How to Run a More Secure Browser
dragonflybsd.org
dragonflybsd.org
http://theinvisiblethings.blogspot.de/2011/04/linux-security...
I could be wrong. Apparently X11 has the SECURITY and XACE extensions which are theoretically capable of preventing this, but nobody uses them (except SSH, see above). It's possible that DragonFlyBSD has these integrated somehow and makes the directions secure, but I don't think so.
Also, how does this setup compare with Subgraph OS which uses Xpra?
There are better alternatives:
Containers. Run your browser in a container. There are some excellent videos explaining how this works on YouTube.
VMs. Like Qubes OS. You run your browser in a separate VM as your other applications. This picture explains it rather well: https://en.wikipedia.org/wiki/Qubes_OS#/media/File:Qubes_sec...
Wayland works on FreeBSD, and I've seen some reports of it working on DragonFlyBSD as well.
I think the post is more about containing what the browser has access to in terms of Unix permissions in the event of it being controlled maliciously. The attack vector of X11 is equally applicable with or without the steps in this post.
My experience is that the SECURITY extension is universal these days using MIT-MAGIC-COOKIE-1. To do otherwise would be insane as any user on the system would be able to sniff your keystrokes and mess with your windows. That would include utility users and probably even chrooted stuff.
However in this case the SECURITY extension is specifically overridden by copying the ~/.Xauthority file to the browser user. So your comment is still valid. The article discusses the performance implications of not doing the override.
For a big chunk of users --- perhaps the majority of all users --- this is all attackers actually want.
There are a ton of rebuttals I can imagine but I don't know nearly enough about any of the stuff involved here to determine whether any of them are true.
[Edit] not sure about video acceleration in the jail though
A more secure (and perhaps simpler approach) is to have each user run their own X server on a separate virtual console. The size of an X server isn't really significant these days. So each X server will be entirely isolated from the other using the regular X security stuff. You wouldn't need much of a desktop environment for the extra sessions. You might not even need a window manager, depending. You could have one extra session for your banking stuff and/or another for your sketchy streaming sites.
[edit] but I'm not arguing its a better solution for you. Depends on your needs and hardware, etc..
Qubes is ahead of its time and far more versatile than most other solutions at this time.
What attacks are they even mitigating?
You seem to contradict yourself there.
> What attacks are they even mitigating?
The page is based on this email to users@dragonflybsd.org
Date: Tue, 11 Aug 2015 10:32:58 -0700 (PDT)
From: Matthew Dillon <dillon@apollo.backplane.com>
To: users@dragonflybsd.org
Subject: Running firefox a bit more safely - HOWTO
As people may know a firefox hack was found in the wild that allows
any accessible file to be read. This hack was due to a bug in
firefox's internal PDF viewer. The exploit that was found in the wild
was trying to snarf developer-related files such as .ssh configuration
files and keys.
[...]