3 ms·
> The one exception to the network policy, for now, is the X11 protocol which is used to display graphics and receive keyboard/mouse input Well, this makes eve
by devit 8y ago
> The one exception to the network policy, for now, is the X11 protocol which is used to display graphics and receive keyboard/mouse input
Well, this makes everything else moot, since you can just inject keystrokes and thus trivially take over the system... (in addition to probably many other vulnerabilities in the X11 server)
They should try to do a proper isolation job (meaning no I/O other than shared memory and pipes to another Firefox process), not this apparently useless effort.
- icebraining 8y agoThe keyword is "for now".
- upofadown 8y ago>since you can just inject keystrokes and thus trivially take over the system... From javascript in a browser? That would indeed be a serious issue. How would this work exactly?
- makomk 8y agoThe whole point of this is to stop attackers who've managed to break out of the JavaScript sandbox. It's an extra layer of protection. If you're going to assume that an attacker is restricted to what JavaScript is meant to be able to do then the whole exercise is pretty much pointless; this is also a bad assumption.
- db48x 8y agoIf you have 10 problems to fix, the effort spent fixing the first 9 of them isn't "useless" as you say, just because you haven't fixed the 10th one yet. And they couldn't fix all of the issues by blindly proxying all IO through the main Firefox process, either, because that wouldn't fix the problem. It has to be able to _selectively_ proxy IO through the main process, and that takes time and effort to implement.
- jpetso 8y agoWayland to the rescue!
- ars 8y agoYou have a good point, but the way you are writing is unnecessarily aggressive. Emphasis on the unnecessary, it doesn't add anything so you should leave it out of your writing.