Consumers may have already decided the long battle of browsers in favor of Google Chrome and other Chromium derivatives, but what seems optimal for end users is not necessarily what a government agency would choose. The “German Federal Office for Security in Information Technology” (BSI) published a report aimed at sharing and recommending security optimizations for modern web browsers, and subjected the leading browsers to an audit. Firefox was the only one to meet every condition, and the most interesting part is that they didn’t even evaluate the latest version.
Regardless of the device or operating system, we all want our browsing sessions to be faster and more secure. Often these two requirements conflict, and the price to pay is a poorer experience. However, there are environments that definitely prioritize security and may decide to put everything else in the background.
One such environment is the “German Federal Office for Security in Information Technology” (Bundesamt für Sicherheit in der Informationstechnik, or simply BSI). This office publishes a guide dedicated to the major browsers in the market, which serves as a reference (and why not, a recommendation) for other agencies, public organizations, and private companies. The first such guide saw the light in 2017, but it received an update at the end of September, which leads us to a new audit.
The browsers selected were Google Chrome 76, Microsoft Internet Explorer 11, Microsoft Edge 44, and Mozilla Firefox 68 in its Extended Support Release. Other Chromium variants were excluded, as was Safari. For a browser to be considered “secure” by the office, it must satisfy these requirements:
Requirements for a Secure Browser
- TLS support
- Trusted certificate list
- Support for extended validation certificates
- Verification of loaded certificates against a revocation list (CRL) or an online status protocol (OCSP)
- Icons that identify encrypted and open communications
- Connections to remote sites with expired certificates manually authorized by the user
- HTTP Strict Transport Security (HSTS) support
- Same Origin Policy (SOP)
- Content Security Policy (CSP) 2.0 support
- Subresource Integrity (SRI) support
- Automatic updates with separate mechanisms for browser components and extensions
- Signed and verifiable updates
- Password manager with encrypted storage
- Access to that manager only after entering a master password
- Ability to delete passwords from the manager
- Block and/or delete cookies / autocomplete history / browsing history
- Disable telemetry
- ... and more conditions.
Firefox 68 ESR was the only one to meet the complete list. The most notable failures in the other browsers were:
- No master password mechanism (Chrome, IE, Edge)
- No built-in update mechanism (IE)
- Inability to block telemetry (Chrome, IE, Edge)
- No Same Origin Policy (IE)
- No Content Security Policy (IE)
- No Subresource Integrity (IE)
- No support for multiple profiles (IE, Edge)
- Lack of organizational transparency (Chrome, IE, Edge)
The last point is probably the most contentious for Firefox’s rivals. Mozilla has always emphasized its openness as one of its greatest virtues, while it is very difficult to extract a word from Google and Microsoft regarding the handling of user data. I imagine this result won’t change anything globally, but Firefox retains some popularity in Germany and has good synergy with that country.
Source: ZDNet
https://old.neoteo.com/como-controlar-a-chrome-y-firefox-con-el-teclado/