information on sites that are full of annoying javascript and Flash ads.

that’s what http://google.de looks like in elinks:

<a href="https://dwaves.de/wp-content/uploads/2015/07/google.de-in-elinks.png"><img alt="google.de in elinks" class="alignnone size-full wp-image-5752" height="424" src="https://dwaves.de/wp-content/uploads/2015/07/google.de-in-elinks.png" width="910"></img></a>

Source: https://www.starryhope.com/10-alternative-browsers-for-ubuntu-linux/

Links:

http://www.linuxuser.co.uk/reviews/arora-web-browser-review

Other alternative fast / lightweight browsers: https://en.wikipedia.org/wiki/Comparison_of_lightweight_web_browsers

https://sourceforge.net/projects/zbrowser-linux/

https://sourceforge.net/projects/bluelightcat/

http://www.vavai.net/2010/01/7-lightweight-linux-browsers-you-may-want-to-consider-for-fast-browsing-experience/

how to get (a bit) more privacy:

https://dwaves.de/2022/03/31/wie-privatsphare-online-verbessern-mit-tor-und-kostenloser-vpn-firmware-fur-router-how-to-protect-privacy-online-with-tor-and-free-vpn-firmware-for-routers-how-to-setup-tor-node-%d0%ba%d0%b0/

#linux #gnu #gnulinux #opensource #administration #sysops #alternatives #browser #www #internet #web #firefox #Linux #Internet #Browser #Alternatives #html #css #js #browse #theweb #javascript #html5 #webrtc #vivaldi #android #mobile

Originally posted at: https://dwaves.de/2015/07/17/gnu-linux-alternative-privacy-enhanced-browsers-for-desktop-and-mobile-warning-sdks-with-surveillance-build-in-check-vpn-app/

canoodle@nerdpol.ch

GNU Linux -> Alternative Privacy enhanced Browsers :) (for Desktop and Mobile) - WARNING SDKs with surveillance build in!

who/what to trust in 2022?

it’s hard…

“A February 2020 research report published by the School of Computer Science and Statistics at Trinity College Dublin tested six browsers and deemed Brave to be the most private of them, in terms of phoning home: “In the first (most private) group lies Brave, in the second Chrome, Firefox and Safari, and in the third (least private) group lie Edge and Yandex.”[108] (src)

“From a privacy perspective Microsoft Edge and Yandex are qualitatively different from the other browsers studied.”

Both send persistent identifiers that can be used to link requests (and associated IP address/location) to backend servers.”

Edge also sends the hardware UUID of the device to Microsoft and Yandex similarly transmits a hashed hardware identifier to back end servers.”

“As far as we can tell this behaviour cannot be disabled by users.”

“In addition to the search autocomplete functionality that shares details of web pages visited, both transmit web page information to servers that appear unrelated to search autocomplete.”

(src: arstechnica.com)

alternative Browsers for Mobile OS: Android

https://privacytests.org/android.html

https://privacytests.org/ios.html

alternative Browsers for Desktop OS:

update 2022-04

https://librewolf.net/

https://librewolf.net/

https://librewolf.net/docs/faq/

just for completion:

https://www.torproject.org/download/

https://www.torproject.org/download/

https://brave.com/

(currently best Browser in terms of privacy according to https://privacytests.org <- check em out they got a ton of alternative browsers also mobile)

(based on Google’s https://www.chromium.org/)

how to install for various GNU Linux distributions: https://brave.com/linux/

update 2020-10

(untested)

https://www.falkon.org/

“Vivaldi is a freeware, cross-platform web browser developed by Vivaldi Technologies, a company founded by Opera Software co-founder and former CEO Jon Stephenson von Tetzchner and Tatsuki Tomita” <- if that is a good thing… probably not.

