Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I love Lynx because of this

Pseudonymous user so concerned about privacy that they use the browser with by far the greatest density of exploitable flaws.



Friend, it is okay to enjoy things. Lynx is just a cool project :)


Well wait, I don't think jeffbee was saying it's bad to enjoy things, but rather that the person they were responding to was implying something, namely "Lynx is (in some way) better than Firefox because it doesn't take telemetry data."

Lynx definitely takes less telemetry data than Firefox, but it also gets substantially fewer updates, including security updates. I think text-based browsing is pretty fun but I don't really use it in no small part because of the infrequency of updates.


The person you are replying to is the same person that they are replying to. you can just say "you".


I didn't see that! Silly me!


I can see how the post could be interpreted that way. I've added an edit at the bottom to clarify that I'm not suggesting people actually use it as they main one.


If it doesn't run JavaScript it immediately loses most attack surface relative to other browsers.


It also doesn’t (nor can it) load images, which is #2


Yeah, right after I hit post it occurred to me that assorted media codecs (pictures, video, audio) were probably the next largest attack surface that lynx would also necessarily be immune to :)


I don't know about Lynx, but terminal browsers can display images. w3m is able to do it on virtual terminals and terminal emulators that support it if you install the right packages (w3m-img on Debian for instance).


Attack surface matters for unknown attacks. If the browser just never gets security updates, it's got more than enough known attacks.


https://lynx.invisible-island.net/current/CHANGES.html seems to show it still getting updates; can you point to these known attacks that aren't getting fixed?


I don't know nothing about Lynx, except that I always wanted to write a CLI web browser that did support all web features like JavaScript, just to see if it'd work.

This advice mainly applies to people using old OSes or who don't update their browsers.


And also probably one of the most distinct footprints.


I just went through Lynx's the <20 CVEs over the last 20 years and couldn't find any that haven't been fixed. Same cannot be said for Chrome or Firefox which have dozens every year.


> Pseudonymous user so concerned about privacy that they use the browser with by far the greatest density of exploitable flaws.

"I love Lynx" is different from "I use Lynx for security-sensitive browsing," and "greatest density of publicly documented exploitable flaws" is, even if true (I don't know), not the same as "greatest density of exploitable flaws."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: