3 ms·
Can't you use ssh and connect to localhost with the -Y option to sandbox an X app?
by southerndrift 7y ago
Can't you use ssh and connect to localhost with the -Y option to sandbox an X app?
- tlb 7y agoNo. An X11 connection forwarded with -Y can receive all keyboard events, capture all screen pixels, inject mouse/keyboard events and read/write the clipboard. A malicious X11 client app can totally pwn you, forwarded or not.
- aswellian 7y agoA bit more involved, but seems to achieve the desired result: https://www.dragonflybsd.org/docs/handbook/RunSecureBrowser/ https://www.dragonflybsd.org/docs/handbook/RunSecureBrowser/