“The browser was officially launched on April 12, 2016.[8][9] The browser is aimed at staunch technologists, heavy Internet users, and previous Opera web browser users disgruntled by Opera’s transition from the Presto layout engine to the Blink layout engine, which removed many popular features.[8][10] Vivaldi aims to revive the old, popular features of Opera 12.[11] The browser has gained popularity since the launch of its first technical preview.[12][13] The browser has 1 million users as of January 2017.[14]

the bigger problem with Opera might be this: the Russian Yandex SDK:

  • “A development kit for applications offered for free by Yandex, the Russian tech giant, collects information, which is then stored on Russian servers.”
  • “The proximity between the company and the Kremlin raises questions about the end use of this data.”
  • “Your personal data probably ends up on Russian servers.”
  • “On Tuesday, March 29, the British daily Financial Times revealed that tens of thousands of applications have been developed using software that retrieves users’ information.”
  • “The computer tool is provided by Yandex, a Russian search engine, Google’s main competitor in this country.”
  • “The recovered data is then stored in servers in Russia and Finland.”
  • auto translated from (src: numerama.com)

Arora

it’s always a good idea to try out alternatives. 🙂 Welcome to Arora: (under Debian-Gnome3)

arora alternative webKit based browser (similar to firefox)_1

is a lightweight, cross-platform, free and open-source web browser

Arora is available for Linux, OS X, Windows, FreeBSD, OS/2, Haiku,[6] and any other operating system supported by the Qt toolkit. Arora’s name is a palindrome.

The browser’s features include tabbed browsing, bookmarks, browsing history, smart location bar, OpenSearch, session management, privacy mode, a download manager, WebInspector, and AdBlock.[7]

For several months, Meyer discontinued development of Arora due to uncertainty about the strictures of non-compete clauses by his employer; finally in July 2011, he announced that he would no longer contribute to the project.[8] Another software developer, Bastien Pederencino forked Arora’s source code, and published a variant called zBrowser – renamed Zeromus Browser in February 2013. In May 2013, Pederencino published another variant called BlueLightCat. In February 2014, some new patches were released on Arora’s github project page, with some Linux distributions incorporating the changes in their individual versions of Arora packages in their repositories.[9]

Source: https://en.wikipedia.org/wiki/Arora_(web_browser)

install

under Debian it’s easy as the usual:

<span style="color: #00ffff;">apt-get update</span>; # update apt package definitions
<span style="color: #00ffff;">apt-get install arora</span>; # install arora browser

Nice features:

  • fast, sleak, efficient, webkit without Google influenced Firefox (they get millions for making Google the default search engine…)
  • JavaScript and Images can be easily disabled
  • AdBlock INCLUDED 🙂
  • Nice Page-loading %percentage% view
  • Excellent https://startpage.com/ / https://ixquick.com/ integration 🙂
  • You can use all the Firefox-Hotkeys like Alt+D to select the Adress-Bar

I really love that loading %percentage display, that also shows you how big and bulky a website is: (maybe disable grafics or js) arora alternative webKit based browser (similar to firefox)_5 size of website

Nicely: Easy to disable image loading (speed up things) and javascript (security problem)

arora alternative webKit based browser (similar to firefox)_3

It has Adblock INCLUDED! 🙂 No extension needed! GOOD JOB!

arora alternative webKit based browser (similar to firefox)_2

Midori

Check out the FAQ.

Midori is a cross-platform GTK browser based on Webkit. It tracks the latest Webkit very closely, so you always have a fresh version. Midori is very lightweight and fast, but still has a lot of features. Midori is amazingly quick and can be useful for sites like Facebook which tend to slow down Firefox. Users concerned about privacy will be interested to know that Midori features Duck Duck Go as the default search engine, offers built-in ad blocking and good cookie control. An old version (0.4.3) is currently included with Ubuntu 13.10, so it is recommended that you install from the Midori PPA.

SETUP:

tested on debian:

<span style="color: #00ffff;">apt-get update; apt-get install midori</span>; # let's test this ;)

QupZilla

QupZilla is a fast Qt and Webkit based browser that is available for multiple operating systems. It features a reasonably simple interface that will seem familiar to new users. The browser is packed with options, but really offers nothing new or unique when compared to Firefox or Chromium. The QupZilla team has put together a really solid browser, but without offering something unique, I find myself asking “what’s the point?” [Install Now](apt://qupzilla)

IceCat

icecat_browser_logo_gnuzilla_fsf

GNU IceCat, formerly known as GNU IceWeasel,[3] is a free software rebranding of the Mozilla Firefox web browser distributed by the GNU Project. It is compatible with Linux, Windows, Android and macOS.[4]

IceCat is released as a part of GNUzilla, GNU’s rebranding of a code base that used to be the Mozilla Application Suite. As an internet suite, GNUzilla also includes a mail & newsgroup program and an HTML composer.

