5 ms·
Aren't those already sandboxed browser-local filesystems?
by MajesticHobo 10y ago
Aren't those already sandboxed browser-local filesystems?
- keeperofdakeys 10y agoThe browser can still access your disk though, so any vulnerability in your browser means arbitrary access. An example from last year https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/ https://blog.mozilla.org/security/2015/08/06/firefox-exploit.... That's the reason that I decided to use firejail myself.
- MajesticHobo 10y agoOkay. So it's a protection against browser exploits, not overreaching web APIs.
- koolba 10y agoGood security has layers. That way if one falls through, hopefully the next layer will catch it.
- cm3 10y agoIt's more a boundary for the browser not to pass because it has no business. I've seen an alternative approach which used a separate user account for Firefox and then SSH forwarding of X.
- cm3 10y agoWebTorrent is something I'm afraid to try due to the laws in the place I live and nobody answered me when I asked if WebRTC p2p connections first show a permission popup like Microphone or Speaker access. I don't know how the file access APIs work in JavaScript, but it's scary to think a random website could have a random JS snippet that uploads a file from $HOME.