Comment by freebsd_lovefes
16 hours ago
Or the reason to run Firefox in a FreeBSD jail to get server-grade security. But the question is can an attacker get access to the Firefox profile data? Because you cannot block that from Firefox, obviously.
16 hours ago
Or the reason to run Firefox in a FreeBSD jail to get server-grade security. But the question is can an attacker get access to the Firefox profile data? Because you cannot block that from Firefox, obviously.
Sure, to some degree you must trust your browser. In the extreme case you could open a new, non-persistent browser session for every page you visit. Could be slightly inconvenient...
Or you could have 2 (or 3) separate browser sessions, one for only important stuff, and one for fun.
Or Firefox containers.
Not sure how that partitions the files on disk though, would probably need some code changes to work with some kind of firejail setup.
> In the extreme case you could open a new, non-persistent browser session for every page you visit.
This is seamless on Qubes OS: You just click a link and a new empty VM with Firefox opens. You close the browser, and the VM is destroyed. Can't recommend it enough.
Not really sure that’s safe. There has been at least 1 Qubes OS specific VM escapes this year and 2 KVM guest->host control ones.
1 reply →