Maybe you don't need one. Also, how much time do you want to invest in your security?
The main advantage of an isolated remote browser is isolation of the threats from the public internet away from your own network and device. Ransomware, malware, virii, browser exploits, zero days; by running your local browser, you directly expose yourself to that. When you connect to the public internet through an isolated remote browser, your device is "air gapped" from this. There's still channels of attack, at the same time, the surface area is greatly reduced. I think that's a reason remote browser isolation is becoming more popular as a security practice.
TL;DR - isolation and containment is an effective complement to detection and neutralization of threats.
At least one part is unclear in the page copy, that the session is only 30 minutes long. A sort of "free public internet cafe" or "library computer" limit. It reads like the browser you use is reset every 30 minutes. Actually the browser session only exists for 30 minutes, after that all data is scrubbed. If you want to keep going, you open a new one browser by clicking on the icon.
But it's been on an anonymously leased LUKS-encrypted server, connecting via Tor. Here, I'd need to trust you to actually scrub the data. And to keep others from logging it.
I wouldn't call this silly. As you say, it does protect users from browser-mediated threats. Better than a local VM could. But trust issues ought to at least be mentioned.
What made you create such a secure setup? And what were the biggest challenges you in this?
I'm just starting this, so I'm using normal cloud servers. Other options I know people are interested in are self-hosting. I really appreciate your suggestion!
But yes, self hosting. It'd be really cool if you could do something analogous to streisand.
The hardest part was doing RDP via Tor. Latency can get so bad that it's unusable.
But now that I think of it, I've also used remote Transmission nodes via Tor, running the WebGUI as an onion service. So maybe there's a way to access a remote browser as an onion service. There'd still be latency, but with less bits to move, maybe it'd be less problematic.
Edit: I looked at the BrowserGap link, but see no documentation. If I may ask, how does it do remote browser isolation? It's gotta be more than a proxy. But it's also gotta be less than a VPS, given that it's just a URL. Some sort of container, I guess.
And another question. Do you implement ad blocking?
There's a link to a PDF of points that address common questions on the BrowserGap homepage. I believe it addresses your question in quite a bit of depth.
I admit the link could be more prominent, and also that the PDF could be more polished.
Also, ad blocking is included! It blocks alot of ads, and not all.
Do you mind if I ask what sort of UI client did you use for RDP?
I see that you do use dedicated VPS. And although I'm still a little puzzled by "Interactive Image™ technology", I gather that it's something like RDP. But just for the browser.
I used mainly rdesktop and Remmina.
A short script which runs "kvm -readonly ..." (and a second one which does browser upgrades), and you have exactly the same functionality in the comfort of your own computer, but much faster, with video support, and not relying on the security of some remote service you know nothing about.
That said, I can see many reasons to run remote browser for other reasons -- zero-setup aspect is pretty useful, and the privacy is better than local VM as IP addresses are not shared. It is also a pretty great free proxy, handy when you are on those annoying networks which block some sites.
Also, it might be easier and faster, but that sometimes comes as a trade-off with security. It's far easier and faster to just use a regular consumer browser on your device, but you get those risks.
Personally, I would feel a large amount of risk running a local VM versus a cloud hosted one. A local VM (sans Tor, sans proxy) would expose my IP, which could still be targeted. The VM could be escaped, I think more readily than a cloud machine. At the same time, I do think that a local isolated server would be a great option if you want to self-host, rather than doing that in the cloud. This is definitely something BrowserGap does.
- I would not "stream the browser view to client", I'd use default display driver for the virtual machine (I think kvm uses SDL by default). kvm also provides VNC interface, if you want to run it remotely, but running it remotely will increase the latency.
- It does not support any clients, including mobile ones. You are not running a client/server setup, you are running virtual machine directly on your desktop/laptop.
- Yes, you need to download special software. This is a local-only solution.
IP exposure is a real risk, but I'd say it is a privacy risk, not a security one. There are scanners scanning IP address space non-stop; if your computer is vulnerable to IP-only attacks, it would be hacked even if you do not go to any websites at all.
VM escaping is a thing, but the cloud machine runs a VM as well, and it can be escaped too -- and then user's computer will be attacked via remote screen connection. So:
If one has 2 exploits: browser escape zero-day + VM-escape zero day, they can attack either via Cloud machine or via local VM.
But Cloud machine has an additional attack vector: if the infrastructure itself is compromised, then you instantly lose all secrecy, and open client computers to remote exploits. And while you can ensure that your laptop is safe and updated on time, you don't really know much about cloud.
That said, I think both of those are pretty unlikely, so the final decision should be based on other factors.
I hadn't thought about why a couple people downvoted that answer. Without thinking about it much my guess is those people value hard technical data over empathic "I see where you're coming from and that's valid. Also, this is what I see there," communication.
In other words, if I'd said, "No, you're wrong, because X, Y and Z," it probably would have gotten upvoted.