Firefox is the only web browser recommended by the German Federal Office for Information Security (BSI) after research it conducted. (German Federal Office for Information Security or Bundesamt für Sicherheit in der Informationstechnik – BSI).
BSI conducted tests on Mozilla Firefox 68 (ESR), Google Chrome 76, Microsoft Internet Explorer 11 and Microsoft Edge 44. The tests did not include other browsers such as Safari, Brave, Opera or Vivaldi.
The audit was conducted in a manner detailed in a guideline (PDF) for “modern secure browsers” published by the BSI last month, in September 2019.
The BSI typically uses this guide to guide government agencies and private sector companies on which browsers are safe to use.
According to the new BSI guide, to be considered “secure”, a modern browser must meet the following minimum requirements:
– Must support TLS
– Must have a list of trusted certificates – Must support Extended Validation (EV) certificates
– Must verify loaded certificates with a Certificate Revocation List (CRL) or an Electronic Certificate Status Protocol (OCSP)
– The browser must use icons or basic colors to indicate whether communication with a remote server is encrypted or in plain text. Connections to remote websites running on expired certificates should only be opened after user approval
– Must support HTTP Strict Transport Security (HSTS) (RFC 6797)
– Must support Same Origin Policy (SOP) and must support Content Security Policy (CSP) 2.0
– Must support Sub-resource integrity (SRI)
– Must support automatic updates with a separate update mechanism for critical updates and browser extensions
– Browser updates should be signed and verifiable
– The browser’s password manager should store passwords in encrypted form and access to the browser’s built-in password feature should only be allowed when the user has entered a master password
– The user should be able to delete passwords from the browser’s password manager
– Users should be able to block or delete cookies. Users should be able to block or delete autofill history
– Users should be able to block or delete browsing history
– Administrators should be able to configure or block browsers from sending telemetry (usage data). Browsers should support the mechanism for checking harmful content and URLs
– Browsers should allow organizations to have local blacklists
– They should support a settings section from where users can enable or disable addons, extensions or JavaScript.
– Administrators should be allowed to disable profile synchronization features used by the Cloud.
– It should run with minimal privileges on the operating system and should support sandboxing. All browser components should be isolated from each other and the operating system. Communication between isolated features should only be possible through defined interfaces. It should not be possible to directly access resources of individual components.
– Web pages should be isolated from each other, ideally in the form of autonomous processes.
– Browsers should be developed using programming languages that support stack and heap memory protections
. – Browsers should use OS memory protections such as Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP).
According to BSI, Firefox is the only browser that supports all of the above. Here are the points where other applications failed:
– Lack of support for a master password (Chrome, IE, Edge)
– No built-in update mechanism (IE)
– No option to block telemetry
– No SOP (Same Origin Policy) support (IE)
– No CSP (Content Security Policy) support (IE)
– No SRI (Subresource Integrity) support (IE)
– No support for browser profiles, different configurations (IE, Edge)
– Lack of transparency (Chrome, IE, Edge)
