To be clear, I'm a fan of the product -- just wondering what the other side of the story is.
To be clear, I'm a fan of the product -- just wondering what the other side of the story is.
What information do you have to the contrary?
Assuming there was an exploit that broke out of the Firefox sand box you are correct that any connection is via tor.
Though tails isn't 100% sure, you could chain a Firefox cve + user land to root and then turn off the to routing rules.
One that comes to mind is dirty sock[0]. It uses a vulnerability in the snap api to create a root user.
https://github.com/initstring/dirty_sock/blob/master/dirty_s...
[1] https://www.vice.com/en/article/v7gd9b/facebook-helped-fbi-h...
but yeah probably going to prioritize Qubes and whonix again.
> The Unsafe Browser allows to retrieve the public IP address by a compromised amnesia user with no user interaction