Mozilla produces free and open-source software, but the binaries include trademarked artwork. The GNU Project attempts to keep IceCat in synchronization with upstream development of Firefox (long-term support versions) while removing all trademarked artwork and non-free add-ons. It also maintains a large list of free software plugins. In addition, it features a few security features not found in the mainline Firefox browser.

https://en.wikipedia.org/wiki/GNU_IceCat

QupZilla 1.6.6 on Debian-Gnome3

qupzilla_screenshot_browser

qupzilla_screenshot_about

install

debian linux

<span style="color: #00ffff;">apt-get update</span>; # you know what this does
<span style="color: #00ffff;">apt-get install qupzilla</span>; # install qupzilla

Screenshots

Import Bookmarks.html

it’s nice that Arora and QupZilla (the naming is terrible 2 remember :-D) allow importing Firefox/Iceweasel exported bookmarks.html.

qupzilla_screenshot_toolbar_bookmarks

QupZilla even gets all the website Icons for you….

qupzilla_screenshot_preferences_bookmark_importer qupzilla_screenshot_preferences_bookmark_importer2

qupzilla_screenshot_preferences_extensions qupzilla_screenshot_preferences_javascript_options qupzilla_screenshot_preferences_privacy qupzilla_screenshot_preferences_appearance qupzilla_screenshot_preferences_downloads qupzilla_screenshot_preferences_browsing qupzilla_screenshot_preferences_browsing2 qupzilla_screenshot_preferences_tabs qupzilla_screenshot_preferences_appearance qupzilla_screenshot_preferences_bookmark_importer qupzilla_screenshot_preferences_adblock_settings

Web (Epiphany)

Web (formerly Epiphany) is the official web browser of the GNOME desktop. It is a very easy to use Webkit based browser with a simplistic user interface. In fact, Web is like the granddaddy of simple web browsers, delivering a simple user interface years before Chrome came on the scene. The browser is very speedy and polished, offering more features with each release. Web makes a great simple alternative to Firefox and Chrome. [Install Now](apt://epiphany-browser)

Bash / Command Line Browsers 🙂

Elinks

Elinks is a text based browser similar to the classic Lynx browser. It launches inside a Terminal window and presents you with only the text of websites, no images, javascript, or Flash. This can be rather useful for website developers to test their sites, or for reading information on sites that are full of annoying javascript and Flash ads.

that’s what http://google.de looks like in elinks:

<a href="https://dwaves.de/wp-content/uploads/2015/07/google.de-in-elinks.png"><img alt="google.de in elinks" class="alignnone size-full wp-image-5752" height="424" src="https://dwaves.de/wp-content/uploads/2015/07/google.de-in-elinks.png" width="910"></img></a>

Source: https://www.starryhope.com/10-alternative-browsers-for-ubuntu-linux/

Links:

http://www.linuxuser.co.uk/reviews/arora-web-browser-review

Other alternative fast / lightweight browsers: https://en.wikipedia.org/wiki/Comparison_of_lightweight_web_browsers

https://sourceforge.net/projects/zbrowser-linux/

https://sourceforge.net/projects/bluelightcat/

http://www.vavai.net/2010/01/7-lightweight-linux-browsers-you-may-want-to-consider-for-fast-browsing-experience/

how to get (a bit) more privacy:

https://dwaves.de/2022/03/31/wie-privatsphare-online-verbessern-mit-tor-und-kostenloser-vpn-firmware-fur-router-how-to-protect-privacy-online-with-tor-and-free-vpn-firmware-for-routers-how-to-setup-tor-node-%d0%ba%d0%b0/

#linux #gnu #gnulinux #opensource #administration #sysops #alternatives #browser #www #internet #web #firefox #Linux #Internet #Browser #Alternatives #html #css #js #browse #theweb #javascript #html5 #webrtc #vivaldi #android #mobile

Originally posted at: https://dwaves.de/2015/07/17/gnu-linux-alternative-privacy-enhanced-browsers-for-desktop-and-mobile-warning-sdks-with-surveillance-build-in/

canoodle@nerdpol.ch

from HTML5 & Javascript blob technique to ransomeware - JS is evil (when it is allowed to do more than gui animations)

“The Duri malware, for example, uses the Javascript blob technique.

