this post was submitted on 22 Mar 2025
298 points (83.7% liked)

Technology

67825 readers
7214 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 
top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 130 points 1 week ago (2 children)

The "backdoor" mentioned in a single reply is very different from the telemetry issue. https://github.com/zen-browser/desktop/pull/927 was fixed a year ago.

I agree the telemetry should be either disabled or at the very least users should just get a config tab on first launch to opt out but the Lemmy submission is misleading and bordering on fake news.

[–] [email protected] 1 points 5 days ago* (last edited 5 days ago) (1 children)
[–] [email protected] 1 points 4 days ago

According to their privacy policy there is no telemetry: 1.1. No Telemetry. We do not collect any telemetry data.

According to https://github.com/zen-browser/desktop/issues/5947#issuecomment-2737211334 one of the issues is that Mozilla's telemetry remains enabled which (if happening in secret) is bad and also dumb because Mozilla can't even use telemetry of a very different browser.

[–] [email protected] 59 points 1 week ago

Either way...reading through this, this developer seems like an idiot.

He doesn't really understand what the code he's shipping is doing, he doesn't want to listen to people or ask real questions. He gets defensive to even constructive criticism

Not who I want driving the project behind something as critical as my browser.

[–] priapus 60 points 1 week ago* (last edited 1 week ago) (2 children)

I'm not sure why you linked to this irrelevant 3 week old issue while referring to something that was fixed a year ago. Referring to it as a backdoor also implies that it was malicious, when it was simply incompetence. Have there been any security issues since? (Not trying to imply that not having any would make it safe, just wondering).

Zen is an amateur hobbyist project, expecting it to be something else is silly. It isn't backed by a company, so you take on these risks when you use the project. The same thing goes for all community run browser forks, and unfortunately, using upstream browsers will 100% be more secure. If you don't want to take those risks, just use Firefox (preferably hardened).

Security costs money, open source browser forks generally don't have much of that.

Edit: I'm not trying to shit on this browser, or even say that nobody should use it. Be aware of your attack surface and know what risks you're taking on when using any piece of software. I'm probably still going to play around with Zen, but I probably won't be doing my banking on it.

[–] [email protected] 16 points 1 week ago* (last edited 1 week ago) (8 children)

I'd like to take this opportunity to say Mullvad browser is maintained by Mullvad and Tor Project which in my eyes sets it way apart from these hobby forks (including librewolf)

load more comments (8 replies)
load more comments (1 replies)
[–] [email protected] 54 points 1 week ago (4 children)

They just closed the issue without even acknowledging it, lol

[–] [email protected] 74 points 1 week ago (2 children)

They just closed the issue without even acknowledging it, lol

They acknowledged the remote debugging backdoor issue and fixed it a year ago.

It was enabled due that zen was still a toy project and we needed people to easily open the debugger for easier bug fixing. This was due because zen was not in a daily drivable state and didn't gain any sort of popularity yet.

https://github.com/zen-browser/desktop/pull/927

The telemetry issue is entirely different. Their handling of that is naive at best, dishonest at worst but it is completely different from the "backdoor".

load more comments (2 replies)
[–] WhyJiffie 13 points 1 week ago* (last edited 1 week ago)

are you really surprised? that bugreport did not contain a single actionable detail. and then it refers to some forum without any real reference, name or URL. there may be truth to it, and the other issue was actually very important and ridiculous, but this issue report is a big wontfix, reopen with real details

load more comments (2 replies)
[–] [email protected] 52 points 1 week ago (3 children)

I thought it just allowede easier debugging, sorry

What the fuck, this dude is making a browser and he doesn't know what shit in the code he's shipping even does?

[–] ayyy 0 points 6 days ago

It turns out hobby forks of a web browser is a dumb idea.

[–] [email protected] 24 points 1 week ago

Not really an excuse but I expect writing a browser is an extremely intensive project and perhaps they were unprepared.

Navigating any code base that isn't your own adds it's own challenge on top.

So at this point I think it's a "deer in headlights" case with some "head in sand" thrown in.

load more comments (1 replies)
[–] [email protected] 30 points 1 week ago (11 children)

Fucks sake, reading through these comments it appears the Zen browser developer doesn’t know what they are doing.

What alternatives are people using? I’m on Mac, iOS and Linux, avoiding Chrome/Safari and not looking to go back to Firefox, is there anything reliable/secure available?

[–] [email protected] 2 points 5 days ago

Have you settled on anything yet? I really like the essentials part of zen but incompetence on that level scares me.

[–] [email protected] 29 points 1 week ago (13 children)
load more comments (13 replies)
load more comments (9 replies)
[–] lemmeBe 30 points 1 week ago (4 children)

Whenever people ask about privacy oriented Firefox alternative, firm answer from most of us is Librewolf. However, for some, shiny things are hard to resist.

[–] [email protected] 4 points 6 days ago (1 children)

I like Floorp but i have no idea how much more/less private it is. I just like customising it

[–] lemmeBe 2 points 6 days ago

That's okay. Means privacy isn't your primary concern.

[–] [email protected] 10 points 1 week ago (1 children)

Librewolf isn't on Android, but IronFox is.

[–] lemmeBe 2 points 5 days ago

I just found out from another thread that Fennec is alive. When DivestOS went under, Fennec was pronounced dead too (that was when I migrated to IronFox) .

However, it seems someone continued maintenance. Does anyone have more details?

load more comments (2 replies)
[–] [email protected] 22 points 1 week ago (2 children)

I didn't see anything about a backdoor at the link.

[–] [email protected] 37 points 1 week ago (7 children)

It's weird link to this issue with that title, since the problem is only referenced in the discussion. The actual backdoor issue is here.

[–] [email protected] 41 points 1 week ago (1 children)

I thought it just allowede easier debugging, sorry

Fuuuuck. I wouldn’t eat a sandwich made by this person let alone a web browser. Forking and mucking around in a code base they clearly don’t understand. I get the feeling they’re one of those chmod -R 777 people.

[–] [email protected] 20 points 1 week ago* (last edited 1 week ago) (1 children)

I agree. That response made me lose any trust I had and I actually went to check that I didn't still have Zen browser installed from some earlier test run. He sounds like a script kiddie.

[–] [email protected] 18 points 1 week ago

He was obviously very amateur by reading his posts on Reddit. Zen is more of a skin than a real browser, but I guess that’s essentially what a fork is at some point.

load more comments (6 replies)
[–] [email protected] 13 points 1 week ago

https://github.com/zen-browser/desktop/issues/5947#issuecomment-2741902234

It's a link to a previous issue that was fixed, but it's an egregious one.

[–] [email protected] 17 points 1 week ago* (last edited 1 week ago) (1 children)

Well, at least they explained it! /s

I thought it just allowede easier debugging, sorry

Source

Edit: This comment is a gem, too.

load more comments (1 replies)
[–] [email protected] 11 points 1 week ago

Were they... vibe coding? ⁽ᵖˡᵉᵃˢᵉ ˢᵃʸ ⁿᵒ ᵖˡᵉᵃˢᵉ ˢᵃʸ ⁿᵒ⁾

[–] [email protected] 10 points 1 week ago (6 children)

So disappointing. I just transitioned my personal browsing from Arc to Zen Browser because it was the closest vertical tab experience I could find. Now I hope one of the other browsers will figure out and implement good drawer-based vertical tab UI.

[–] [email protected] 11 points 1 week ago (1 children)

Any Firefox-based browser can use "Tree style tabs" it's vertical tabs from the time before they were cool. Very customizable.

load more comments (1 replies)
load more comments (5 replies)
load more comments
view more: next ›