And here's Theo de Raadt's opinion of Firefox from back in 2018: https://marc.info/?l=openbsd-misc&m=152872551609819&w=2
And here's Theo de Raadt's opinion of Firefox from back in 2018: https://marc.info/?l=openbsd-misc&m=152872551609819&w=2
> Firefox's sandboxing lacks any site isolation. Site isolation runs every website inside its own sandbox so that an exploit in one website cannot access the data from another.
It does seem that Firefox's site isolation is becoming more ready. From a Mozilla blog post two days ago, with instructions how to manually enable it on Firefox stable, beta, or nightly: https://blog.mozilla.org/security/2021/05/18/introducing-sit...
Also, from the same link, they mention X11:
> One example of such sandbox escape flaws is X11 — X11 doesn't implement any GUI isolation which makes it very easy to escape sandboxes with it.
Definitely true that X11 sucks (sorry NVIDIA users). So we have Wayland becoming more mainstream now. I've been using it for several years already, on GNOME and Sway. Working great... even Electron is native now (Signal, VS Code, etc).
And lastly, they rightly mention Pulseaudio:
> PulseAudio is a common sound server on Linux however, it was not written with isolation in mind, making it possible to escape sandboxes with it.
In the last few months PipeWire became a mature drop-in substitute for Pulseaudio in my experience. It was designed with isolation in mind, and a whole bunch of other things.
Hoping Firefox can bridge the gap in security with Chrome so we can wholeheartedly recommend it to people without caveats! We deserve a fast, full-featured, secure, and open source alternative to proprietary web browsers.
A slightly tangential issue is that the mitigations section is not super compelling to me because I think many mitigations are low-value. Evaluation of mitigations typically does not ask the right questions: How much work is it for an attacker to bypass the mitigation, assuming they're aware of it? Can that work be packaged and reused in multiple exploits? And how many bugs become completely non-exploitable due to the mitigation?