[ / / / / / / / / / / / / / ] [ dir / animu / discord / loomis / tacos / tenda / vg / vichan / wooo ][Options][ watchlist ]

/tech/ - Technology

You can now write text to your AI-generated image at https://aiproto.com It is currently free to use for Proto members.
Email
Comment *
File
Select/drop/paste files here
Password (Randomized for file and post deletion; you may also set your own.)
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Expand all images

File (hide): 6d7f6155e9c56fd⋯.png (99.46 KB, 1074x808, 537:404, Screenshot_2018-09-30_17-3….png) (h) (u)

[–]

 No.980294[Watch Thread][Show All Posts]

Does anyone else run their browser under a different user?


ssh ff@localhost -f "DISPLAY=:0.0 firefox"

https://www.dragonflybsd.org/docs/docs/handbook/RunSecureBrowser/

 No.980295>>980336

I just use firejail


 No.980300>>980694

I just whistle the HTTP packages in my 33.6k modem.


 No.980336>>980342

>>980295

What does firejail in this case that's better?

Looking at https://firejail.wordpress.com/support/ doesn't show firejail to be as robust as the other solution.

Look like it's just a Linux only attempt at possibly bootlegging together real jails.

https://firejail.wordpress.com/support/

>Why on earth should I use Firejail?

>Actually, most of the time you don’t need to learn anything, just prefix your application with “firejail” and run it. This makes Firejail ideal for the regular, not-so-skilled home user.

>not-so-skilled home user.

Oh... ok then.

https://firejail.wordpress.com/

>Firejail is a SUID program

That's nice I guess. :/


 No.980342>>980370

>>980336

It enables seccomp, blacklists many unnecessary programs and libraries so they can't be executed by the program being firejailed, applies netfilters, blocks certain permissions, mounts temporary overlayFs directories on places like /tmp... it is a much more thorough solution than just sudo-ing a program, although the fact that it uses namespaces and apparently had a root privilege escalation vulnerability back in 2017 make it more of a sidegrade than a straight upgrade.


 No.980370>>980560

>>980342

So basically a convoluted Linux only solution in a SUID program that isn't any better than running under a less privileged user. So why aren't we just logging in under root and using firejail wrapped around everything we run?


 No.980560

>>980370

Running under a different user doesn't do seccomp, boy.


 No.980694

File (hide): 708b535b607e2ad⋯.jpg (11.54 KB, 241x309, 241:309, 1483150658.jpg) (h) (u)




[Return][Go to top][Catalog][Screencap][Nerve Center][Cancer][Update] ( Scroll to new posts) ( Auto) 5
7 replies | 1 images | Page ?
[Post a Reply]
[ / / / / / / / / / / / / / ] [ dir / animu / discord / loomis / tacos / tenda / vg / vichan / wooo ][ watchlist ]