Conversation

It's all fine with server and command-line applications and on Android, but GTK+ and Qt applications often take a ridiculously long time to load because applications feel like reallocating 32 bytes to 32 MiB via realloc loops in increments of 32 bytes. Krita is particularly bad.
2
8
Epiphany does a lot of this but it's also packed full of memory corruption so it's hard to test performance... not that anyone should be using such an insecure browser anyway. Even Firefox's lack of meaningful sandboxing and other issues are way less bad than the WebKitGTK mess.
2
4
Replying to
Mozilla still owes me a bit of money, along with being in an enormous debt for all the volunteer work I did and the horrible treatment that I was given. I'm extremely unlikely to contribute anything else, and that includes not reporting vulnerabilities in any Mozilla projects.
2
Replying to and
I don't think you need specific reports of vulnerabilities in the sandbox to know that it's nowhere close to the same thing as the Chromium sandbox though, even before they implemented site isolation. I'm not even sure I would call the trivial sandbox bypasses bugs at this point.
1
Replying to and
bugzilla.mozilla.org/show_bug.cgi?i Here's one example of the kind of issue that I'm talking about. These issues aren't limited to X11 platforms. I'm not talking about tricky sandbox bypasses via memory corruption exploits or subtle flaws in the implementation. It's just not really done.