The attacks are triggered by visiting a website with the malicious code.”

(this could be a well known, sincere, but hacked website)

“By downloading, the malware can install itself on the target device.”

“HTML smuggling is also made possible by the HTML5 “Download” attribute for anchor tags.”

“When a user clicks the HTML link, a download of the file is triggered.”

“The attack therefore uses conventional HTML5 and JavaScript functions.”

“The attack occurs especially in email campaigns.”

“That is, users with Exchange Online mailboxes are also affected.”

“Spear phishing campaign can ransomware”

“This technique was noticed in a spear phishing campaign in May 2021.

“As part of these attacks, the banking Trojan Mekotio as well as AsyncRAT/NJRAT and Trickbot were infiltrated – this also means remote code execution and complete takeover of computers is possible.”

Ransomware also enters networks in this way.”

“The Microsoft 365 Defender Threat Intelligence Team shows what such an attack looks like in a Twitter post.

ISOMorph Infection: In-Depth Analysis of a New HTML Smuggling Campaign

src: translated from https://www.security-insider.de/html-smuggling-greift-netzwerke-von-innen-an-a-1109311/

Links:

https://www.bleepingcomputer.com/news/security/duri-campaign-smuggles-malware-via-html-and-javascript/

https://dwaves.de/2018/09/10/javascript-is-evil-a-major-security-problem/

https://dwaves.de/2021/02/26/the-evilness-of-javascript-dont-be-evil-twitter-strikes-again/

https://dwaves.de/2018/11/16/xiaomi-nfc-and-baseband-exploit-confirmed-javascript-is-indeed-evil-also-on-phones/

https://dwaves.de/2017/12/21/bitcoin-zcash-monero-mining-via-javascript-inside-browser-of-website-visitors/

https://dwaves.de/2018/01/04/amd-arm-intel-cpus-all-got-problems-meltdown-and-spectre-javascript-could-steal-your-firefoxs-passwords/

https://dwaves.de/2019/12/17/mail-thunderbird-disable-javascript/

#linux #gnu #gnulinux #opensource #administration #sysops #itsec #itsecurity #js #html5 #html #javascript #cyber #cybersecurity #cybersec

Originally posted at: https://dwaves.de/2022/04/13/from-html5-javascript-blob-technique-to-ransomeware-js-is-evil-when-it-is-allowed-to-do-more-than-gui-animations/

canoodle@nerdpol.ch

GNU Linux -> Alternative Browsers :) (for Desktop and Mobile)

alternative Browsers for Mobile OS: Android

https://privacytests.org/android.html

https://privacytests.org/ios.html

alternative Browsers for Desktop OS:

update 2022-04

https://librewolf.net/

https://librewolf.net/

https://librewolf.net/docs/faq/

just for completion:

https://www.torproject.org/download/

https://www.torproject.org/download/

https://brave.com/

(currently best Browser in terms of privacy according to https://privacytests.org <- check em out they got a ton of alternative browsers also mobile)

(based on Google’s https://www.chromium.org/)

how to install for various GNU Linux distributions: https://brave.com/linux/

https://vivaldi.com/

https://vivaldi.com/

Vivaldi Web Browser Made in Norway (!) by Vivaldi Technologies

(based on Google’s https://www.chromium.org/)

(It is Open Source (get the source here)! but not under GPL, but this licence)

https://vivaldi.com/blog/technology/why-isnt-vivaldi-browser-open-source/

update 2020-10

(untested)

https://www.falkon.org/

update: 2018:

https://en.wikipedia.org/wiki/Vivaldi_(web_browser)

Vivaldi is a freeware, cross-platform web browser developed by Vivaldi Technologies, a company founded by Opera Software co-founder and former CEO Jon Stephenson von Tetzchner and Tatsuki Tomita. The browser was officially launched on April 12, 2016.[8][9] The browser is aimed at staunch technologists, heavy Internet users, and previous Opera web browser users disgruntled by Opera’s transition from the Presto layout engine to the Blink layout engine, which removed many popular features.[8][10] Vivaldi aims to revive the old, popular features of Opera 12.[11] The browser has gained popularity since the launch of its first technical preview.[12][13] The browser has 1 million users as of January 2017.[14]

Arora

it’s always a good idea to try out alternatives. 🙂 Welcome to Arora: (under Debian-Gnome3)

arora alternative webKit based browser (similar to firefox)_1

is a lightweight, cross-platform, free and open-source web browser

Arora is available for Linux, OS X, Windows, FreeBSD, OS/2, Haiku,[6] and any other operating system supported by the Qt toolkit. Arora’s name is a palindrome.

