4 ms·
A random site with "just html" has the possibility as well to "spread viruses" with a unknown zero-day with for example a image handling exploit, or a novel sor
by ElectricalUnion 3y ago
A random site with "just html" has the possibility as well to "spread viruses" with a unknown zero-day with for example a image handling exploit, or a novel sort of ram rewriting attack.
If you really care about "casual usability of things that can spread viruses" in your security model, you would actually prefer documents in PDF format and running them thru Qubes sanitizing conversion appvm.
- kevincox 3y agoBoth Chromium and Firefox also have built-in PDF readers that run in the browser sandbox so you can read PDFs with no more attack surface than the webpage that you downloaded them from has access to. Of course a separate VM is going to be even more secure but it is a much bigger step for the average user.
- ElectricalUnion 3y agoIt all depends on your Operations Security model. For some people it's more important for things to be available and convenient that for them to be secure. For the average user, I would say malware running under the browser sandbox within a domain context is game over, assuming for example malware under your webmail or bank page domain. This XKCD applies to this very well: https://xkcd.com/1200/ https://xkcd.com/1200/ > If someone steals my laptop while I'm logged in, they can read my email, take my money, and impersonate me to my friends, but at least they can't install drivers without my permission.
- ppergame 3y agoEach browser tab and cross-origin iframe is its own process sandbox. Web security operates on domain boundaries. If your webmail provider or bank is serving malware or user generated content under the same origin as the frontend, they have self-owned beyond the browser’s capacity to help.
- autoexec 3y ago> A random site with "just html" has the possibility as well to "spread viruses" with a unknown zero-day with for example a image handling exploit, or a novel sort of ram rewriting attack. Technically possible, but the vast majority of sites that can get you infected just by viewing them depend on JS. I'd much sooner trust an HTML document than a PDF file from some random website.