Can you please provide more detail as to what attack vectors you forsee being a problem? I want to be conscientious of security concerns, but I legitimately can't think of a scenario that would make what I'm doing genuinely unsafe.
This machine:
• Is connected to the internet.
• Is behind a router. All incoming ports are closed, except one for ssh. (An updated SSH binary has been installed via Macports.)
• Runs Little Snitch, so I can monitor what data gets sent out of my machine.
• Is running an up-to-date copy of Firefox.
• Has all important data backed up to cold storage regularly.
I consider any application I install locally to be trusted code, so the only source of untrusted code is the Javascript that I run inside of Firefox, which is up to date.
Some attack scenarios I can imagine:
1. There's a Firefox zero day. My vulnerable OS does not offer the extra layers of protection that a newer one might.
2. Someone exploits Spectre/Meltdown/etc via Javascript. My attacker is incredibly lucky, and the tiny portion of memory they retrieve just so happens to be the bit that contains something vital, like my master password.
3. Someone emails me a malicious image, which isn't caught by Gmail (personal accounts) or Microsoft Exchange (work account), and infects my machine when it's rendered by Apple Mail.
4. A person I know/trust is tricked into sending me an infected document, likely a PDF or MS Office file. Even though I don't have Acrobat or Microsoft Office installed, the vulnerability is compatible with Preview or iWork '09.
I'm not a particularly important person, so I think I'm more likely to die in a plane crash than get hit by 1 or 2. The latter two scenarios are maybe a bit more concerning, but not to the point where I consider them real threats. Particularly given that I also have cold data backups and Little Snitch.