The browser’s features include tabbed browsing, bookmarks, browsing history, smart location bar, OpenSearch, session management, privacy mode, a download manager, WebInspector, and AdBlock.[7]

For several months, Meyer discontinued development of Arora due to uncertainty about the strictures of non-compete clauses by his employer; finally in July 2011, he announced that he would no longer contribute to the project.[8] Another software developer, Bastien Pederencino forked Arora’s source code, and published a variant called zBrowser – renamed Zeromus Browser in February 2013. In May 2013, Pederencino published another variant called BlueLightCat. In February 2014, some new patches were released on Arora’s github project page, with some Linux distributions incorporating the changes in their individual versions of Arora packages in their repositories.[9]

Source: https://en.wikipedia.org/wiki/Arora_(web_browser)

install

under Debian it’s easy as the usual:

<span style="color: #00ffff;">apt-get update</span>; # update apt package definitions
<span style="color: #00ffff;">apt-get install arora</span>; # install arora browser

Nice features:

  • fast, sleak, efficient, webkit without Google influenced Firefox (they get millions for making Google the default search engine…)
  • JavaScript and Images can be easily disabled
  • AdBlock INCLUDED 🙂
  • Nice Page-loading %percentage% view
  • Excellent https://startpage.com/ / https://ixquick.com/ integration 🙂
  • You can use all the Firefox-Hotkeys like Alt+D to select the Adress-Bar

I really love that loading %percentage display, that also shows you how big and bulky a website is: (maybe disable grafics or js) arora alternative webKit based browser (similar to firefox)_5 size of website

Nicely: Easy to disable image loading (speed up things) and javascript (security problem)

arora alternative webKit based browser (similar to firefox)_3

It has Adblock INCLUDED! 🙂 No extension needed! GOOD JOB!

arora alternative webKit based browser (similar to firefox)_2

What features i would love to see:

  • easy Tor enable/disable buttone 😀 (if that is not making it very bulky)

Links:

http://www.linuxuser.co.uk/reviews/arora-web-browser-review

Other alternative fast / lightweight browsers: https://en.wikipedia.org/wiki/Comparison_of_lightweight_web_browsers

https://sourceforge.net/projects/zbrowser-linux/

https://sourceforge.net/projects/bluelightcat/

http://www.vavai.net/2010/01/7-lightweight-linux-browsers-you-may-want-to-consider-for-fast-browsing-experience/

Midori

Check out the FAQ.

Midori is a cross-platform GTK browser based on Webkit. It tracks the latest Webkit very closely, so you always have a fresh version. Midori is very lightweight and fast, but still has a lot of features. Midori is amazingly quick and can be useful for sites like Facebook which tend to slow down Firefox. Users concerned about privacy will be interested to know that Midori features Duck Duck Go as the default search engine, offers built-in ad blocking and good cookie control. An old version (0.4.3) is currently included with Ubuntu 13.10, so it is recommended that you install from the Midori PPA.

SETUP:

tested on debian:

<span style="color: #00ffff;">apt-get update; apt-get install midori</span>; # let's test this ;)

QupZilla

QupZilla is a fast Qt and Webkit based browser that is available for multiple operating systems. It features a reasonably simple interface that will seem familiar to new users. The browser is packed with options, but really offers nothing new or unique when compared to Firefox or Chromium. The QupZilla team has put together a really solid browser, but without offering something unique, I find myself asking “what’s the point?” [Install Now](apt://qupzilla)

IceCat

icecat_browser_logo_gnuzilla_fsf

GNU IceCat, formerly known as GNU IceWeasel,[3] is a free software rebranding of the Mozilla Firefox web browser distributed by the GNU Project. It is compatible with Linux, Windows, Android and macOS.[4]

IceCat is released as a part of GNUzilla, GNU’s rebranding of a code base that used to be the Mozilla Application Suite. As an internet suite, GNUzilla also includes a mail & newsgroup program and an HTML composer.

