(There's not a well-supported way to avoid this, but there are some tools that use Xpra for it.)
We are in full agreement. On X11, the security model is: every application can see/do everything. You should only run an application in X11 when you fully trust it.
https://wiki.mozilla.org/Security/Sandbox#Linux and https://chromium.googlesource.com/chromium/src/+/master/docs...
There's more details than I can easily describe in a HN post, but in general read those links to learn why
> if you use GNU/Linux it should be trivial to give your web browser better sandboxing than what it does by itself
There's a difference between sandbox separating it from the system (what apparmor/selinux can do) and sandbox of each content and plugin (what browser itself can do, mostly with seccomp). Or in a practical example - why do I care that a website can't write to my home directory, if it still has full access to my bank in another tab.
e10s helps a bit, but it's still in early stages. It wasn't even enabled for everybody until 12th Sept this year. Even now, I believe (please correct me if untrue) that there's only one child for all web content, not one per tab.
http://venturebeat.com/2016/03/18/pwn2own-2016-chrome-edge-a...
I've finally settled on this:
Why are dev tools 1-size-fits-all? What is that? I should be able to say, turn on all the tools, or just give me simple mode.
For a lot of websites I create, I would love to have:
1) Console for errors and debugging output.
2) A way to edit the source of the page I'm looking at, and any connected CSS/JS pages in a regular notepad-like editor to make real-time changes to what I'm looking at (and reload with those changes in place)
That's it. Then I can transfer my changes to my dev files and upload to the FTP server.
Then, when I'm working on some huge bloated website with all kinds of craziness, I can turn on all the tools in an advanced mode.
And the worst privacy story and resource handling.