5 ms·
All of that is only marginally helpful without X sandboxing.
by startling 10y ago
All of that is only marginally helpful without X sandboxing.
- danieldk 10y agoI agree, but the same applies to Chrome on X11.
- startling 10y agoNo, I mean that even if you add additional layers of sandboxing, the chrome process can still access the X socket. A process with the ability to read and write to the X socket can record keypresses, issue mouse and key events, etc etc. (There's not a well-supported way to avoid this, but there are some tools that use Xpra for it.)
- danieldk 10y agoI know. My point was that Chrome does not have a security advantage over Firefox on X11, since the discussion was about the security advantages of Chrome/Chromium over Firefox. We are in full agreement. On X11, the security model is: every application can see/do everything. You should only run an application in X11 when you fully trust it.