Mozilla produces free and open-source software, but the binaries include trademarked artwork. The GNU Project attempts to keep IceCat in synchronization with upstream development of Firefox (long-term support versions) while removing all trademarked artwork and non-free add-ons. It also maintains a large list of free software plugins. In addition, it features a few security features not found in the mainline Firefox browser.

https://en.wikipedia.org/wiki/GNU_IceCat

QupZilla 1.6.6 on Debian-Gnome3

qupzilla_screenshot_browser

qupzilla_screenshot_about

install

debian linux

apt-get update; # you know what this does
apt-get install qupzilla; # install qupzilla

Screenshots

Import Bookmarks.html

it’s nice that Arora and QupZilla (the naming is terrible 2 remember :-D) allow importing Firefox/Iceweasel exported bookmarks.html.

qupzilla_screenshot_toolbar_bookmarks

QupZilla even gets all the website Icons for you….

qupzilla_screenshot_preferences_bookmark_importer qupzilla_screenshot_preferences_bookmark_importer2

qupzilla_screenshot_preferences_extensions qupzilla_screenshot_preferences_javascript_options qupzilla_screenshot_preferences_privacy qupzilla_screenshot_preferences_password_manager qupzilla_screenshot_preferences_downloads qupzilla_screenshot_preferences_browsing qupzilla_screenshot_preferences_browsing2 qupzilla_screenshot_preferences_tabs qupzilla_screenshot_preferences_appearance qupzilla_screenshot_preferences_general qupzilla_screenshot_preferences_adblock_settings

Web (Epiphany)

Web (formerly Epiphany) is the official web browser of the GNOME desktop. It is a very easy to use Webkit based browser with a simplistic user interface. In fact, Web is like the granddaddy of simple web browsers, delivering a simple user interface years before Chrome came on the scene. The browser is very speedy and polished, offering more features with each release. Web makes a great simple alternative to Firefox and Chrome. [Install Now](apt://epiphany-browser)

Bash / Command Line Browsers 🙂

Elinks

Elinks is a text based browser similar to the classic Lynx browser. It launches inside a Terminal window and presents you with only the text of websites, no images, javascript, or Flash. This can be rather useful for website developers to test their sites, or for reading information on sites that are full of annoying javascript and Flash ads.

that’s what http://google.de looks like in elinks:

<a href="https://dwaves.de/wp-content/uploads/2015/07/google.de-in-elinks.png"><img alt="google.de in elinks" class="alignnone size-full wp-image-5752" height="424" src="https://dwaves.de/wp-content/uploads/2015/07/google.de-in-elinks.png" width="910"></img></a>

Source: https://www.starryhope.com/10-alternative-browsers-for-ubuntu-linux/

#linux #gnu #gnulinux #opensource #administration #sysops #alternatives #browser #www #internet #web #firefox #Linux #Internet #Browser #Alternatives #html #css #js #browse #theweb #javascript #html5 #webrtc #vivaldi #android #mobile

Originally posted at: https://dwaves.de/2015/07/17/gnu-linux-alternative-browsers-for-desktop-and-mobile/

coderdojo_bxl_yser@diaspora.psyco.fr
coderdojo_bxl_yser@diaspora.psyco.fr
coderdojo_bxl_yser@diaspora.psyco.fr
coderdojo_bxl_yser@diaspora.psyco.fr
coderdojo_bxl_yser@diaspora.psyco.fr
coderdojo_bxl_yser@diaspora.psyco.fr
coderdojo_bxl_yser@diaspora.psyco.fr

We zijn op zoek naar nieuwe vrijwillige coaches

Coach zijn bij CoderDojo is een buitengewoon avontuur. Wij organiseren ludieke workshops rond computerwetenschappen voor jongeren van 7~8 jaar tot 18 jaar. En je hoeft geen computergoeroe te zijn om een coach te zijn. Dus, als je geïnteresseerd bent om het team van CoderDojo Brussels Yser te versterken, neem dan contact met ons op via bxl-yser@coderdojobelgium.be.

