Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Tom Ritter

@tomrittervg@infosec.exchange
  • Open on infosec.exchange

Firefox Security, Tor Browser Dev. Also: exploits, mitigations, crypto, privacy, pseudonymity & anonymity, tor

0 Followers
0 Following
5 Posts
Joined September 10, 2024

Posts

Open post
tomrittervg
Tom Ritter @tomrittervg@infosec.exchange · May 14, 2026
Tom Ritter
@tomrittervg@infosec.exchange

Firefox Security, Tor Browser Dev. Also: exploits, mitigations, crypto, privacy, pseudonymity & anonymity, tor

infosec.exchange

Firefox started the week with SIX entries at pwn2own!! We shipped a dot release this week that made half of them withdraw. I got asked "Isn't that kind of cheating?" The answer is no - it is strictly better for contestants. Here's why.

If a contestant goes on stage and demos an exploit that we could have killed but didn't, then they go to the disclosure room. ZDI asks us if we know about the vulnerability. Duplicates don't count. So now the contestant walks away with nothing AND loses their chance.

If we kill the bug ahead of time, sometimes contestants have a backup bug. Sometimes they're just really extra and decide to find a bug and write an exploit the night before. (I forget if it was Dino or Charlie that did this...) Either way they have a shot at something. It would be underhanded to hold things back that we could have patched.

(By the way, of the three remaining entries, two withdrew today...)

23
0
9
0
Open post
tomrittervg
Tom Ritter @tomrittervg@infosec.exchange · Apr 21, 2026
Tom Ritter
@tomrittervg@infosec.exchange

Firefox Security, Tor Browser Dev. Also: exploits, mitigations, crypto, privacy, pseudonymity & anonymity, tor

infosec.exchange

New version of Firefox released.

It's got uh... (checks notes) 354 vuln fixes. So pretty impressed by the platform team for pulling that off in a 4-week cycle.

Actually, a 4 week cycle would include the 41 vulns we fixed in the dot release, so that would be 395 vulns.... Exciting times.

https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-25/

Security Vulnerabilities fixed in Firefox 150
Mozilla

Security Vulnerabilities fixed in Firefox 150

27
13
25
2
Open post
tomrittervg
Tom Ritter @tomrittervg@infosec.exchange · Mar 05, 2026
Tom Ritter
@tomrittervg@infosec.exchange

Firefox Security, Tor Browser Dev. Also: exploits, mitigations, crypto, privacy, pseudonymity & anonymity, tor

infosec.exchange

I've been seeing a lot of comments online about how browser telemetry is just a way to spy on users and we never actually use it, and it provides no value.

We can debate whether you think someone (Firefox or otherwise) overcollects telemetry, or doesn't collect it in a privacy-preserving enough way. And you should be able to turn it all off, for any reason.

But it's been instrumental for me, personally, to ship multiple security improvements to Firefox - and I'm just one of hundreds of developers. I wrote up some more here: https://ritter.vg/blog-telemetry.html

33
22
36
0
Open post
tomrittervg
Tom Ritter @tomrittervg@infosec.exchange · Jan 16, 2026
Tom Ritter
@tomrittervg@infosec.exchange

Firefox Security, Tor Browser Dev. Also: exploits, mitigations, crypto, privacy, pseudonymity & anonymity, tor

infosec.exchange
Replying to @natashenka@infosec.exchange
@natashenka There always seems to be so much pushback on removing functionality. While turning it into a 1-click would help some (especially if the sender isn't in your contacts!), I'd be more curious to see if it could be very tightly sandboxed. (And if not... why not? Tight sandboxing of media libraries with limited kernel attack surface seems like a platform primitive that is broadly useful.) Or cross compiled to wasm - performance of an edge case scenario shouldn't be a concern.
1
0
0
0
Open post
tomrittervg
Tom Ritter @tomrittervg@infosec.exchange · Apr 24, 2025
Tom Ritter
@tomrittervg@infosec.exchange

Firefox Security, Tor Browser Dev. Also: exploits, mitigations, crypto, privacy, pseudonymity & anonymity, tor

infosec.exchange

As a reminder to my academic friends. If you are doing research that involves modifying a compiler - perhaps to add a security mitigation or to test an optimization or some other interesting behavior - and you want to run a real world benchmark or test suite: we can help you run it on Firefox.

We can get you set up with our CI so it's easy and efficient to iterate on your patches and run it through the whole gamut.

If you want a compelling story in your paper, showing results on what is probably the second most complicated piece of software in use ought to do it.

https://wiki.mozilla.org/Building_Firefox/SURF

35
1
30
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 01:29:02 UTC