3 ms·
No, I mean that even if you add additional layers of sandboxing, the chrome process can still access the X socket. A process with the ability to read and write
by startling 10y ago
No, I mean that even if you add additional layers of sandboxing, the chrome process can still access the X socket. A process with the ability to read and write to the X socket can record keypresses, issue mouse and key events, etc etc.
(There's not a well-supported way to avoid this, but there are some tools that use Xpra for it.)
- danieldk 10y agoI know. My point was that Chrome does not have a security advantage over Firefox on X11, since the discussion was about the security advantages of Chrome/Chromium over Firefox. We are in full agreement. On X11, the security model is: every application can see/do everything. You should only run an application in X11 when you fully trust it.