#arduino #belgie #belgië #brussel #code #coderdojo #coderdojo-belgium #coderdojo_belgium #coderdojobelgium #codering #coding #computerontwikkeling #css #css3 #elektronicaworkshops #elektronisch #elektronisch-circuit #elektronisch_circuit #elektronischcircuit #formatie #godot #html #html5 #informatica #initiatie #it-ontwikkeling #it_ontwikkeling #itontwikkeling #javascript #jeugd #jeugdigheid #jongere #kind #kinderen #microbit #ontwikkeling #programmering #python #robotica #scratch #technologie #vrijwilliger #web #webontwikkeling

coderdojo_bxl_yser@diaspora.psyco.fr
coderdojo_bxl_yser@diaspora.psyco.fr
coderdojo_bxl_yser@diaspora.psyco.fr
coderdojo_bxl_yser@diaspora.psyco.fr
taz@pod.geraspora.de

Schon wieder eine #Stellenausschreibung

Webentwickler:in mit Schwerpunkt Frontend in Voll- oder Teilzeit für taz.de ab sofort gesucht

Die #taz war die erste online lesbare #Tageszeitung Deutschlands. Sie bietet nach wie vor alltäglich die Möglichkeit Dinge anders zu machen und ist immer noch #Konzern-unabhängig.
Willst Du mit uns die zunehmend digitale #Zukunft des #Journalismus gestalten? Wir bieten ein kooperatives #Umfeld, das Raum für #Weiterentwicklung und #Kreativität lässt, aber auch strategisches #Denken erfordert und die Bereitschaft, alltägliche Probleme auch eigenverantwortlich zu lösen.

Wir suchen zeitnah ein:e Kolleg:in mit praktischer Berufserfahrung in der Webentwicklung, gerne auch als Quereinsteiger:in. Wichtig ist uns, dass Du nicht nur teamfähig bist, sondern bevorzugt gemeinsam arbeitest, auch mit technischen Laien.

Im #Frontend-Bereich von taz.de stehen viele Veränderungen an. Derzeit gestalten und bauen wir unseren Verlagsbereich neu. Als nächstes plant die #taz, den redaktionellen Bereich zu relaunchen. Dabei werden wir vieles überdenken und verändern. Neben der Pflege und der Weiterentwicklung von taz.de erwartet dich ein bunter Strauß an Themen: #Datenschutz, #Tracking, #Ads, #SEO, strukturierte #Daten, #Feeds, #Barrierefreiheit und vieles mehr.

Anforderungen:

Wenn Du Lust darauf hast, in einem nach wie vor politisch motivierten Umfeld als Teil des Web-Entwickler:innen-Teams auch abteilungsübergreifend mit vielfältig interessanten Menschen, mit Produktentwicklung, EDV, Redaktion und Verlag zusammenzuarbeiten, melde Dich.
Bei der taz bieten wir nicht nur ein kollegiales Arbeitsumfeld, sondern auch familienfreundliche #Arbeitszeiten (flexible #Vollzeit 36,5h/Woche, remote-Arbeit aktuell bis auf Weiteres aufgrund von #Corona erwünscht, auch danach ist prinzipiell #Home-Office möglich, 30 Tage #Urlaub) – es gibt ein ordentliches (und subventioniertes) #Mittagessen im taz-Café.
Wir wollen diverser werden. Deshalb freuen wir uns besonders über Bewerbungen von People of Color und Menschen mit Behinderung. Deine Perspektiven sind uns wichtig und sollen in der taz vertreten sein. Die Arbeitsplätze und Toiletten sind weitestgehend #barrierefrei. Das taz-Café ist mit dem #Rollstuhl erreichbar.
Schicke uns deine #Bewerbung und zeige uns, welche Kenntnisse und Erfahrungen Du gerne bei der taz entfalten würdest.
Es handelt sich um eine volle unbefristete Stelle ab taz-Lohngruppe V. Auch Teilzeit wäre denkbar, wenn Vollzeit für dich nicht möglich ist. Arbeitsaufnahme zum nächst möglichen Zeitpunkt. Schreibe uns gerne, ab wann Du einsteigen könntest und richte Deine Bewerbung an webjob@taz.de.

Wir freuen uns auch über Weiterleitung, ihr findet die Stellenausschreibung auch unter https://taz.de/jobs

#job #jobs #arbeit #anstellung #jobangebot

coderdojo_bxl_yser@diaspora.psyco.fr
coderdojo_bxl_yser@diaspora.psyco.fr