traur scan trivalent-bintraur: trivalent-bin (trust: 71/100) Trust: OK Negative signals: B-MAINTAINER-SINGLE: Maintainer has only 1 package B-SUBMITTER-CHANGED: Package maintainer (aedfvasdfawse) differs from original submitter (kemal) ! B-ORPHAN-TAKEOVER: Adopted package with new git author (Ast3risk-ops) — orphan takeover pattern T-AUTHOR-CHANGE: Git history shows multiple different authors ! B-BIN-DOMAIN-MISMATCH: -bin package upstream is ``github.com`` but source downloads from repo.secureblue.dev ! B-BIN-DOMAIN-MISMATCH: -bin package upstream is ``github.com`` but source downloads from repo.secureblue.dev
I use Trivalent daily but it’s disappointed me in that it has not fixed this ^^ seemingly sketchy modus operandi yet…
..so I considered Helium Browser.
And this right here, on first launch, is the reason I don’t go further:
Helium Services? Why does anyone want that? Mozilla wants this too I think. Disable.
allow browser to update extensions? That’s normal, right? Enable
don’t know what a !bang is nor do I want to procure one of this nature. Disable
browsers usually update UBO lists. this looks normal. Enable?
component updates? uh, why? Disable
HOLY SKETCHORAMA BATMAN–I have to make you get me a spellchecker from Helium HQ? In ungoogled they show you where to get a .bdic file and install it DIY. This is already bundled in most browsers..TOO WEIRD, dealbreaker
Some of this sounds normal, other parts unreasonable.
Your thoughts? Am I looking at this right? And thank you
***firefox has a lot of “opt-out” telemetry until you dig deep into about:config and see they were less than forthcoming…
traur: helium-browser-bin (trust: 92/100)
Trust: TRUSTED
Negative signals:
B-MAINTAINER-SINGLE: Maintainer has only 1 package
T-AUTHOR-CHANGE: Git history shows multiple different authors
so maybe a difference in the packages. As far as the start screen I don’t recall seeing anything like that when I first downloaded a few months back. I guess it could have been there but interesting enough I see nothing in settings about these settings you show here.
thanks for the fast reponse. the package I ran at the top was trivalent. so I was unhappy with the low trust as (thanks to you who introduced me to that app) I put a lot of trust in traur lately.
that said I almost started a thread as to why “single maintainer” is such a badge of suspect? lots of guys/girls have a single app which is their baby. chrome takes a day to rebuild/recompile sometimes and everyone works..I’m OT on my own thread…
The idea of Helium services is that you connect to things like Chrome Store via their services which anonomise your connection. This is beyond even my privacy paranoia and I have it disabled. You can host your own instance of it though it seems like a lot of trouble for little/no gain.
I’m still running Brave-origin alongside Helium. They both seem to be on par with each other tbh.
Trivalent seems more focused on security on a wider system level as apposed to privacy.
A lot of what they wanted was beyond my privacy paranoia too. I think it’s ok if they update UBO lists. after that it just seemed odd.( as much as I want to admire their transparency)
Just fyi, !bangs are a duckduckgo feature that I find super useful. It’s just short abbreviations you can use when searching, e.g. !w <query> just searches wikipedia, !gh searches github, etc. I assume that download gets the current list of them from ddg.
Telemetry isn’t evil on its own. Them being opt-out isn’t something inherently bad. Out of millions of users, few submit feedback and even fewer submit constructive feedback. Doing data analysis on user behavior, that is aggregated and anonymized to begin with in the case of Firefox, isn’t a bad thing to do. While it sounds scary, Mozilla outlines exactly what they get and what they do with that data and it is frankly benign.
HOWEVER, this is the web browser that some months was beating its chest loudly over the fact that Mozilla has page after page of legal ass covering in form of the TOS and the Privacy Notice for Firefox and they don’t. Now they have services? Don’t these require… I don’t know… privacy notices and terms of service? For what is essentially Ungoogle Chromium with the ManifestV2 version of uBO on top and DDG bangs, it sure feels like yet another web browser that exists only so mall ninja infosec folks can point at as “the good guys” after Brave screwed them over with their BS business practices. The fact these exist now only validates my original thought when I saw they retweeted on their official account the clown of tech influencers, mister Theo t3.gg, stating how Firefox is shit now and this 2 people project is actually very good and not at all meh at best: they aren’t in the business of making a clean web browser. They just want to play nice to the infosec folks that believe the government is out to get them.
Hell of a synopsis, thank you. you made me realize that at the end of the day there was nothing wrong with the original Ungoogled Chromium which I was attempting to evolve away from..the revved up UBO is not a selling point, nor the rest of the show you describe. I know there is good telemetry…I consider most of Helium’s telemetry requests from me to be unreasonable. I will applaud them for making it opt-out and move on.
I agree with this even though I sometimes fit into this catergory. A lot of the time my interest in things like Mullvad browser are just out of boredom rather than actually freaking out about privacy.
Firefox wound me up when they introduced the profiles options within the UI but was in no way conneted to the old profile system. It was my fault but I lost a profile from this misunderstanding. I know most code these days is bloated but it just seemed such a waste of resources that someone worked on a whole different but concurrent system and made it seem like the team don’t even know their own product.
I really liked Librewolf not because of the privacy stuff but because it seemed slimmed down but maybe they don’t actually remove a lot of code and just hide it from the UI.
You don’t need to evolve away from a browser but having a few that you like is not a bad thing. It’s not like there’s many to really choose from and less so browser engines obviously.
If one goes kaput or starts being managed in a way you don’t like you don’t have to find a new one in a panic. We all have that backup distro in mind and a backup browser is good.
I also fit in that category at times. It’s hard nowadays to learn what’s true online because a lot of is lies wrapped around a truth. Even with Helium, there’s a small nugget of truth: Mozilla’s management is shaky and not fully trustworthy if you are more conscious of how modern computing can make one dependent on a system that isn’t valuing them as human beings. It’s cool that you can learn about these things without panicking, because a lot of folks end up being super paranoid from this.
As far as I understand it, LibreWolf doesn’t remove code, but it does ship with better configurations out-of-the-box for more privacy conscious people. Firefox is plenty already in that respect, at least in my opinion, with minimal settings that can be done in UI. Whatever else Mozilla has in Firefox is, frankly, none of my business, because it is likely still better than Google shipping a 4GB LLM model that I will never use and I can’t remove at all with their flagship browser. Arguing more enters a realm that simply shifts trust among similar entities (with Helium, it is Mozilla vs. a couple of folks from the open source community that were put on the map from a webtool to download things off websites like Instagram or YouTube). Either way you cut it, you have to trust someone higher up in the chain.
Really don’t understand the “trend” of using the Helium project, it’s a customized fork of ungoogled chromium. Just don’t bother and use ungoogled-chromium instead, that’s what i use side by side with firefox 3 years now.
[the reason I turned to librewolf and mullvad browser is because it became too time-consuming to wrench Firefox down in about:config, I had this rigged where I wanted it which was much better than Arkenfox or Betterfox but so time-consuming.]
Meanwhile, I’m here having switched back to regular Firefox with Betterfox fixes because FireDragon stable (v12.xx) was/is months out-of-date, and the new version (13.xx) was/is just taking too long to be passed as fit for everyday use.
Luckily, copying and pasting profiles between forks has not failed so far, so my locked down profile works identically (so far) to how it was with FireDragon.